RHSA-2022:4829: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666) kernel: security regression for CVE-2018-13405 (CVE-2021-4037) kernel: new DNS Cache Poisoning Attack based on ICMP fragment needed packets replies (CVE-2021-20322) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel: Add support for CPU-MF counter second version 7 (BZ#2050686) BNXT driver logging added latency tc-hw-offload (BZ#2059860) RHEL 8 not disabling the qla2x00timer() when the system is rebooted. (BZ#2066347) spec: Fix separate tools build (BZ#2074075) VirtIO Throughput for VM on host with OVS HW-Offload is very low (BZ#2074222) kernel BUG at fs/ext4/mballoc.c:3245! (BZ#2074241) sctp connection abort unexpected. (BZ#2075131) [GSS]OCP node kernel crash due to cephfsync - unsaferequestwait+0x143 (BZ#2080072) TCP doesn't retransmit if in reorder state and waits for RTO (BZ#2080973) kernel paging space issue (BZ#2080990) Important ice bug fixes (BZ#2081795) Enhancement(s): Bring UV subsystem up to date with upstream kernel 5.12 (BZ#2058190) update qla2xxx driver to latest upstream (BZ#2060427) Update ice and iavf drivers to upstream v5.17 (BZ#2070546)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.49.1.el8_4.aa - Compensating control
Reboot the system after applying the kernel update for the changes in the advisory to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4829?
RHSA-2022:4829 has been assigned a high severity rating due to multiple vulnerabilities in the Linux kernel that could lead to severe consequences.
How do I fix RHSA-2022:4829?
To fix RHSA-2022:4829, you should update the kernel packages to version 4.18.0-305.49.1.el8_4 or later.
What vulnerabilities are addressed in RHSA-2022:4829?
RHSA-2022:4829 addresses vulnerabilities including a buffer overflow in IPsec ESP transformation code (CVE-2022-27666) and a security regression for CVE-2018-13405 (CVE-2021-4037).
Which systems are affected by RHSA-2022:4829?
RHSA-2022:4829 affects systems running vulnerable versions of the Linux kernel and related packages, specifically those prior to 4.18.0-305.49.1.el8_4.
Is it necessary to apply the patch for RHSA-2022:4829 immediately?
Yes, it is strongly recommended to apply the patch for RHSA-2022:4829 immediately to protect your systems from the identified vulnerabilities.