RHSA-2021:0136: Moderate: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: soft-lockups in iovitercopyfromuseratomic() could result in DoS (CVE-2020-25641) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the latest RHEL-8.2.z6 Batch source tree (BZ#1902783)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0136?
The severity of RHSA-2021:0136 is classified as moderate.
How do I fix RHSA-2021:0136?
To fix RHSA-2021:0136, update your kernel-rt packages to version 4.18.0-193.40.1.rt13.90.el8_2.
What vulnerability is addressed in RHSA-2021:0136?
RHSA-2021:0136 addresses a DoS vulnerability due to soft-lockups in iov_iter_copy_from_user_atomic() (CVE-2020-25641).
Which packages are affected by RHSA-2021:0136?
The affected packages include kernel-rt, kernel-rt-core, kernel-rt-debug, and several other kernel-rt related packages.
Is there a specific version I need to upgrade to for RHSA-2021:0136?
Yes, you need to upgrade to kernel-rt version 4.18.0-193.40.1.rt13.90.el8_2 to mitigate the vulnerability.