RHSA-2022:0958: Important: kpatch-patch-4_18_0-147_58_1 security and bug fix update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: use-after-free in RDMA listen() (CVE-2021-4028) kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: xfs: raw block device data leak in XFSIOCALLOCSP IOCTL (CVE-2021-4155) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: cgroups v1 releaseagent feature may allow privilege escalation (CVE-2022-0492) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Several kpatch CVEs needed for kernel-4.18.0-147.58.1.el81 (BZ#2064297)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0958?
RHSA-2022:0958 addresses a medium severity vulnerability related to a use-after-free issue that can lead to local privilege escalation.
How do I fix RHSA-2022:0958?
To fix RHSA-2022:0958, update the kpatch-patch package to version 4_18_0-147_58_1-1-1.el8_1 or later.
What vulnerabilities are addressed in RHSA-2022:0958?
RHSA-2022:0958 addresses a use-after-free vulnerability in unix_gc() identified by CVE-2021-0920.
Which systems are affected by RHSA-2022:0958?
RHSA-2022:0958 affects systems running specific versions of the kpatch-patch package on Red Hat Enterprise Linux.
Is there a workaround for RHSA-2022:0958?
No official workaround exists for RHSA-2022:0958; the recommended action is to apply the security update as soon as possible.