RHSA-2022:1106: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.99.1.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1106?
RHSA-2022:1106 is classified as important due to the potential for local privilege escalation.
How do I fix RHSA-2022:1106?
You can fix RHSA-2022:1106 by updating to the latest kernel package version 3.10.0-514.99.1.el7 or later.
What vulnerabilities does RHSA-2022:1106 address?
RHSA-2022:1106 addresses a Use After Free vulnerability in unix_gc() and additional potential privilege escalation issues.
Which systems are affected by RHSA-2022:1106?
RHSA-2022:1106 affects Red Hat Enterprise Linux systems utilizing the kernel version 3.10.0-514.99.1.el7.
What are the consequences of not addressing RHSA-2022:1106?
Not addressing RHSA-2022:1106 could allow attackers to escalate privileges on affected systems, compromising security.