RHSA-2022:0849: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435) kernel: cgroups v1 releaseagent feature may allow privilege escalation (CVE-2022-0492) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348-1-3.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_12_2-1-1.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_2_1-1-2.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_7_1-1-2.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348-debuginfo-1-3.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348-debugsource-1-3.el8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_12_2-debuginfo-1-1.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_12_2-debugsource-1-1.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_2_1-debuginfo-1-2.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_2_1-debugsource-1-2.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_7_1-debuginfo-1-2.el8_5 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-348_7_1-debugsource-1-2.el8_5 - Upgrade
Upgrade
kpatch-patchto a version that resolves this vulnerability.Patch kpatch-patch security update - Compensating control
Apply the kpatch-patch kernel live patch update; it is automatically loaded by the RPM post-install script to modify the code of a running kernel.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0849?
The severity of RHSA-2022:0849 is classified as high due to the potential for local privilege escalation.
How do I fix RHSA-2022:0849?
To fix RHSA-2022:0849, update the kpatch-patch package to the recommended versions listed in the advisory.
What vulnerabilities are addressed in RHSA-2022:0849?
RHSA-2022:0849 addresses a use-after-free vulnerability in unix_gc() that may lead to local privilege escalation (CVE-2021-0920).
Which software packages are affected by RHSA-2022:0849?
Affected packages include various versions of the kpatch-patch package specifically for el8 and el8_5 distributions.
Is a reboot required after applying the fix for RHSA-2022:0849?
A reboot may be required after applying the fix for RHSA-2022:0849 to ensure that all components are properly updated.