Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-12069

Опубликовано: 11 янв. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-12069: kernel security update (IMPORTANT)

[4.18.0-513.11.1.0.1_9.OL8]

  • scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress {CVE-2023-2162}
  • af_unix: Fix null-ptr-deref in unix_stream_sendpage() {CVE-2023-4622}
  • netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet {CVE-2023-42753}

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

bpftool

4.18.0-513.11.0.1.el8_9

kernel-cross-headers

4.18.0-513.11.0.1.el8_9

kernel-headers

4.18.0-513.11.0.1.el8_9

kernel-tools

4.18.0-513.11.0.1.el8_9

kernel-tools-libs

4.18.0-513.11.0.1.el8_9

kernel-tools-libs-devel

4.18.0-513.11.0.1.el8_9

perf

4.18.0-513.11.0.1.el8_9

python3-perf

4.18.0-513.11.0.1.el8_9

Oracle Linux x86_64

bpftool

4.18.0-513.11.0.1.el8_9

kernel

4.18.0-513.11.0.1.el8_9

kernel-abi-stablelists

4.18.0-513.11.0.1.el8_9

kernel-core

4.18.0-513.11.0.1.el8_9

kernel-cross-headers

4.18.0-513.11.0.1.el8_9

kernel-debug

4.18.0-513.11.0.1.el8_9

kernel-debug-core

4.18.0-513.11.0.1.el8_9

kernel-debug-devel

4.18.0-513.11.0.1.el8_9

kernel-debug-modules

4.18.0-513.11.0.1.el8_9

kernel-debug-modules-extra

4.18.0-513.11.0.1.el8_9

kernel-devel

4.18.0-513.11.0.1.el8_9

kernel-doc

4.18.0-513.11.0.1.el8_9

kernel-headers

4.18.0-513.11.0.1.el8_9

kernel-modules

4.18.0-513.11.0.1.el8_9

kernel-modules-extra

4.18.0-513.11.0.1.el8_9

kernel-tools

4.18.0-513.11.0.1.el8_9

kernel-tools-libs

4.18.0-513.11.0.1.el8_9

kernel-tools-libs-devel

4.18.0-513.11.0.1.el8_9

perf

4.18.0-513.11.0.1.el8_9

python3-perf

4.18.0-513.11.0.1.el8_9

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.

CVSS3: 6.6
redhat
больше 2 лет назад

A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.

CVSS3: 5.5
nvd
около 2 лет назад

A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.

CVSS3: 5.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 5.5
debian
около 2 лет назад

A use-after-free vulnerability was found in iscsi_sw_tcp_session_creat ...