RHSA-2020:4331: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: metadata validator in XFS may cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt (CVE-2020-14385) kernel: memory corruption in net/packet/afpacket.c leads to elevation of privilege (CVE-2020-14386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193-1-7.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_13_2-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_14_3-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_19_1-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_1_2-1-5.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_6_3-1-4.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193-debuginfo-1-7.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193-debugsource-1-7.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_13_2-debuginfo-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_13_2-debugsource-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_14_3-debuginfo-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_14_3-debugsource-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_19_1-debuginfo-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_19_1-debugsource-1-2.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_1_2-debuginfo-1-5.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_1_2-debugsource-1-5.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_6_3-debuginfo-1-4.el8_2 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-193_6_3-debugsource-1-4.el8_2
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4331?
The severity of RHSA-2020:4331 is considered moderate as it addresses a vulnerability in the kernel live patch module.
How do I fix RHSA-2020:4331?
To fix RHSA-2020:4331, you should update your kpatch-patch package to the recommended versions specified in the advisory.
Which versions of kpatch-patch are affected by RHSA-2020:4331?
RHSA-2020:4331 affects multiple versions of kpatch-patch, and specific versions are listed in the advisory.
What types of issues does RHSA-2020:4331 address?
RHSA-2020:4331 addresses a vulnerability in the XFS file system's metadata validator that may incorrectly flag inodes.
Is it safe to ignore the patch for RHSA-2020:4331?
It is not safe to ignore the patch for RHSA-2020:4331, as failing to apply the update may leave your system vulnerable to exploitation.