RHSA-2022:0592: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.<br>Security Fix(es):<br><li> kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466)</li> <li> kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920)</li> <li> kernel: xfs: raw block device data leak in XFSIOCALLOCSP IOCTL (CVE-2021-4155)</li> <li> kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330)</li> <li> kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0592?
The severity of RHSA-2022:0592 is classified as important due to the potential for privilege escalation.
What are the vulnerabilities addressed by RHSA-2022:0592?
RHSA-2022:0592 addresses multiple vulnerabilities, including a use-after-free issue in eventpoll.c (CVE-2020-0466) that may lead to privilege escalation.
How do I fix RHSA-2022:0592?
To fix RHSA-2022:0592, update the kpatch-patch package to the recommended versions ranging from 3_10_0-1160_21_1-1-9.el7 to 3_10_0-1160_53_1-1-1.el7.
Which systems are affected by RHSA-2022:0592?
RHSA-2022:0592 affects systems running the affected versions of the kpatch-patch package on Red Hat Enterprise Linux 7.
Is a reboot required after applying the RHSA-2022:0592 patch?
Yes, a reboot is recommended after applying the patches from RHSA-2022:0592 to ensure the kernel updates are fully enacted.