First published: Tue Oct 12 2021(Updated: )
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.<br>Security Fix(es):<br><li> kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543)</li> <li> kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555)</li> <li> kernel: powerpc: KVM guest OS users can cause host OS memory corruption (CVE-2021-37576)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kpatch-patch | <3_10_0-957_61_1-1-6.el7 | 3_10_0-957_61_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_2-1-6.el7 | 3_10_0-957_61_2-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_62_1-1-6.el7 | 3_10_0-957_62_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_65_1-1-6.el7 | 3_10_0-957_65_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_66_1-1-6.el7 | 3_10_0-957_66_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_70_1-1-5.el7 | 3_10_0-957_70_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-957_72_1-1-3.el7 | 3_10_0-957_72_1-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_76_1-1-3.el7 | 3_10_0-957_76_1-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_78_2-1-2.el7 | 3_10_0-957_78_2-1-2.el7 |
redhat/kpatch-patch | <3_10_0-957_80_1-1-1.el7 | 3_10_0-957_80_1-1-1.el7 |
redhat/kpatch-patch | <3_10_0-957_61_1-1-6.el7 | 3_10_0-957_61_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_1-debuginfo-1-6.el7 | 3_10_0-957_61_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_2-1-6.el7 | 3_10_0-957_61_2-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_2-debuginfo-1-6.el7 | 3_10_0-957_61_2-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_62_1-1-6.el7 | 3_10_0-957_62_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_62_1-debuginfo-1-6.el7 | 3_10_0-957_62_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_65_1-1-6.el7 | 3_10_0-957_65_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_65_1-debuginfo-1-6.el7 | 3_10_0-957_65_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_66_1-1-6.el7 | 3_10_0-957_66_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_66_1-debuginfo-1-6.el7 | 3_10_0-957_66_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_70_1-1-5.el7 | 3_10_0-957_70_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-957_70_1-debuginfo-1-5.el7 | 3_10_0-957_70_1-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-957_72_1-1-3.el7 | 3_10_0-957_72_1-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_72_1-debuginfo-1-3.el7 | 3_10_0-957_72_1-debuginfo-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_76_1-1-3.el7 | 3_10_0-957_76_1-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_76_1-debuginfo-1-3.el7 | 3_10_0-957_76_1-debuginfo-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_78_2-1-2.el7 | 3_10_0-957_78_2-1-2.el7 |
redhat/kpatch-patch | <3_10_0-957_78_2-debuginfo-1-2.el7 | 3_10_0-957_78_2-debuginfo-1-2.el7 |
redhat/kpatch-patch | <3_10_0-957_80_1-1-1.el7 | 3_10_0-957_80_1-1-1.el7 |
redhat/kpatch-patch | <3_10_0-957_80_1-debuginfo-1-1.el7 | 3_10_0-957_80_1-debuginfo-1-1.el7 |
redhat/kpatch-patch | <3_10_0-957_61_1-1-6.el7 | 3_10_0-957_61_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_1-debuginfo-1-6.el7 | 3_10_0-957_61_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_2-1-6.el7 | 3_10_0-957_61_2-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_61_2-debuginfo-1-6.el7 | 3_10_0-957_61_2-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_62_1-1-6.el7 | 3_10_0-957_62_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_62_1-debuginfo-1-6.el7 | 3_10_0-957_62_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_65_1-1-6.el7 | 3_10_0-957_65_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_65_1-debuginfo-1-6.el7 | 3_10_0-957_65_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_66_1-1-6.el7 | 3_10_0-957_66_1-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_66_1-debuginfo-1-6.el7 | 3_10_0-957_66_1-debuginfo-1-6.el7 |
redhat/kpatch-patch | <3_10_0-957_70_1-1-5.el7 | 3_10_0-957_70_1-1-5.el7 |
redhat/kpatch-patch | <3_10_0-957_70_1-debuginfo-1-5.el7 | 3_10_0-957_70_1-debuginfo-1-5.el7 |
redhat/kpatch-patch | <3_10_0-957_72_1-1-3.el7 | 3_10_0-957_72_1-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_72_1-debuginfo-1-3.el7 | 3_10_0-957_72_1-debuginfo-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_76_1-1-3.el7 | 3_10_0-957_76_1-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_76_1-debuginfo-1-3.el7 | 3_10_0-957_76_1-debuginfo-1-3.el7 |
redhat/kpatch-patch | <3_10_0-957_78_2-1-2.el7 | 3_10_0-957_78_2-1-2.el7 |
redhat/kpatch-patch | <3_10_0-957_78_2-debuginfo-1-2.el7 | 3_10_0-957_78_2-debuginfo-1-2.el7 |
redhat/kpatch-patch | <3_10_0-957_80_1-1-1.el7 | 3_10_0-957_80_1-1-1.el7 |
redhat/kpatch-patch | <3_10_0-957_80_1-debuginfo-1-1.el7 | 3_10_0-957_80_1-debuginfo-1-1.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2021:3814 is classified as a critical vulnerability due to its potential impact on kernel security.
To fix RHSA-2021:3814, update the kpatch-patch package to the recommended versions provided by Red Hat.
RHSA-2021:3814 addresses vulnerabilities in KVM that allow bypassing read-only checks, notably CVE-2021-22543.
RHSA-2021:3814 affects various Red Hat Enterprise Linux 7 systems using specific versions of the kpatch-patch package.
There is no specified workaround for RHSA-2021:3814 other than applying the security updates.