RHSA-2022:5636: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012) kernel: race condition in perfeventopen leads to privilege escalation (CVE-2022-1729) kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root (CVE-2022-32250) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Backport request of "genirq: use rcu in kstatirqsusr()" (BZ#2083311)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5636?
The severity of RHSA-2022:5636 is considered to be moderate due to the potential for information leakage.
How do I fix RHSA-2022:5636?
To fix RHSA-2022:5636, update the affected kernel packages to version 4.18.0-147.70.1.el8_1 or later.
What vulnerabilities are addressed by RHSA-2022:5636?
RHSA-2022:5636 addresses vulnerabilities including CVE-2022-1012, which involves an information leak in TCP source port generation.
Which systems are affected by RHSA-2022:5636?
Systems running affected versions of the kernel and related packages in Red Hat Enterprise Linux 8 are impacted by RHSA-2022:5636.
Is a reboot required after applying the fix for RHSA-2022:5636?
Yes, a reboot is typically required after updating the kernel packages to ensure the changes take effect.