RHSA-2022:0825: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.The following packages have been upgraded to a later upstream version: kernel (4.18.0). (BZ#2036888)Security Fix(es): kernel: improper initialization of the "flags" member of the new pipebuffer (CVE-2022-0847) kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435) kernel: cgroups v1 releaseagent feature may allow privilege escalation (CVE-2022-0492) kernel: missing check in ioctl allows kernel memory read/write (CVE-2022-0516) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Intel QAT Kernel power up fix (BZ#2016437) RHEL8.4 seeing scsidmamap failed with mpt3sas driver and affecting performance (BZ#2018928) [Lenovo 8.4 bug] audioHDMI certification failed on RHEL 8.4GA (No hdmi out) (BZ#2027335) [RHEL-8.5][4.18.0-323.el8.ppc64le][POWER8/9/10] securityflavor mode is not set back to zero post online migration (BZ#2027448) iommu/amd: Fix unable to handle page fault due to AVIC (BZ#2030854) [Lenovo 8.4 bug]The VGA display shows no signal (black screen) when install RHEL8.4(beta or rc1) in the legacy BIOS mode. (BZ#2034949) Double free of kmalloc-64 cache struct ibport->pkeygroup from module ibcore . (BZ#2038724) Bus error with huge pages enabled (BZ#2039015) RHEL8 - kvm: floating interrupts may get stuck (BZ#2040769) Data corruption on small files served by httpd, which is backed by cifs-mount (BZ#2041529) Add a net/mlx5 patch for Hardware Offload Fix (BZ#2042663) Windows guest random Bsod when 'hv-tlbflush' enlightenment is enabled (BZ#2043237) DNS lookup failures when run two times in a row (BZ#2043548) net/sched: Fix ct zone matching for invalid conntrack state (BZ#2043550) Kernel 4.18.0-348.2.1 secpathcache memory leak involving strongswan tunnel (BZ#2047427) OCP node XFS metadata corruption after numerous reboots (BZ#2049292) Broadcom bnxtre: RDMA stats are not incrementing (BZ#2049684) ice: bug fix series for 8.6 (BZ#2051951) panic while looking up a symlink due to NULL iop->getlink (BZ#2052558) ceph omnibus backport for RHEL-8.6.0 (BZ#2053725) SCTP peel-off with SELinux and containers in OCP (BZ#2054112) Selinux is not allowing SCTP connection setup between inter pod communication in enforcing mode (BZ#2054117) dnf fails with fsync() over local repository present on CIFS mount point (BZ#2055824)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0825?
The severity of RHSA-2022:0825 is classified as important.
How do I fix RHSA-2022:0825?
To fix RHSA-2022:0825, you should update the affected kernel packages to version 4.18.0-348.20.1.el8_5.
Which packages are affected by RHSA-2022:0825?
The affected packages for RHSA-2022:0825 include kernel, bpftool, and several kernel-related packages.
What vulnerabilities does RHSA-2022:0825 address?
RHSA-2022:0825 addresses an improper initialization vulnerability in the Linux kernel.
Is RHSA-2022:0825 applicable to all Red Hat systems?
RHSA-2022:0825 is applicable specifically to Red Hat Enterprise Linux 8.