CLSA-2023-1686651204

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLSA-2023-1686651204
Upstream
Published
2023-06-13T10:13:28Z
Modified
2026-05-27T11:36:14.067743853Z
Summary
kernel: Fix of 25 CVEs
Details
  • cgroup: Use open-time cgroup namespace for process migration perm checks {CVE-2021-4197}
  • cgroup: Use open-time credentials for process migraton perm checks {CVE-2021-4197}
  • vt: drop old FONT ioctls {CVE-2021-33656}
  • fbmem: Check virtual screen sizes in fbsetvar() {CVE-2021-33655}
  • fbcon: Prevent that screen size is smaller than font size {CVE-2021-33655}
  • fbcon: Disallow setting font bigger than screen size {CVE-2021-33655}
  • KVM: nVMX: add missing consistency checks for CR0 and CR4 {CVE-2023-30456}
  • net: usb: ax88179_178a: Fix packet receiving
  • ipv4: make exception cache less predictible {CVE-2021-20322}
  • ipv4: use siphash instead of Jenkins in fnhe_hashfun() {CVE-2021-20322}
  • ipv6: make exception cache less predictible {CVE-2021-20322}
  • ipv6: use siphash in rt6exceptionhash() {CVE-2021-20322}
  • ipv6: use jhash2() in rt6exceptionhash()
  • psi: Fix uaf issue when psi trigger is destroyed while being polled {CVE-2022-2938}
  • psi: fix possible trigger missing in the window
  • cgroup: Allocate cgroupfilectx for kernfsopenfile->priv
  • cgroup: make per-cgroup pressure stall tracking configurable
  • netfilter: nftablesoffload: incorrect flow offload action array size {CVE-2022-25636}
  • netfilter: nftablesoffload: KASAN slab-out-of-bounds Read in nftflowrulecreate
  • Bluetooth: L2CAP: Fix l2capglobalchanbypsm {CVE-2022-42896}
  • Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM {CVE-2022-42896}
  • devlink: Fix use-after-free after a failed reload {CVE-2022-3625}
  • KVM: VMX: Execute IBPB on emulated VM-exit when guest has IBRS {CVE-2022-2196}
  • net/sched: tcindex: update imperfect hash filters respecting rcu {CVE-2023-1281}
  • seqbuf: Fix overflow in seqbufputmemhex() {CVE-2023-28772}
  • wifi: brcmfmac: slab-out-of-bounds read in brcmfgetassoc_ies() {CVE-2023-1380}
  • kvm: initialize all of the kvm_debugregs structure before sending it to userspace {CVE-2023-1513}
  • Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work {CVE-2023-1989}
  • net: sched: schqfq: prevent slab-out-of-bounds in qfqactivate_agg {CVE-2023-31436}
  • cgroup-v1: Require capabilities to set release_agent {CVE-2022-0492}
  • net: sched: fix use-after-free in tcnewtfilter() {CVE-2022-1055}
  • SUNRPC: Ensure we flush any closed sockets before xsxprtfree() {CVE-2022-28893}
  • net/sched: clsu32: fix netns refcount changes in u32change() {CVE-2022-29581}
  • i2c: ismt: Fix an out-of-bounds bug in ismt_access() {CVE-2022-2873}
  • RDMA/cma: Do not change route.addr.srcaddr.ssfamily {CVE-2021-4028}
  • net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup {CVE-2022-2964}
  • KVM: x86/mmu: do compare-and-exchange of gPTE via the user address {CVE-2022-1158}
  • ovl: fail on invalid uid/gid mapping at copy up {CVE-2023-0386}
References

Affected packages

TuxCare:CentOS:8.5
bpftool

Package

Name
bpftool
Purl
pkg:rpm/tuxcare/bpftool?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel

Package

Name
kernel
Purl
pkg:rpm/tuxcare/kernel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-core

Package

Name
kernel-core
Purl
pkg:rpm/tuxcare/kernel-core?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-cross-headers

Package

Name
kernel-cross-headers
Purl
pkg:rpm/tuxcare/kernel-cross-headers?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-debug

Package

Name
kernel-debug
Purl
pkg:rpm/tuxcare/kernel-debug?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-debug-core

Package

Name
kernel-debug-core
Purl
pkg:rpm/tuxcare/kernel-debug-core?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-debug-devel

Package

Name
kernel-debug-devel
Purl
pkg:rpm/tuxcare/kernel-debug-devel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-debug-modules

Package

Name
kernel-debug-modules
Purl
pkg:rpm/tuxcare/kernel-debug-modules?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-debug-modules-extra

Package

Name
kernel-debug-modules-extra
Purl
pkg:rpm/tuxcare/kernel-debug-modules-extra?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-debug-modules-internal

Package

Name
kernel-debug-modules-internal
Purl
pkg:rpm/tuxcare/kernel-debug-modules-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-devel

Package

Name
kernel-devel
Purl
pkg:rpm/tuxcare/kernel-devel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-headers

Package

Name
kernel-headers
Purl
pkg:rpm/tuxcare/kernel-headers?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-ipaclones-internal

Package

Name
kernel-ipaclones-internal
Purl
pkg:rpm/tuxcare/kernel-ipaclones-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-modules

Package

Name
kernel-modules
Purl
pkg:rpm/tuxcare/kernel-modules?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-modules-extra

Package

Name
kernel-modules-extra
Purl
pkg:rpm/tuxcare/kernel-modules-extra?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-modules-internal

Package

Name
kernel-modules-internal
Purl
pkg:rpm/tuxcare/kernel-modules-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-selftests-internal

Package

Name
kernel-selftests-internal
Purl
pkg:rpm/tuxcare/kernel-selftests-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-tools

Package

Name
kernel-tools
Purl
pkg:rpm/tuxcare/kernel-tools?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-tools-libs

Package

Name
kernel-tools-libs
Purl
pkg:rpm/tuxcare/kernel-tools-libs?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
kernel-tools-libs-devel

Package

Name
kernel-tools-libs-devel
Purl
pkg:rpm/tuxcare/kernel-tools-libs-devel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
perf

Package

Name
perf
Purl
pkg:rpm/tuxcare/perf?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"
python3-perf

Package

Name
python3-perf
Purl
pkg:rpm/tuxcare/python3-perf?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els8

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2023-1686651204.json"