• kernel-5.14.0-70.26.1.0.1.el9_0 (oel9)
  • 5.14.0-427.42.1.el9_4
  • 2024-11-24 10:37:33
  • 2024-11-26 16:37:40
  • K20241124_03
  • CVE-2022-23816, CVSSv2 Score:
  • Description:

    Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.

  • From:
  • CVE-2022-23825, CVSSv2 Score:
  • Description:

    Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.

  • From:
  • CVE-2022-26373, CVSSv2 Score:
  • Description:

    Livepatching Retbleed may decrease the stability and performance of the kernel, while vulnerability has a medium security impact and only for a certain hardware environment.

  • From:
  • CVE-2022-29900, CVSSv2 Score:
  • Description:

    Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.

  • From:
  • CVE-2022-29901, CVSSv2 Score:
  • Description:

    Livepatching Retbleed may decrease the stability and performance of the kernel, while vulnerability has a medium security impact and only for a certain hardware environment.

  • From:
  • CVE-2023-1206, CVSSv2 Score:
  • Description:

    This is a low priority CVE & the patch impacts many critical components of the networking subsystem & it requires multiple complex adaptations in those components to avoid losing existing connections on patch/unpatch.

  • From:
  • CVE-2023-0597, CVSSv2 Score:
  • Description:

    Medium severity vulnerability CVE requiring extremely complex adaptation (if at all possible)

  • From:
  • CVE-2022-3565, CVSSv2 Score:
  • Description:

    In RHEL9 (and derivatives) isdn/mISDN driver is absent, not compiled.

  • From:
  • CVE-2023-4015, CVSSv2 Score:
  • Description:

    kernel-5.14.0-284.11.1.el9_2 and earlier are not vulnerable because they don't have the commit 4bedf9eee016 (netfilter: nf_tables: fix chain binding transaction logic) that introduced the vulnerability

  • From:
  • CVE-2023-6679, CVSSv2 Score:
  • Description:

    Affected device driver does not exist in supported kernels.

  • From:
  • CVE-2023-4244, CVSSv2 Score:
  • Description:

    An introduction of required changes through KernelCare could cause unavoidable problems to applications which use netfilter functionality.

  • From:
  • CVE-2024-0193, CVSSv2 Score:
  • Description:

    Vulnerable commit 5f68718b34a5 (netfilter: nf_tables: GC transaction API to avoid race with control plane) was introduced later than kernel-5.14.0-362.18.1.el9_3. None of our kernels are vulnerable.

  • From:
  • CVE-2023-52581, CVSSv2 Score:
  • Description:

    The patch for this CVE already present in kernel-5.14.0-362.24.1.el9_3 version. The kernel-5.14.0-362.18.1.el9_3 version and below are not vulnerable because they don't have commit 5f68718b34a5 (netfilter: nf_tables: GC transaction API to avoid race with control plane) which introduced the vulnerability.

  • From:
  • CVE-2023-4133, CVSSv2 Score:
  • Description:

    Complex adaptation required to add timer_shutdown_sync() in timers subsystem.

  • From:
  • CVE-2024-26583, CVSSv2 Score:
  • Description:

    Low-severity patch proven to suffer from stack-unsafety problem when patching during network load.

  • From:
  • CVE-2024-26584, CVSSv2 Score:
  • Description:

    Low-severity patch proven to suffer from stack-unsafety problem when patching during network load.

  • From:
  • CVE-2024-26585, CVSSv2 Score:
  • Description:

    Low-severity patch proven to suffer from stack-unsafety problem when patching during network load.

  • From:
  • CVE-2023-52489, CVSSv2 Score:
  • Description:

    The modified structure mem_section_usage is used only during bootup time. As we patch the changes after booting they will have no effect. Therefore we cannot patch this CVE.

  • From:
  • CVE-2023-42756, CVSSv2 Score:
  • Description:

    The given kernel version isn't vulnerable (Netfilter).

  • From:
  • CVE-2024-26609, CVSSv2 Score:
  • Description:

    CVE has been marked as REJECTED on the NVD website.

  • From:
  • CVE-2024-26737, CVSSv2 Score:
  • Description:

    eBPF: low score UAF with CONFIG_BPF_UNPRIV_DEFAULT_OFF=y by default but needs complex adaptation.

  • From:
  • CVE-2024-35839, CVSSv2 Score:
  • Description:

    Live-patching will introduce network performance degradation in the best case scenario, or even some more serious issues. N/A or Low cvss3 score from NVD or vendors.

  • From:
  • CVE-2024-26720, CVSSv2 Score:
  • Description:

    This CVE introduces a regression and is reverted by CVE-2024-42102 in the same errata

  • From:
  • CVE-2024-41055, CVSSv2 Score:
  • Description:

    Fix for skipped CVE-2023-52489 that modifies structure mem_section_usage only used at boot time

  • From:
  • CVE-2023-28746, CVSSv2 Score:
  • Description:

    RFDS: Medium score vulnerability affecting only Intel Atom CPUs, mitigated via microcode update.

  • From:
  • CVE-2024-39502, CVSSv2 Score:
  • Description:

    Patches a sleepable function, there is a small but non-zero risk of livepatching failure

  • From:
  • CVE-2024-38663, CVSSv2 Score:
  • Description:

    Not vulnerable: buggy commit 3b8cc6298 (blk-cgroup: Optimize blkcg_rstat_flush) was introduced in v6.2 upstream and appeared in RHEL9's 284.11.1

  • From:
  • CVE-2024-26858, CVSSv2 Score:
  • Description:

    Not vulnerable: mapping mechanism that the bug applies to was introduced in v6.6 upstream (3178308ad4c) and appeared in RHEL9's since -427

  • From:
  • CVE-2024-38543, CVSSv2 Score:
  • Description:

    Not vulnerable: function with the buggy code `dmirror_device_evict_chunk()` exists since 362.8.1

  • From:
  • CVE-2024-38593, CVSSv2 Score:
  • Description:

    Not vulnerable: buggy function was introduced in v6.5 upsteam (or RHEL9's 427.13.1), and no similar code patterns existed before for this module

  • From:
  • CVE-2024-26783, CVSSv2 Score:
  • Description:

    Not vulnerable: vulnerable calls to `wakeup_kswapd()` did not exist prior to 284.11.1

  • From: