[CLSA-2024:1705496273] kernel: Fix of 13 CVEs
Type:
security
Severity:
None
Release date:
2024-01-17
Description:
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb {CVE-2023-40283} - ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet {CVE-2023-6932} - smb: client: fix OOB in smbCalcSize() {CVE-2023-6606} - net/sched: sch_hfsc: Ensure inner classes have fsc curve {CVE-2023-4623} - net/sched: cls_fw: Fix improper refcount update leads to use-after-free {CVE-2023-3776} - vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF {CVE-2023-3567} - relayfs: fix out-of-bounds access in relay_file_read {CVE-2023-3268} - btrfs: unset reloc control if transaction commit fails in prepare_to_relocate() {CVE-2023-3111} - xirc2ps_cs: Fix use after free bug in xirc2ps_detach {CVE-2023-1670} - Bluetooth: L2CAP: Fix u8 overflow {CVE-2022-45934} - Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM {CVE-2022-42896} - tcp: Fix data races around icsk->icsk_af_ops. {CVE-2022-3566} - ipv6: use prandom_u32() for ID generation {CVE-2021-45485}
Updated packages:
  • kernel-abi-whitelists-2.6.32-754.35.8.el6.tuxcare.els14.noarch.rpm
    sha:526b2f5c0b2a1aa9491c75d0433b344569ab1271
  • kernel-doc-2.6.32-754.35.8.el6.tuxcare.els14.noarch.rpm
    sha:328a3e85d7ddbc4a7987223bbe1514e325459125
  • kernel-firmware-2.6.32-754.35.8.el6.tuxcare.els14.noarch.rpm
    sha:b60d7ac5e1f8f183ec825ffbea65756535098e63
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.