RHSA-2022:1455: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) kernel: cgroups v1 releaseagent feature may allow privilege escalation (CVE-2022-0492) kernel: heap out of bounds write in nfdupnetdev.c (CVE-2022-25636) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fixes: Power10 PMU fix for PMCYC/PMINSTCMPL ( kernel/perf) (BZ#2040665) call traces and packet drops seen after changing mtu of ibmvnic interface. (ibmvnic/ P10/ Everglade) (BZ#2050679) zfcp: fix failed recovery on gone remote port, non-NPIV FCP dev (BZ#2050739) overlay mount fails with ELOOP (Too many levels of symbolic links) (BZ#2053030) Host unable to automatically add namespaces belonging to a new ANA group (BZ#2055466) scheduler updates and fixes [None8.4.0.z] (BZ#2056834) nfreinject calls nfqueueentryfree on an already freed entry->state (BZ#2061445) First Packet Latency impacted by mlx5 warning msg (BZ#2067992) openvswitch connection tracking sends incorrect flow key for some upcalls (BZ#2068477) Backport upstream rcu commits up to v5.10 (BZ#2069819) Packages have been upgraded to a later upstream version: kernel (4.18.0) (BZ#2036932) Enhancement: zcrypt DD: Toleration for new IBM Z Crypto Hardware (BZ#2054097)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.45.1.el8_4.aa - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Fixed in 4.18.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2036932 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2056834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2040665 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2069819 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2067992 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2055466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2061445 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2068477 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2053030 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2050739 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2054097 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2050679 - Configuration
Reboot the system for this update to take effect (required by the advisory).
Linux kernel reboot_required_for_update = true
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1455?
The severity of RHSA-2022:1455 is categorized as critical due to the potential for privilege escalation and denial of service.
How do I fix RHSA-2022:1455?
To fix RHSA-2022:1455, you need to update to the kernel packages version 4.18.0-305.45.1.el8_4 or later.
Which systems are affected by RHSA-2022:1455?
RHSA-2022:1455 affects multiple versions of the Red Hat Enterprise Linux kernel and associated packages.
What vulnerabilities are addressed in RHSA-2022:1455?
RHSA-2022:1455 addresses vulnerabilities including CVE-2021-4083 which allows for checking file descriptor validity.
Is RHSA-2022:1455 related to Linux kernel security?
Yes, RHSA-2022:1455 is specifically related to vulnerabilities within the Linux kernel impacting system security.