RHSA-2022:1103: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1103?
The severity of RHSA-2022:1103 is classified as critical due to potential local privilege escalation vulnerabilities.
How do I fix RHSA-2022:1103?
To fix RHSA-2022:1103, you should update to the latest version of the kpatch-patch package specified in the advisory.
What vulnerabilities are addressed in RHSA-2022:1103?
RHSA-2022:1103 addresses a Use After Free vulnerability in unix_gc() which can lead to local privilege escalation.
Which software packages are affected by RHSA-2022:1103?
The affected software packages include various versions of the kpatch-patch package for Red Hat Enterprise Linux 7.
Is it safe to ignore RHSA-2022:1103?
No, it is not safe to ignore RHSA-2022:1103 as it poses a significant security risk due to privilege escalation possibilities.