RHSA-2022:1975: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: avoid cyclic entity chains due to malformed USB descriptors (CVE-2020-0404) kernel: integer overflow in kascii() in drivers/tty/vt/keyboard.c (CVE-2020-13974) kernel: out-of-bounds read in bpfskbchangehead() of filter.c due to a use-after-free (CVE-2021-0941) kernel: joydev: zero size passed to joydevhandleJSIOCSBTNMAP() (CVE-2021-3612) kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts (CVE-2021-3669) kernel: out-of-bound Read in qrtrendpointpost in net/qrtr/qrtr.c (CVE-2021-3743) kernel: crypto: ccp - fix resource leaks in ccprunaesgcmcmd() (CVE-2021-3744) kernel: possible use-after-free in bluetooth module (CVE-2021-3752) kernel: unaccounted ipc objects in Linux kernel lead to breaking memcg limits and DoS attacks (CVE-2021-3759) kernel: DoS in ccprunaesgcmcmd() function (CVE-2021-3764) kernel: sctp: Invalid chunks may be used to remotely remove existing associations (CVE-2021-3772) kernel: lack of port sanity checking in natd and netfilter leads to exploit of OpenVPN clients (CVE-2021-3773) kernel: possible leak or coruption of data residing on hugetlbfs (CVE-2021-4002) kernel: security regression for CVE-2018-13405 (CVE-2021-4037) kernel: Buffer overwrite in decodenfsfh function (CVE-2021-4157) kernel: cgroup: Use open-time creds and namespace for migration perm checks (CVE-2021-4197) kernel: Race condition in races in skpeerpid and skpeercred accesses (CVE-2021-4203) kernel: new DNS Cache Poisoning Attack based on ICMP fragment needed packets replies (CVE-2021-20322) hw: cpu: LFENCE/JMP Mitigation Update for CVE-2017-5715 (CVE-2021-26401) kernel: Local privilege escalation due to incorrect BPF JIT branch displacement computation (CVE-2021-29154) kernel: use-after-free in hsofreenetdevice() in drivers/net/usb/hso.c (CVE-2021-37159) kernel: eBPF multiplication integer overflow in preallocelemsandfreelist() in kernel/bpf/stackmap.c leads to out-of-bounds write (CVE-2021-41864) kernel: Heap buffer overflow in firedtv driver (CVE-2021-42739) kernel: an array-index-out-bounds in detachcapictr in drivers/isdn/capi/kcapi.c (CVE-2021-43389) kernel: mwifiexusbrecv() in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker to cause DoS via crafted USB device (CVE-2021-43976) kernel: use-after-free in the TEE subsystem (CVE-2021-44733) kernel: information leak in the IPv6 implementation (CVE-2021-45485) kernel: information leak in the IPv4 implementation (CVE-2021-45486) hw: cpu: intel: Branch History Injection (BHI) (CVE-2022-0001) hw: cpu: intel: Intra-Mode BTI (CVE-2022-0002) kernel: Local denial of service in bondipsecaddsa (CVE-2022-0286) kernel: DoS in sctpaddtochunk in net/sctp/smmakechunk.c (CVE-2022-0322) kernel: FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes (CVE-2022-1011) kernel: use-after-free in nouveau kernel module (CVE-2020-27820) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1975?
The severity of RHSA-2022:1975 is considered moderate due to the potential impact of the reported vulnerabilities.
How do I fix RHSA-2022:1975?
To fix RHSA-2022:1975, update the kernel-rt packages to version 4.18.0-372.9.1.rt7.166.el8 or higher.
What vulnerabilities are addressed in RHSA-2022:1975?
RHSA-2022:1975 addresses vulnerabilities including CVE-2021-4083, which relates to file descriptor management.
Which packages are affected by RHSA-2022:1975?
The RHSA-2022:1975 vulnerability affects several kernel-rt related packages, including kernel-rt, kernel-rt-core, and kernel-rt-debug.
Is there a specific version I need to upgrade to for RHSA-2022:1975?
Yes, you need to upgrade to version 4.18.0-372.9.1.rt7.166.el8 specifically to mitigate the vulnerabilities found in RHSA-2022:1975.