kernel-5.14.0-503.21.1.el9_5
エラータID: AXSA:2025-9568:07
以下項目について対処しました。
[Security Fix]
- kernel/events/core.c には、AUX バッファのシリアル化
処理におけるミューテックスロックの獲得順序に問題がある
ため、ローカルの攻撃者により、サービス拒否攻撃を可能と
する脆弱性が存在します。(CVE-2024-46713)
- drivers/infiniband/hw/bnxt_re/qplib_res.c の
bnxt_qplib_alloc_init_hwq() 関数には、確保した PDE
ページ領域が連続していることを前提としたロジックよる
メモリ破壊の問題があるため、ローカルの攻撃者により、
サービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2024-50208)
- drivers/net/ethernet/mellanox/mlxsw/spectrum_ipip.c
の mlxsw_sp_ipip_ol_netdev_change_gre6() 関数には、
IPv6 アドレスを変更する際におけるメモリリークの問題が
あるため、ローカルの攻撃者により、ip6gre ネットワーク
デバイスのリモートアドレスの変更を介して、サービス拒否
攻撃を可能とする脆弱性が存在します。(CVE-2024-50252)
- net/mptcp/protocol.c の mptcp_rcv_space_adjust()
関数には、サブフローの状態のチェック処理が欠落している
ことに起因したゼロ除算の問題があるため、リモートの
攻撃者より、サービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2024-53122)
パッケージをアップデートしてください。
In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the AUX buffer, add a per RB mutex to fully serialize it. Note that in the lock order comment the perf_event::mmap_mutex order was already wrong, that is, it nesting under mmap_lock is not new with this patch.
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages Avoid memory corruption while setting up Level-2 PBL pages for the non MR resources when num_pages > 256K. There will be a single PDE page address (contiguous pages in the case of > PAGE_SIZE), but, current logic assumes multiple pages, leading to invalid memory access after 256K PBL entries in the PDE.
In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address The device stores IPv6 addresses that are used for encapsulation in linear memory that is managed by the driver. Changing the remote address of an ip6gre net device never worked properly, but since cited commit the following reproducer [1] would result in a warning [2] and a memory leak [3]. The problem is that the new remote address is never added by the driver to its hash table (and therefore the device) and the old address is never removed from it. Fix by programming the new address when the configuration of the ip6gre net device changes and removing the old one. If the address did not change, then the above would result in increasing the reference count of the address and then decreasing it. [1] # ip link add name bla up type ip6gre local 2001:db8:1::1 remote 2001:db8:2::1 tos inherit ttl inherit # ip link set dev bla type ip6gre remote 2001:db8:3::1 # ip link del dev bla # devlink dev reload pci/0000:01:00.0 [2] WARNING: CPU: 0 PID: 1682 at drivers/net/ethernet/mellanox/mlxsw/spectrum.c:3002 mlxsw_sp_ipv6_addr_put+0x140/0x1d0 Modules linked in: CPU: 0 UID: 0 PID: 1682 Comm: ip Not tainted 6.12.0-rc3-custom-g86b5b55bc835 #151 Hardware name: Nvidia SN5600/VMOD0013, BIOS 5.13 05/31/2023 RIP: 0010:mlxsw_sp_ipv6_addr_put+0x140/0x1d0 [...] Call Trace:
In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust Additional active subflows - i.e. created by the in kernel path manager - are included into the subflow list before starting the 3whs. A racing recvmsg() spooling data received on an already established subflow would unconditionally call tcp_cleanup_rbuf() on all the current subflows, potentially hitting a divide by zero error on the newly created ones. Explicitly check that the subflow is in a suitable state before invoking tcp_cleanup_rbuf().
N/A
SRPMS
- kernel-5.14.0-503.21.1.el9_5.src.rpm
MD5: 148afd36dcc2a2e5edc74a1b33d5a24c
SHA-256: 5bbff2dd7e9bf3a95e92a3bff914b3a0090033a9b224ee15b99199349421482d
Size: 141.84 MB
Asianux Server 9 for x86_64
- bpftool-7.4.0-503.21.1.el9_5.x86_64.rpm
MD5: 8d51e8f3509b00caa7f21ac2827d78ca
SHA-256: 05314748722645235ac6067d273b42592d49032b51341f94cbda63df6e2b5b3a
Size: 2.79 MB - kernel-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 1d7c31b84c87e79ae18dffc7af463037
SHA-256: 3446fab464248f31e071494f5d4f9c74cdfae1f318e1d37b982daba5cd4beb2e
Size: 2.02 MB - kernel-abi-stablelists-5.14.0-503.21.1.el9_5.noarch.rpm
MD5: 444c2044e88dc41a43122ed8804bde41
SHA-256: 8aa87f945e020d21c17da176f21b3eb5caa71892637f2aaaad9403119acd5465
Size: 2.04 MB - kernel-core-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: fd4138bc3292683b75323c54d1bb5434
SHA-256: 89fc8d9bd5f3a9192810f65e9bbc8566100b8d0f107a99159f46302d4cb82354
Size: 17.64 MB - kernel-cross-headers-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 404d8af8dc1c6cf9dce4be316c59e9d8
SHA-256: 2ea874e8772ab07022b712c666086e63e7179fbd25948914eef6126147ecc6f3
Size: 8.77 MB - kernel-debug-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: f73b7132282144d54e6cb9ed6edb8a97
SHA-256: 2f9b7aea282f5497bef8bc7f8c310e31990b7c90101469dc400479e7032f518b
