RHSA-2022:5214: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012) kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root (CVE-2022-1966) kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5214?
RHSA-2022:5214 has a high severity level due to its potential to lead to information leakage.
How do I fix RHSA-2022:5214?
To fix RHSA-2022:5214, you should update to the recommended versions of the kpatch-patch package provided by Red Hat.
What vulnerabilities are associated with RHSA-2022:5214?
RHSA-2022:5214 addresses a vulnerability related to small table perturb size in the TCP source port generation algorithm which could result in an information leak.
Which systems are affected by RHSA-2022:5214?
RHSA-2022:5214 affects various architectures of the kpatch-patch package, specifically those running version 5_14_0-70_13_1-1-1.el9_0.
What is the impact of RHSA-2022:5214?
The impact of RHSA-2022:5214 includes the potential exposure of sensitive information due to an information leak in the kernel.