RHSA-2022:0772: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: use-after-free in RDMA listen() (CVE-2021-4028) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305-1-11.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_10_2-1-8.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_12_1-1-7.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_17_1-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_19_1-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_25_1-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_28_1-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_30_1-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_34_2-1-1.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_3_1-1-10.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_7_1-1-9.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305-debuginfo-1-11.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305-debugsource-1-11.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_10_2-debuginfo-1-8.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_10_2-debugsource-1-8.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_12_1-debuginfo-1-7.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_12_1-debugsource-1-7.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_17_1-debuginfo-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_17_1-debugsource-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_19_1-debuginfo-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_19_1-debugsource-1-6.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_25_1-debuginfo-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_25_1-debugsource-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_28_1-debuginfo-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_28_1-debugsource-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_30_1-debuginfo-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_30_1-debugsource-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_34_2-debuginfo-1-1.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_34_2-debugsource-1-1.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_3_1-debuginfo-1-10.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_3_1-debugsource-1-10.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_7_1-debuginfo-1-9.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_7_1-debugsource-1-9.el8_4 - Compensating control
Apply the kpatch-patch security update so the kernel live patch module is installed and automatically loaded by the RPM post-install script to modify the code of a running kernel.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0772?
The severity of RHSA-2022:0772 is classified as important due to the potential for local privilege escalation.
How do I fix RHSA-2022:0772?
To fix RHSA-2022:0772, you should update the kpatch-patch package to a version that includes the security fix.
What vulnerability does RHSA-2022:0772 address?
RHSA-2022:0772 addresses a use after free vulnerability in unix_gc() that could lead to local privilege escalation.
Which systems are affected by RHSA-2022:0772?
RHSA-2022:0772 affects systems running specific versions of the kpatch-patch package on Red Hat Enterprise Linux 8.
Is there a workaround for RHSA-2022:0772?
There are no specific workarounds for RHSA-2022:0772, the recommended action is to apply the available updates.