RedHat Linux 核心多個漏洞
最後更新
2025年02月20日
發佈日期:
2025年02月06日
325
觀看次數
風險: 中度風險
類型: 操作系統 - LINUX

於 RedHat Linux核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、洩露敏感資料及繞過保安限制。
注意:
CVE-2024-53104 正在被廣泛利用。Linux 核心在 USB Video Class (UVC) 驅動程式的 uvc_parse_streaming 元件中存在一個越界寫入漏洞,這允許實體攻擊者觸發權限提升。由於利用該漏洞需要與惡意硬件進行物理連接,因此風險等級仍然為中度風險。
[更新於 2025-02-11]
更新受影響之系統或技術、解決方案、漏洞識別碼及相關連結。
[更新於 2025-02-12]
更新受影響之系統或技術、解決方案、漏洞識別碼及相關連結。
[更新於 2025-02-14]
更新受影響之系統或技術、解決方案、漏洞識別碼及相關連結。
[更新於 2025-02-20]
更新影響、受影響之系統或技術、解決方案、漏洞識別碼及相關連結。
影響
- 阻斷服務
- 資料洩露
- 繞過保安限制
- 權限提升
受影響之系統或技術
- Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.8 aarch64
- Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.2 aarch64
- Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.4 aarch64
- Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
- Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
- Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.2 s390x
- Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.4 s390x
- Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x
- Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.8 ppc64le
- Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.2 ppc64le
- Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.4 ppc64le
- Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
- Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
- Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.8 x86_64
- Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.2 x86_64
- Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.4 x86_64
- Red Hat CodeReady Linux Builder for x86_64 8 x86_64
- Red Hat CodeReady Linux Builder for x86_64 9 x86_64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.2 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
- Red Hat Enterprise Linux for ARM 64 8 aarch64
- Red Hat Enterprise Linux for ARM 64 9 aarch64
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.2 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
- Red Hat Enterprise Linux for IBM z Systems 8 s390x
- Red Hat Enterprise Linux for IBM z Systems 9 s390x
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.2 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
- Red Hat Enterprise Linux for Power, little endian 8 ppc64le
- Red Hat Enterprise Linux for Power, little endian 9 ppc64le
- Red Hat Enterprise Linux for Real Time - Telecommunications Update Service 8.4 x86_64
- Red Hat Enterprise Linux for Real Time 8 x86_64
- Red Hat Enterprise Linux for Real Time 9 x86_64
- Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service 8.4 x86_64
- Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
- Red Hat Enterprise Linux for Real Time for NFV 9 x86_64
- Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.0 x86_64
- Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.2 x86_64
- Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.4 x86_64
- Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.0 x86_64
- Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.2 x86_64
- Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.4 x86_64
- Red Hat Enterprise Linux for Real Time for x86_64 - Extended Life Cycle Support 7 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.2 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
- Red Hat Enterprise Linux for x86_64 8 x86_64
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat Enterprise Linux Server - AUS 7.7 x86_64
- Red Hat Enterprise Linux Server - AUS 8.2 x86_64
- Red Hat Enterprise Linux Server - AUS 8.4 x86_64
- Red Hat Enterprise Linux Server - AUS 8.6 x86_64
- Red Hat Enterprise Linux Server - AUS 9.2 x86_64
- Red Hat Enterprise Linux Server - AUS 9.4 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 s390x
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
- Red Hat Enterprise Linux Server - TUS 8.4 x86_64
- Red Hat Enterprise Linux Server - TUS 8.6 x86_64
- Red Hat Enterprise Linux Server - TUS 8.8 x86_64
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
- Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.12 for RHEL 9 x86_64
- Red Hat OpenShift Container Platform 4.14 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.14 for RHEL 9 x86_64
- Red Hat OpenShift Container Platform 4.16 for RHEL 9 x86_64
- Red Hat OpenShift Container Platform 4.17 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.17 for RHEL 9 x86_64
- Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 8 aarch64
- Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 9 aarch64
- Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 8 aarch64
- Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 9 aarch64
- Red Hat OpenShift Container Platform for ARM 64 4.16 for RHEL 9 aarch64
- Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 8 aarch64
