RHSA-2021:1377: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374) kernel: out-of-bounds read in libiscsi module (CVE-2021-27364) kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:1377?
The severity of RHSA-2021:1377 is classified as important due to potential exploitation risks from the kernel vulnerabilities.
How do I fix RHSA-2021:1377?
To resolve RHSA-2021:1377, you should update the kpatch-patch package to one of the remedied versions specified in the advisory.
What vulnerabilities are addressed in RHSA-2021:1377?
RHSA-2021:1377 addresses multiple vulnerabilities including CVE-2020-28374 which relates to an out-of-bounds write issue.
Which Red Hat versions are affected by RHSA-2021:1377?
Versions of kpatch-patch prior to 3_10_0-957_70_1-1-2.el7 are affected by RHSA-2021:1377.
Is there a risk of data loss due to RHSA-2021:1377?
Yes, exploitation of the vulnerabilities in RHSA-2021:1377 may lead to potential data loss or corruption if not properly mitigated.