ALAS2023LIVEPATCH-2023-002


Amazon Linux 2023 Security Advisory: ALASLIVEPATCH-2023-002
Advisory Release Date: 2023-04-13 17:56 Pacific
Advisory Updated Date: 2023-05-09 18:35 Pacific
Severity: Important

Issue Overview:

A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel. This flaw allows an attacker to crash the system and possibly cause a kernel information lea (CVE-2023-1611)

do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference). (CVE-2023-28466)


Affected Packages:

kernel-livepatch-6.1.19-30.43


Issue Correction:
Please ensure you have live patching enabled.
Run dnf update kernel-livepatch-6.1.19-30.43 to update your system.

New Packages:
src:
    kernel-livepatch-6.1.19-30.43-1.0-1.amzn2023.src

x86_64:
    kernel-livepatch-6.1.19-30.43-1.0-1.amzn2023.x86_64