RHSA-2022:8673: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): KVM: cmpxchggpte can write to pfns outside the userspace region (CVE-2022-1158) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Multicast packets are not received by all VFs on the same port even though they have the same VLAN (BZ#2117027) Backport use of a dedicate thread for timer wakeups (BZ#2127206) Update RT source tree to the RHEL-8.4.z13 source tree. (BZ#2129948) Cannot trigger kernel dump using NMI on SNO node running PAO and RT kernel [RT-8] (BZ#2139853)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8673?
The severity of RHSA-2022:8673 is classified as critical.
How do I fix RHSA-2022:8673?
To fix RHSA-2022:8673, update to kernel-rt package version 4.18.0-305.71.1.rt7.143.el8_4 or later.
Which packages are affected by RHSA-2022:8673?
RHSA-2022:8673 affects multiple kernel-rt packages including kernel-rt, kernel-rt-core, and kernel-rt-debug.
What specific vulnerability is addressed in RHSA-2022:8673?
RHSA-2022:8673 addresses a vulnerability in KVM related to the cmpxchg_gpte function which can write to page frame numbers outside the userspace region.
How can I determine if I am vulnerable to RHSA-2022:8673?
You can determine your vulnerability to RHSA-2022:8673 by checking if your kernel-rt version is earlier than 4.18.0-305.71.1.rt7.143.el8_4.