RHSA-2022:0620: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466) kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: xfs: raw block device data leak in XFSIOCALLOCSP IOCTL (CVE-2021-4155) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) kernel: out of bounds write in hid-multitouch.c may lead to escalation of privilege (CVE-2020-0465) kernel: double free in bluetooth subsystem when the HCI device initialization fails (CVE-2021-3564) kernel: use-after-free in function hcisockboundioctl() (CVE-2021-3573) kernel: possible use-after-free in bluetooth module (CVE-2021-3752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Kernel with enabled BERT does not decode CPU fatal events correctly (BZ#1950302) RHEL 7.9 - Call trace seen during controller random reset on IB config (BZ#1984070) Infinite loop in blksetqueuedying() from blkqueueforeachrl() when another CPU races and modifies the queue's blkglist (BZ#2029574) NFS client kernel crash in NFS4 backchannel transmit path - ftraceraweventrpctaskqueued called from rpcrunbctask (BZ#2039508) SELinux is preventing / from mount access on the filesystem /proc (BZ#2040196)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0620?
The severity of RHSA-2022:0620 is classified as important due to potential escalation of privilege vulnerabilities.
How do I fix RHSA-2022:0620?
To fix RHSA-2022:0620, update the affected kernel packages to version 3.10.0-1160.59.1.el7 or later.
What vulnerabilities are addressed in RHSA-2022:0620?
RHSA-2022:0620 addresses a use-after-free vulnerability in eventpoll.c and another use-after-free vulnerability in unix_gc().
What systems are affected by RHSA-2022:0620?
Systems running Red Hat Enterprise Linux 7 with kernel versions prior to 3.10.0-1160.59.1.el7 are affected by RHSA-2022:0620.
Is RHSA-2022:0620 related to CVE-2020-0466?
Yes, RHSA-2022:0620 includes a fix for the vulnerability CVE-2020-0466, which is a use-after-free issue.