- Red Hat OpenShift Container Platform for ARM 64 4.17 for RHEL 9 aarch64
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 9 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 9 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.16 for RHEL 9 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.17 for RHEL 9 s390x
- Red Hat OpenShift Container Platform for Power 4.12 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for Power 4.12 for RHEL 9 ppc64le
- Red Hat OpenShift Container Platform for Power 4.14 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for Power 4.14 for RHEL 9 ppc64le
- Red Hat OpenShift Container Platform for Power 4.16 for RHEL 9 ppc64le
- Red Hat OpenShift Container Platform for Power 4.17 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for Power 4.17 for RHEL 9 ppc64le
解決方案
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
- https://access.redhat.com/errata/RHSA-2025:1067
- https://access.redhat.com/errata/RHSA-2025:1068
- https://access.redhat.com/errata/RHSA-2025:1230
- https://access.redhat.com/errata/RHSA-2025:1231
- https://access.redhat.com/errata/RHSA-2025:1253
- https://access.redhat.com/errata/RHSA-2025:1254
- https://access.redhat.com/errata/RHSA-2025:1264
- https://access.redhat.com/errata/RHSA-2025:1262
- https://access.redhat.com/errata/RHSA-2025:1266
- https://access.redhat.com/errata/RHSA-2025:1267
- https://access.redhat.com/errata/RHSA-2025:1268
- https://access.redhat.com/errata/RHSA-2025:1269
- https://access.redhat.com/errata/RHSA-2025:1270
- https://access.redhat.com/errata/RHSA-2025:1278
- https://access.redhat.com/errata/RHSA-2025:1280
- https://access.redhat.com/errata/RHSA-2025:1281
- https://access.redhat.com/errata/RHSA-2025:1282
- https://access.redhat.com/errata/RHSA-2025:1291
- https://access.redhat.com/errata/RHSA-2025:1347
- https://access.redhat.com/errata/RHSA-2025:1374
- https://access.redhat.com/errata/RHSA-2025:1242
- https://access.redhat.com/errata/RHSA-2025:1433
- https://access.redhat.com/errata/RHSA-2025:1434
- https://access.redhat.com/errata/RHSA-2025:1437
- https://access.redhat.com/errata/RHSA-2025:1386
- https://access.redhat.com/errata/RHSA-2025:1403
- https://access.redhat.com/errata/RHSA-2025:1451
- https://access.redhat.com/errata/RHSA-2025:1453
- https://access.redhat.com/errata/RHSA-2025:1657
- https://access.redhat.com/errata/RHSA-2025:1658
- https://access.redhat.com/errata/RHSA-2025:1659
- https://access.redhat.com/errata/RHSA-2025:1662
- https://access.redhat.com/errata/RHSA-2025:1663
- https://access.redhat.com/errata/RHSA-2025:1680
漏洞識別碼
- CVE-2023-52490
- CVE-2023-52679
- CVE-2024-11218
- CVE-2024-12085
- CVE-2024-23307
- CVE-2024-26924
- CVE-2024-26935
- CVE-2024-26960
- CVE-2024-27011
- CVE-2024-27012
- CVE-2024-27017
- CVE-2024-35824
- CVE-2024-35876
- CVE-2024-36954
- CVE-2024-45337
- CVE-2024-45338
- CVE-2024-46695
- CVE-2024-50110
- CVE-2024-50142
- CVE-2024-50256
- CVE-2024-50275
- CVE-2024-52336
- CVE-2024-52337
- CVE-2024-53104
- CVE-2024-53113
- CVE-2024-56326
資料來源
相關連結
- https://access.redhat.com/errata/RHSA-2025:1067
- https://access.redhat.com/errata/RHSA-2025:1068
- https://access.redhat.com/errata/RHSA-2025:1230
- https://access.redhat.com/errata/RHSA-2025:1231
- https://access.redhat.com/errata/RHSA-2025:1253
- https://access.redhat.com/errata/RHSA-2025:1254
- https://access.redhat.com/errata/RHSA-2025:1264
- https://access.redhat.com/errata/RHSA-2025:1262
- https://access.redhat.com/errata/RHSA-2025:1266
- https://access.redhat.com/errata/RHSA-2025:1267
- https://access.redhat.com/errata/RHSA-2025:1268
- https://access.redhat.com/errata/RHSA-2025:1269
- https://access.redhat.com/errata/RHSA-2025:1270
- https://access.redhat.com/errata/RHSA-2025:1278
- https://access.redhat.com/errata/RHSA-2025:1280
- https://access.redhat.com/errata/RHSA-2025:1281
- https://access.redhat.com/errata/RHSA-2025:1282
- https://access.redhat.com/errata/RHSA-2025:1291
- https://access.redhat.com/errata/RHSA-2025:1347
- https://access.redhat.com/errata/RHSA-2025:1374
- https://access.redhat.com/errata/RHSA-2025:1242
- https://access.redhat.com/errata/RHSA-2025:1433
- https://access.redhat.com/errata/RHSA-2025:1434
- https://access.redhat.com/errata/RHSA-2025:1437
- https://access.redhat.com/errata/RHSA-2025:1386
- https://access.redhat.com/errata/RHSA-2025:1403
- https://access.redhat.com/errata/RHSA-2025:1451
- https://access.redhat.com/errata/RHSA-2025:1453
- https://access.redhat.com/errata/RHSA-2025:1657
- https://access.redhat.com/errata/RHSA-2025:1658
- https://access.redhat.com/errata/RHSA-2025:1659
- https://access.redhat.com/errata/RHSA-2025:1662
- https://access.redhat.com/errata/RHSA-2025:1663
- https://access.redhat.com/errata/RHSA-2025:1680
分享至