ALSA-2023:4377
Dashboard / Vulnerabilities / ALSA-2023:4377
ALSA-2023:4377
Summary: Important: kernel security, bug fix, and enhancement update
Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipvlan: out-of-bounds write caused by unclear skb->cb (CVE-2023-3090) * kernel: cls_flower: out-of-bounds write in fl_set_geneve_opt() (CVE-2023-35788) * kernel: KVM: x86/mmu: race condition in direct_page_fault() (CVE-2022-45869) * kernel: speculative pointer dereference in do_prlimit() in kernel/sys.c (CVE-2023-0458) * kernel: Spectre v2 SMT mitigations problem (CVE-2023-1998) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2023:4377, https://access.redhat.com/security/cve/CVE-2022-45869, https://access.redhat.com/security/cve/CVE-2023-0458, https://access.redhat.com/security/cve/CVE-2023-1998, https://access.redhat.com/security/cve/CVE-2023-3090, https://access.redhat.com/security/cve/CVE-2023-35788, https://bugzilla.redhat.com/2151317, https://bugzilla.redhat.com/2187257, https://bugzilla.redhat.com/2193219, https://bugzilla.redhat.com/2215768, https://bugzilla.redhat.com/2218672, https://errata.almalinux.org/9/ALSA-2023-4377.html
Affected packages
Package
Name: bpftool
Purl: pkg:rpm/almalinux/bpftool
Affected ranges
Type: ECOSYSTEM
Events:
