RHSA-2021:4000: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Improper handling of VMIO|VMPFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543) kernel: powerpc: KVM guest OS users can cause host OS memory corruption (CVE-2021-37576) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:4000?
The severity of RHSA-2021:4000 is classified as important due to improper handling of VM_IO|VM_PFNMAP vmas in KVM.
How do I fix RHSA-2021:4000?
To fix RHSA-2021:4000, upgrade the kpatch-patch package to one of the specified remedied versions such as 3_10_0-1062_40_1-1-6.el7 or above.
Which systems are affected by RHSA-2021:4000?
RHSA-2021:4000 affects systems running the Red Hat Enterprise Linux kernel versions specified in the advisory.
What vulnerabilities are addressed in RHSA-2021:4000?
RHSA-2021:4000 addresses vulnerability CVE-2021-22543 related to improper handling in KVM.
Is a reboot required after applying RHSA-2021:4000?
A reboot may be required to fully apply the necessary changes after upgrading the kpatch-patch package for RHSA-2021:4000.