RHSA-2021:3375: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.<br>Security Fix(es):<br><li> kernel: race condition in net/can/bcm.c leads to local privilege escalation (CVE-2021-3609)</li> <li> kernel: Improper handling of VMIO|VMPFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543)</li> <li> kernel: out-of-bounds write in xtcompattargetfromuser() in net/netfilter/xtables.c (CVE-2021-22555)</li> <li> kernel: race condition for removal of the HCI controller (CVE-2021-32399)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> kernel-rt: update RT source tree to the latest RHEL-8.2.z11 Batch source tree (BZ#1984586)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3375?
The severity of RHSA-2021:3375 is critical due to the local privilege escalation vulnerability (CVE-2021-3609).
How do I fix RHSA-2021:3375?
To fix RHSA-2021:3375, update to kernel-rt version 4.18.0-193.64.1.rt13.115.el8_2 or newer.
What vulnerability does RHSA-2021:3375 address?
RHSA-2021:3375 addresses a race condition in net/can/bcm.c that leads to local privilege escalation.
What components are affected by RHSA-2021:3375?
RHSA-2021:3375 affects multiple kernel-rt packages including kernel-rt, kernel-rt-core, and kernel-rt-debug among others.
Is mitigation available for RHSA-2021:3375?
The best mitigation for RHSA-2021:3375 is to promptly update to the specified kernel-rt version.