CVE-2023-6535
Description
RHSA-2024:0897: kernel security update (Important)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description kernel: NULL pointer dereference in nvmet_tcp_execute_request Red Hat statement Red Hat Enterprise Linux 6 and 7 are not affected by this issue as it doesn't ship the related NVMe driver code. CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linuxβ¦
Description
kernel: NULL pointer dereference in nvmet_tcp_execute_request
Red Hat statement
Red Hat Enterprise Linux 6 and 7 are not affected by this issue as it doesn't ship the related NVMe driver code.
CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9 | RHSA-2024:0881 | 2024-02-20T00:00:00Z |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.18.1.el8_9 | RHSA-2024:0897 | 2024-02-20T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.91.1.el8_6 | RHSA-2024:0724 | 2024-02-07T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.58.1.el8_8 | RHSA-2024:3810 | 2024-06-11T00:00:00Z |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.24.1.el9_3 | RHSA-2024:1248 | 2024-03-12T00:00:00Z |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.24.1.el9_3 | RHSA-2024:1248 | 2024-03-12T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.52.1.el9_2 | RHSA-2024:0723 | 2024-02-07T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2 | RHSA-2024:0725 | 2024-02-07T00:00:00Z |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.91.1.el8_6 | RHSA-2024:0724 | 2024-02-07T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/cluster-logging-operator-bundle:v5.8.6-22 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/cluster-logging-rhel9-operator:v5.8.6-11 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch6-rhel9:v6.8.1-407 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch-operator-bundle:v5.8.6-19 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch-rhel9-operator:v5.8.6-7 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/eventrouter-rhel9:v0.4.0-247 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/fluentd-rhel9:v5.8.6-5 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/logging-curator5-rhel9:v5.8.1-470 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/logging-loki-rhel9:v2.9.6-14 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/logging-view-plugin-rhel9:v5.8.6-2 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/loki-operator-bundle:v5.8.6-24 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/loki-rhel9-operator:v5.8.6-10 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/lokistack-gateway-rhel9:v0.1.0-525 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/opa-openshift-rhel9:v0.1.0-224 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
| RHOL-5.8-RHEL-9 | openshift-logging/vector-rhel9:v0.28.1-56 | RHSA-2024:2094 | 2024-05-01T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected |
| Red Hat Enterprise Linux 7 | kernel | Not affected |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected |
Apply commands
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 6 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| sles | affected | | |
| rocky | 9 | fixed | |
| debian | bookworm | fixed | 6.1.76-1 |
| debian | bullseye | fixed | 5.10.209-1 |
| debian | forky | fixed | 6.6.15-1 |
| debian | sid | fixed | 6.6.15-1 |
| debian | trixie | fixed | 6.6.15-1 |
| rhel | 8 | fixed | |
References
- https://access.redhat.com/errata/RHSA-2024:1248
- https://www.suse.com/security/cve/CVE-2023-6535.html
- https://errata.rockylinux.org/RXSA-2024:1248
- https://security-tracker.debian.org/tracker/CVE-2023-6535
- https://access.redhat.com/errata/RHSA-2024:0897
- https://bugzilla.redhat.com/2087568
- https://bugzilla.redhat.com/2144379
- https://bugzilla.redhat.com/2161310
- https://bugzilla.redhat.com/2173403
- https://bugzilla.redhat.com/2187813
- https://bugzilla.redhat.com/2187931
- https://bugzilla.redhat.com/2231800
- https://bugzilla.redhat.com/2237757
- https://bugzilla.redhat.com/2244723
- https://bugzilla.redhat.com/2245514
- https://bugzilla.redhat.com/2246944
- https://bugzilla.redhat.com/2246945
- https://bugzilla.redhat.com/2253611
- https://bugzilla.redhat.com/2253614
- https://bugzilla.redhat.com/2253908
- https://bugzilla.redhat.com/2254052
- https://bugzilla.redhat.com/2254053
- https://bugzilla.redhat.com/2254054
- https://bugzilla.redhat.com/2255139
- https://errata.almalinux.org/8/ALSA-2024-0897.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.