RHSA-2022:5633: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012) kernel: race condition in perfeventopen leads to privilege escalation (CVE-2022-1729) kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root (CVE-2022-32250) kernel: cgroup: Use open-time creds and namespace for migration perm checks (CVE-2021-4197) kernel: Race condition in races in skpeerpid and skpeercred accesses (CVE-2021-4203) kernel: the copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check (CVE-2020-29368) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the RHEL-8.4.z10 source tree (BZ#2087922)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5633?
The severity of RHSA-2022:5633 is classified as important due to a potential information leak.
How do I fix RHSA-2022:5633?
To fix RHSA-2022:5633, upgrade to the kernel-rt package version 4.18.0-305.57.1.rt7.129.el8_4 or later.
Which systems are affected by RHSA-2022:5633?
RHSA-2022:5633 affects systems using the kernel-rt packages version prior to 4.18.0-305.57.1.rt7.129.el8_4.
What kind of vulnerability does RHSA-2022:5633 address?
RHSA-2022:5633 addresses a vulnerability in the TCP source port generation algorithm that can lead to information leakage.
Is there a recommended action for administrators regarding RHSA-2022:5633?
Administrators are recommended to apply the security updates for RHSA-2022:5633 to mitigate the vulnerability.