Size: 2.02 MB - kernel-debug-core-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 9e0b80044f43a49598bbe48520778581
SHA-256: ca5a12a10d96e49e1bca89e1f5ee77313f1697ebb384005bb20686a68f8edbbc
Size: 30.70 MB - kernel-debug-devel-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: ddfec516045e5c9b3d43d08a149294bd
SHA-256: 6708cc9d477fc142c01011d81aba5ad75335d21534bebe88a0a108f6565ec82f
Size: 21.75 MB - kernel-debug-devel-matched-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 58547b847e1346be1e143d0546455832
SHA-256: 15a671f726a0b18ccbe7892bd483bbef04d3b728b4957b921ec55a3479e0890b
Size: 2.02 MB - kernel-debug-modules-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: ff29f8644ee7f16051dff7f1896015bb
SHA-256: ae687ee999a5e02ae4937226b204463b03a9c49682add881baeac08aee5a16fc
Size: 62.66 MB - kernel-debug-modules-core-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 56c0b9f5b5def1f69c7acc1c844ec7f5
SHA-256: 9216fefc56c840a7c8dbd3349fb57b0369a8ca52f545cd8bdd3975d3849788ed
Size: 47.98 MB - kernel-debug-modules-extra-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 327d3e7489a610c2ce82401617a9b489
SHA-256: 5b4bf004362443f8675aebf458493bfd9ba9fcb8a0c745725c62d7b8916c4403
Size: 2.88 MB - kernel-debug-uki-virt-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: ee2c2696cf7c3e25ccebbaf2a922bbfe
SHA-256: 1400ff2c1df84d52fef01c16e951a9197f716c8804874d5fa32e579dd4b302a1
Size: 81.29 MB - kernel-devel-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 5c5bf288c363aee1f6f855b7e9b5686f
SHA-256: 8aeef75170253de2eb906c7381a97094a963907894e1a98859cd6aceb2d34fcf
Size: 21.56 MB - kernel-devel-matched-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 634dcad56c4d29cca463cf22cf040d99
SHA-256: 4ac5959ba559cf958c73ffd4bdda6f43e97a8f5f0bf9e6c4d6cc0ed65ada2bb6
Size: 2.02 MB - kernel-doc-5.14.0-503.21.1.el9_5.noarch.rpm
MD5: 3076eb8d236f870db13640f95d4885d5
SHA-256: fee6cc80d9bad4beb736061d03c471ad0ba9bc3ee2413def8f22dd9bfd88529f
Size: 37.42 MB - kernel-headers-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 340830892ba68a33130ea51ca2b4628c
SHA-256: c9969909e7c88043a041db1addebb773b938cdd9440128d9271bafd3e28cfd94
Size: 3.73 MB - kernel-modules-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 47892b8b5a490e6eba7747dffeed9467
SHA-256: 66050f2988fde49fddf6c95ffa56d378b74dd9ee170b33979cc62abf558b7ab8
Size: 36.55 MB - kernel-modules-core-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: a997b605ee2a125de5e9cd55957258b0
SHA-256: e479ce43ca937bbee62d102c7dfd88d93211bd321c015a2c6cfacebbafd2e595
Size: 30.44 MB - kernel-modules-extra-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 8e26f0b7e08df7f895a004284ba1eb31
SHA-256: 130e7691ac5e4fc0e2b6c6f99a5d115a407c3d3c48410b4887ad0a1c72a8e7f9
Size: 2.49 MB - kernel-tools-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 479533026e39be40d6e4f4034592595c
SHA-256: a6fc9ede47bc7e3b74112491382c64081807e1858eb4da7ff7c7aaaae368ec07
Size: 2.29 MB - kernel-tools-libs-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 1e6f9306febf5aee07b3a75e0a7605b9
SHA-256: 3730588141a3a53ce4fa7a980ef3230fb88561981cac64bda1c808dfeeca2040
Size: 2.03 MB - kernel-tools-libs-devel-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 2b8b9fa58181fef203ce0aeac0f8785c
SHA-256: b8d9e2093b26180edba30789c80a897a7647c8577098e37325b3dbb46ac320d3
Size: 2.02 MB - kernel-uki-virt-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 91d9f8910b5d49ca252987cf77d66f74
SHA-256: f8b1f4892a9a631d77439692d7c36227f176259a34d8df90d2f788304d7322e1
Size: 60.49 MB - kernel-uki-virt-addons-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 1ca0dcde6f977b6b3447a55d82885aa7
SHA-256: fa1db971b3c7bc0c46bc9a8fdb8d62121c7b472b553bf30e2d1a49dd7d374549
Size: 2.04 MB - libperf-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 4ffc92a5b8b2bc04b6f1a14a3dbd8fe2
SHA-256: 11a35f9bb87333afc0567bee57d08aa8bcfca15577223335ec354eef613dc0f2
Size: 2.04 MB - perf-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 945bd4147095760d06233e582afa7ec0
SHA-256: 01afac521bd4fce9b0e4ee7456193e259f9125aba7d2949755dc34c5b62f70f1
Size: 4.20 MB - python3-perf-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: 25ee0b21975ea851222e361d237ab952
SHA-256: aa937225ba252b5ea2ba24186752e3fed4756465d77dfe2da659bd187baa063e
Size: 2.12 MB - rtla-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: e2c115174ef61020f7067e3375638040
SHA-256: fae88f592d595112131cae1d65b146138bd3d39ed843ac7236471b4d9d8ca83f
Size: 2.07 MB - rv-5.14.0-503.21.1.el9_5.x86_64.rpm
MD5: b56e695fb974877b07108b275e871e76
SHA-256: a8cf6b1360e68aec53f30b590e4b1d2c75ed0b439391006f6201e950c4148b4d
Size: 2.04 MB