Amazon Linux 2 Security Advisory: ALASKERNEL-5.10-2023-042
Advisory Release Date: 2023-10-31 00:17 Pacific
Advisory Updated Date: 2024-08-01 01:11 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
2024-08-01: CVE-2023-52566 was added to this advisory.
2024-08-01: CVE-2023-52527 was added to this advisory.
2024-08-01: CVE-2023-52577 was added to this advisory.
2024-08-01: CVE-2023-52564 was added to this advisory.
2024-08-01: CVE-2023-52528 was added to this advisory.
2024-07-03: CVE-2023-52573 was added to this advisory.
2024-07-03: CVE-2023-52522 was added to this advisory.
2024-07-03: CVE-2023-52578 was added to this advisory.
2024-07-03: CVE-2023-42756 was added to this advisory.
2024-07-03: CVE-2023-52574 was added to this advisory.
2024-06-06: CVE-2023-52567 was added to this advisory.
2024-06-06: CVE-2023-52501 was added to this advisory.
2024-04-25: CVE-2023-52628 was added to this advisory.
2024-03-27: CVE-2023-52433 was added to this advisory.
2024-02-01: CVE-2024-0641 was added to this advisory.
An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->erasesize), used indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0. (CVE-2023-31085)
A flaw in the kernel Xen event handler can cause a deadlock with Xen console handling in unprivileged Xen guests. (CVE-2023-34324)
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.
We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8. (CVE-2023-4244)
A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system. (CVE-2023-42754)
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system. (CVE-2023-42756)
Rejected reason: CVE-2023-4881 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux kernel security team. (CVE-2023-4881)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
New elements in this transaction might expired before such transaction
ends. Skip sync GC for such elements otherwise commit path might walk
over an already released object. Once transaction is finished, async GC
will collect such expired element. (CVE-2023-52433)
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Do not attempt to read past "commit" (CVE-2023-52501)
In the Linux kernel, the following vulnerability has been resolved:
net: fix possible store tearing in neigh_periodic_work() (CVE-2023-52522)
In the Linux kernel, the following vulnerability has been resolved:
ipv4, ipv6: Fix handling of transhdrlen in __ip{,6}_append_data() (CVE-2023-52527)
In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg (CVE-2023-52528)
In the Linux kernel, the following vulnerability has been resolved:
Revert "tty: n_gsm: fix UAF in gsm_cleanup_mux" (CVE-2023-52564)
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix potential use after free in nilfs_gccache_submit_read_data() (CVE-2023-52566)
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_port: Check IRQ data before use (CVE-2023-52567)
In the Linux kernel, the following vulnerability has been resolved:
net: rds: Fix possible NULL-pointer dereference (CVE-2023-52573)
In the Linux kernel, the following vulnerability has been resolved:
team: fix null-ptr-deref when team device type is changed (CVE-2023-52574)
In the Linux kernel, the following vulnerability has been resolved:
dccp: fix dccp_v4_err()/dccp_v6_err() again (CVE-2023-52577)
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: use DEV_STATS_INC() (CVE-2023-52578)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftables: exthdr: fix 4-byte stack OOB write
If priv->len is a multiple of 4, then dst[len / 4] can write past
the destination array which leads to stack corruption.
This construct is necessary to clean the remainder of the register
in case ->len is NOT a multiple of the register size, so make it
conditional just like nft_payload.c does.
The bug was added in 4.1 cycle and then copied/inherited when
tcp/sctp and ip option support was added.
Bug reported by Zero Day Initiative project (ZDI-CAN-21950,
ZDI-CAN-21951, ZDI-CAN-21961). (CVE-2023-52628)
A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel's TIPC subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system. (CVE-2024-0641)
Affected Packages:
kernel
Note:
This advisory is applicable to Amazon Linux 2 - Kernel-5.10 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update kernel to update your system.
aarch64:
kernel-5.10.198-187.748.amzn2.aarch64
kernel-headers-5.10.198-187.748.amzn2.aarch64
kernel-debuginfo-common-aarch64-5.10.198-187.748.amzn2.aarch64
perf-5.10.198-187.748.amzn2.aarch64
perf-debuginfo-5.10.198-187.748.amzn2.aarch64
python-perf-5.10.198-187.748.amzn2.aarch64
python-perf-debuginfo-5.10.198-187.748.amzn2.aarch64
kernel-tools-5.10.198-187.748.amzn2.aarch64
kernel-tools-devel-5.10.198-187.748.amzn2.aarch64
kernel-tools-debuginfo-5.10.198-187.748.amzn2.aarch64
bpftool-5.10.198-187.748.amzn2.aarch64
bpftool-debuginfo-5.10.198-187.748.amzn2.aarch64
kernel-devel-5.10.198-187.748.amzn2.aarch64
kernel-debuginfo-5.10.198-187.748.amzn2.aarch64
kernel-livepatch-5.10.198-187.748-1.0-0.amzn2.aarch64
i686:
kernel-headers-5.10.198-187.748.amzn2.i686
src:
kernel-5.10.198-187.748.amzn2.src
x86_64:
kernel-5.10.198-187.748.amzn2.x86_64
kernel-headers-5.10.198-187.748.amzn2.x86_64
kernel-debuginfo-common-x86_64-5.10.198-187.748.amzn2.x86_64
perf-5.10.198-187.748.amzn2.x86_64
perf-debuginfo-5.10.198-187.748.amzn2.x86_64
python-perf-5.10.198-187.748.amzn2.x86_64
python-perf-debuginfo-5.10.198-187.748.amzn2.x86_64
kernel-tools-5.10.198-187.748.amzn2.x86_64
kernel-tools-devel-5.10.198-187.748.amzn2.x86_64
kernel-tools-debuginfo-5.10.198-187.748.amzn2.x86_64
bpftool-5.10.198-187.748.amzn2.x86_64
bpftool-debuginfo-5.10.198-187.748.amzn2.x86_64
kernel-devel-5.10.198-187.748.amzn2.x86_64
kernel-debuginfo-5.10.198-187.748.amzn2.x86_64
kernel-livepatch-5.10.198-187.748-1.0-0.amzn2.x86_64