Skip to content

Commit ec1bb3a

Browse files
authored
Merge pull request #293 from bottlerocket-os/advisories-20251014
advisories: Add BRSA for Kernel Kit 4.3.4
2 parents 92c039e + 33a7a91 commit ec1bb3a

22 files changed

+373
-0
lines changed
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-2uq7otsimmgp"
3+
title = "kernel CVE-2024-57924"
4+
cve = "CVE-2024-57924"
5+
severity = "moderate"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-4w6xuffmokzc"
3+
title = "kernel CVE-2025-39843"
4+
cve = "CVE-2025-39843"
5+
severity = "high"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: mm: slub: avoid wake up kswapd in set_track_prepare"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-byfuwryw5xtd"
3+
title = "kernel CVE-2025-39877"
4+
cve = "CVE-2025-39877"
5+
severity = "high"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix use-after-free in state_show()"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "4.3.4"
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
[advisory]
2+
id = "BRSA-bzvcguhwp93i"
3+
title = "Bottlerocket Kernel 6.1 Updates"
4+
severity = "high"
5+
description = "Kernel version 6.1.155 is now available with important fixes. All users must upgrade. Advisory information for kernel is often published after new kernels become available. Bottlerocket recommends that you consume the latest kernel release for your LTS version."
6+
7+
[[advisory.products]]
8+
package-name = "kernel-6.1"
9+
patched-version = "6.1.155"
10+
patched-epoch = "0"
11+
12+
[updateinfo]
13+
author = "yeazelm"
14+
issue-date = 2025-10-14T20:26:26Z
15+
arches = ["aarch64", "x86_64"]
16+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-dg8pyordlzru"
3+
title = "kernel CVE-2025-39866"
4+
cve = "CVE-2025-39866"
5+
severity = "high"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty()"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-g2zrqspdhtfg"
3+
title = "kernel CVE-2025-39909"
4+
cve = "CVE-2025-39909"
5+
severity = "moderate"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters()"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-gd6oibbnzngh"
3+
title = "kernel CVE-2025-23143"
4+
cve = "CVE-2025-23143"
5+
severity = "moderate"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod."
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-hc6rceo3sh1i"
3+
title = "kernel CVE-2025-39881"
4+
cve = "CVE-2025-39881"
5+
severity = "high"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is released"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-kmihpzxkzxec"
3+
title = "kernel CVE-2025-39902"
4+
cve = "CVE-2025-39902"
5+
severity = "high"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err()"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-kwnahsylgrmv"
3+
title = "kernel CVE-2025-39898"
4+
cve = "CVE-2025-39898"
5+
severity = "high"
6+
description = "In the Linux kernel, the following vulnerability has been resolved: e1000e: fix heap overflow in e1000_set_eeprom"
7+
8+
[[advisory.products]]
9+
package-name = "kernel-6.1"
10+
patched-version = "6.1.155"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "yeazelm"
15+
issue-date = 2025-10-14T20:26:26Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "4.3.4"

0 commit comments

Comments
 (0)