RHSA-2022:1413: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: cgroups v1 releaseagent feature may allow privilege escalation (CVE-2022-0492) kernel: heap out of bounds write in nfdupnetdev.c (CVE-2022-25636) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the RHEL-8.4.z8 source tree (BZ#2059334)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1413?
The severity of RHSA-2022:1413 is classified as critical due to vulnerabilities in the kernel-rt packages.
How do I fix RHSA-2022:1413?
To fix RHSA-2022:1413, update the kernel-rt packages to version 4.18.0-305.45.1.rt7.117.el8_4 or later.
What vulnerabilities are addressed by RHSA-2022:1413?
RHSA-2022:1413 addresses vulnerabilities such as CVE-2021-4083 related to file descriptor handling.
Which systems are affected by RHSA-2022:1413?
RHSA-2022:1413 affects systems using the kernel-rt packages that are less than version 4.18.0-305.45.1.rt7.117.el8_4.
Is there a specific package I need to update for RHSA-2022:1413?
Yes, the specific packages to update for RHSA-2022:1413 include kernel-rt, kernel-rt-core, and associated kernel-rt debugging packages.