RHSA-2022:6991: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): A use-after-free in clsroute filter implementation may lead to privilege escalation (CVE-2022-2588) Information leak in the IPv6 implementation (CVE-2021-45485) Information leak in the IPv4 implementation (CVE-2021-45486) Incomplete cleanup of multi-core shared buffers (aka SBDR) (CVE-2022-21123) Incomplete cleanup of microarchitectural fill buffers (aka SBDS) (CVE-2022-21125) Incomplete cleanup in specific special register write operations (aka DRPW) (CVE-2022-21166) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): update RT source tree to the RHEL-8.4.z12 source tree (BZ#2119160) using thiscpuadd() in preemptible [00000000] - caller is modmemcglruvecstate+0x69/0x1c0 [None8.4.0.z] (BZ#2124454)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6991?
The severity of RHSA-2022:6991 is classified as critical due to the potential for privilege escalation.
How do I fix RHSA-2022:6991?
To fix RHSA-2022:6991, update to kernel-rt package version 4.18.0-305.65.1.rt7.137.el8_4 or newer.
What vulnerability does RHSA-2022:6991 address?
RHSA-2022:6991 addresses a use-after-free vulnerability in the cls_route filter implementation.
Which systems are affected by RHSA-2022:6991?
RHSA-2022:6991 affects systems using the Real Time Linux Kernel with specific version constraints.
Is there a specific package version required for RHSA-2022:6991 mitigation?
Yes, for mitigation of RHSA-2022:6991, the specific package version required is 4.18.0-305.65.1.rt7.137.el8_4.