RHSA-2022:0231: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154) kernel: xfs: raw block device data leak in XFSIOCALLOCSP IOCTL (CVE-2021-4155) kernel: fscontext: heap overflow in legacy parameter handling (CVE-2022-0185) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305-1-10.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_10_2-1-7.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_12_1-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_17_1-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_19_1-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_25_1-1-4.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_28_1-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_30_1-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_3_1-1-9.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_7_1-1-8.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305-debuginfo-1-10.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305-debugsource-1-10.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_10_2-debuginfo-1-7.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_10_2-debugsource-1-7.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_12_1-debuginfo-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_12_1-debugsource-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_17_1-debuginfo-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_17_1-debugsource-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_19_1-debuginfo-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_19_1-debugsource-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_25_1-debuginfo-1-4.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_25_1-debugsource-1-4.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_28_1-debuginfo-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_28_1-debugsource-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_30_1-debuginfo-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_30_1-debugsource-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_3_1-debuginfo-1-9.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_3_1-debugsource-1-9.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_7_1-debuginfo-1-8.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_7_1-debugsource-1-8.el8_4 - Upgrade
Upgrade
kpatch-patchto a version that resolves this vulnerability.Patch CVE-2022-0185 - Upgrade
Upgrade
kpatch-patchto a version that resolves this vulnerability.Patch CVE-2021-4155 - Upgrade
Upgrade
kpatch-patchto a version that resolves this vulnerability.Patch CVE-2021-4154
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0231?
The severity of RHSA-2022:0231 is considered high due to the potential for local privilege escalation resulting from a vulnerability in the kernel.
How do I fix RHSA-2022:0231?
To fix RHSA-2022:0231, update the kpatch-patch package to one of the remedied versions listed in the advisory.
What systems are affected by RHSA-2022:0231?
RHSA-2022:0231 affects systems running specific versions of the kpatch-patch package on Red Hat Enterprise Linux 8.
What is the nature of the vulnerability in RHSA-2022:0231?
The vulnerability involves a local privilege escalation through the exploitation of the fsconfig syscall parameter leading to container breakout.
When was RHSA-2022:0231 published?
RHSA-2022:0231 was published on March 9, 2022.