RHSA-2022:0823: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: improper initialization of the "flags" member of the new pipebuffer (CVE-2022-0847) kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: use-after-free in RDMA listen() (CVE-2021-4028) kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: cgroups v1 releaseagent feature may allow privilege escalation (CVE-2022-0492) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0823?
The severity of RHSA-2022:0823 is considered moderate due to improper initialization and potential use-after-free vulnerabilities.
How do I fix RHSA-2022:0823?
To fix RHSA-2022:0823, update your kernel packages to version 4.18.0-147.64.1.el8_1 or later.
What vulnerabilities are addressed in RHSA-2022:0823?
RHSA-2022:0823 addresses a vulnerability related to improper initialization and a use-after-free issue in the Linux kernel.
Which systems are affected by RHSA-2022:0823?
Systems running the affected kernel versions up to 4.18.0-147.64.1.el8_1 are impacted by RHSA-2022:0823.
Are there any workarounds for RHSA-2022:0823?
There are no specific workarounds recommended for RHSA-2022:0823; applying the update is the best course of action.