RHSA-2022:1209: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435) kernel: out-of-bounds read in in vcdoresize function in drivers/tty/vt/vt.c (CVE-2020-8647) kernel: invalid read location in vgaconinvertregion function in drivers/video/console/vgacon.c (CVE-2020-8649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the latest RHEL-8.2.z16 Batch (BZ#2066950)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1209?
The severity of RHSA-2022:1209 is classified as critical due to the potential for remote stack overflow that can lead to denial of service.
How do I fix RHSA-2022:1209?
To fix RHSA-2022:1209, you should update your kernel-rt packages to version 4.18.0-193.80.1.rt13.130.el8_2 or later.
What are the risks associated with RHSA-2022:1209?
The risks associated with RHSA-2022:1209 include potential denial of service attacks on systems using TIPC, which can disrupt system availability.
Which packages are affected by RHSA-2022:1209?
Affected packages include kernel-rt, kernel-rt-core, kernel-rt-debug, and several others within the Red Hat kernel-rt family.
What should I do if I can't update my kernel due to compatibility issues?
If you cannot update your kernel due to compatibility issues, consider reviewing your dependencies and testing updates in a staging environment before deployment.