RHSA-2022:1373: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Use After Free in unixgc() which could result in a local privilege escalation (CVE-2021-0920) kernel: use-after-free in RDMA listen() (CVE-2021-4028) kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1373?
The severity of RHSA-2022:1373 is considered critical due to a use-after-free vulnerability that could lead to local privilege escalation.
How do I fix RHSA-2022:1373?
To fix RHSA-2022:1373, update the kpatch-patch package to one of the patched versions listed in the advisory.
What systems are affected by RHSA-2022:1373?
RHSA-2022:1373 affects specific versions of the kpatch-patch package on Red Hat Enterprise Linux 7 systems.
What is the CVE associated with RHSA-2022:1373?
RHSA-2022:1373 addresses the vulnerabilities identified by CVE-2021-0920.
Is a reboot required after applying RHSA-2022:1373?
A reboot may be necessary after applying RHSA-2022:1373 to ensure that the updated kernel live patch is fully effective.