[CLSA-2024:1705494763] kernel: Fix of 13 CVEs
Type:
security
Severity:
None
Release date:
2024-01-17
Description:
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb {CVE-2023-40283} - ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet {CVE-2023-6932} - smb: client: fix OOB in smbCalcSize() {CVE-2023-6606} - net/sched: sch_hfsc: Ensure inner classes have fsc curve {CVE-2023-4623} - net/sched: cls_fw: Fix improper refcount update leads to use-after-free {CVE-2023-3776} - vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF {CVE-2023-3567} - relayfs: fix out-of-bounds access in relay_file_read {CVE-2023-3268} - btrfs: unset reloc control if transaction commit fails in prepare_to_relocate() {CVE-2023-3111} - xirc2ps_cs: Fix use after free bug in xirc2ps_detach {CVE-2023-1670} - Bluetooth: L2CAP: Fix u8 overflow {CVE-2022-45934} - Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM {CVE-2022-42896} - tcp: Fix data races around icsk->icsk_af_ops. {CVE-2022-3566} - ipv6: use prandom_u32() for ID generation {CVE-2021-45485}
Updated packages:
  • kernel-abi-whitelists-2.6.32-754.35.8.el6.tuxcare.els14.noarch.rpm
    sha:02d287321837996d1f62a4e00cee65cd2a94cc90
  • kernel-doc-2.6.32-754.35.8.el6.tuxcare.els14.noarch.rpm
    sha:9bde92b8bd1a3febc5d6f6850a456f2da41a291c
  • kernel-firmware-2.6.32-754.35.8.el6.tuxcare.els14.noarch.rpm
    sha:1c7fd207e203b32548d9ef50e64d94bc697c8062
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.