First published: Tue Apr 06 2021(Updated: )
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.<br>Security Fix(es):<br><li> kernel: out-of-bounds read in libiscsi module (CVE-2021-27364)</li> <li> kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kpatch-patch | <3_10_0-1160-1-5.el7 | 3_10_0-1160-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_11_1-1-4.el7 | 3_10_0-1160_11_1-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_15_2-1-4.el7 | 3_10_0-1160_15_2-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_21_1-1-2.el7 | 3_10_0-1160_21_1-1-2.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_1-1-5.el7 | 3_10_0-1160_2_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_2-1-5.el7 | 3_10_0-1160_2_2-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_6_1-1-5.el7 | 3_10_0-1160_6_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160-1-5.el7 | 3_10_0-1160-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160-debuginfo-1-5.el7 | 3_10_0-1160-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_11_1-1-4.el7 | 3_10_0-1160_11_1-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_11_1-debuginfo-1-4.el7 | 3_10_0-1160_11_1-debuginfo-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_15_2-1-4.el7 | 3_10_0-1160_15_2-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_15_2-debuginfo-1-4.el7 | 3_10_0-1160_15_2-debuginfo-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_21_1-1-2.el7 | 3_10_0-1160_21_1-1-2.el7 |
redhat/kpatch-patch | <3_10_0-1160_21_1-debuginfo-1-2.el7 | 3_10_0-1160_21_1-debuginfo-1-2.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_1-1-5.el7 | 3_10_0-1160_2_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_1-debuginfo-1-5.el7 | 3_10_0-1160_2_1-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_2-1-5.el7 | 3_10_0-1160_2_2-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_2-debuginfo-1-5.el7 | 3_10_0-1160_2_2-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_6_1-1-5.el7 | 3_10_0-1160_6_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_6_1-debuginfo-1-5.el7 | 3_10_0-1160_6_1-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160-1-5.el7 | 3_10_0-1160-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160-debuginfo-1-5.el7 | 3_10_0-1160-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_11_1-1-4.el7 | 3_10_0-1160_11_1-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_11_1-debuginfo-1-4.el7 | 3_10_0-1160_11_1-debuginfo-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_15_2-1-4.el7 | 3_10_0-1160_15_2-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_15_2-debuginfo-1-4.el7 | 3_10_0-1160_15_2-debuginfo-1-4.el7 |
redhat/kpatch-patch | <3_10_0-1160_21_1-1-2.el7 | 3_10_0-1160_21_1-1-2.el7 |
redhat/kpatch-patch | <3_10_0-1160_21_1-debuginfo-1-2.el7 | 3_10_0-1160_21_1-debuginfo-1-2.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_1-1-5.el7 | 3_10_0-1160_2_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_1-debuginfo-1-5.el7 | 3_10_0-1160_2_1-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_2-1-5.el7 | 3_10_0-1160_2_2-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_2_2-debuginfo-1-5.el7 | 3_10_0-1160_2_2-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_6_1-1-5.el7 | 3_10_0-1160_6_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-1160_6_1-debuginfo-1-5.el7 | 3_10_0-1160_6_1-debuginfo-1-5.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:1069 is classified as important.
To fix RHSA-2021:1069, apply the latest kernel live patch provided by Red Hat for the package kpatch-patch.
RHSA-2021:1069 addresses an out-of-bounds read in the libiscsi module and a heap buffer overflow in the iSCSI subsystem.
The affected systems include those using kpatch-patch versions prior to 3_10_0-1160-1-5.el7 on Red Hat Enterprise Linux.
Not addressing RHSA-2021:1069 could lead to potential exploitation of the out-of-bounds read and heap buffer overflow vulnerabilities.