QID 257270

Date Published: 2023-12-19

QID 257270: Centos Security Update for kernel

The kernel packages contain the linux kernel, the core of any linux operating system...Security Fix(es):

    kernel: net/sched: sch_qfq component can be exploited if in qfq_change_agg function happens qfq_enqueue overhead (cve-2023-3611).
    Kernel: net/sched: cls_fw component can be exploited as result of failure in tcf_change_indev function (cve-2023-3776).
    Kernel: net/sched: use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route (cve-2023-4128, cve-2023-4206, cve-2023-4207, cve-2023-4208).
    Hw: intel: gather data sampling (gds) side channel vulnerability (cve-2022-40982).
Affected Products:
    CentOS linux 7 x86_64.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Centos mirror patch for updates and patch information.
    Software Advisories
    Advisory ID Software Component Link
    centos mirror URL Logo mirror.centos.org/centos/7/updates/x86_64/Packages/?C=M;O=D