RHSA-2022:5249: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012) kernel: race condition in perfeventopen leads to privilege escalation (CVE-2022-1729) kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root (CVE-2022-1966) kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): make SHA512arch algos and CRYPTOUSER built-ins (BZ#2072643) SR-IOV performance > 50% degradation (BZ#2074830) fix data corruption caused by dm-integrity (BZ#2082187) SCTP client-side peeloff issues [rhel-9] (BZ#2084044) TCP connection fails in a asymmetric routing situation (BZ#2085480) Fails to boot Multiple RT VMs each with multiple vCPUs (BZ#2086963) spec: Fix separate tools build (BZ#2090852) call traces related to eehpseries observed and vmcore is not captured, when kdump is triggered (BZ#2092255) Mark ThunderX NIC driver as unmaintained (BZ#2092638)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.17.1.el9_0.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5249?
The severity of RHSA-2022:5249 is classified as moderate.
How do I fix RHSA-2022:5249?
To fix RHSA-2022:5249, you need to update the affected packages to version 5.14.0-70.17.1.el9_0.
What vulnerabilities are addressed by RHSA-2022:5249?
RHSA-2022:5249 addresses vulnerabilities including CVE-2022-1012, which can lead to an information leak.
What packages are affected by RHSA-2022:5249?
RHSA-2022:5249 affects several kernel-related packages, including kernel, bpftool, and kernel-devel among others.
Is RHSA-2022:5249 applicable to all distributions?
RHSA-2022:5249 is specifically relevant to Red Hat distributions, particularly those running the affected kernel version.