RHSA-2022:8685: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): KVM: cmpxchggpte can write to pfns outside the userspace region (CVE-2022-1158) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): E810-XXV - Multicast packets are not received by all VFs on the same port even though they have the same VLAN (BZ#2117027) kernel BUG at kernel/sched/deadline.c:1561! [rhel-8.4.0] (BZ#2125673) zfcp: fix missing auto port scan and thus missing target ports (BZ#2127851) memory leak in vxlanxmitone (BZ#2131256) nfconntrack causing nfs to stall (BZ#2134090) s390x: bpftrace Could not read symbols from /sys/kernel/debug/tracing/availablefilterfunctions: No such device (BZ#2134809) Intel E810 PTP clock glitching (BZ#2136038) configure link-down-on-close on and change interface mtu to 9000,the interface can't up (BZ#2136218) dump additional CSRs for Tx hang debugging (BZ#2136515) system panic during sriov sriovtestcntvfreboot testing (BZ#2137272) arp replies not making it to switch (BZ#2137521) WARNING: CPU: 0 PID: 9637 at kernel/time/hrtimer.c:1309 hrtimerstartrangens+0x35d/0x400 (BZ#2138956) Cannot trigger kernel dump using NMI on SNO node running PAO and RT kernel (BZ#2139582)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.71.1.el8_4.aa - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2125673 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2131256 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2134090 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2134809 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136218 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136038 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136515 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2137272 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2137521 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2139582 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2127851 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2138956 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2117027 - Operational
Reboot the system after applying the kernel security and bug fix update for the changes to take effect (as stated: “The system must be rebooted for this update to take effect.”).
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8685?
RHSA-2022:8685 has been classified with an important severity level.
How do I fix RHSA-2022:8685?
To fix RHSA-2022:8685, update the kernel and related packages to version 4.18.0-305.71.1.el8_4.
What are the affected components in RHSA-2022:8685?
RHSA-2022:8685 affects multiple kernel packages including kernel, bpftool, and kernel-modules.
What vulnerability does RHSA-2022:8685 address?
RHSA-2022:8685 addresses a security vulnerability in KVM identified as CVE-2022-1158.
Is a reboot required after applying the patch for RHSA-2022:8685?
Yes, a reboot is typically required to fully apply the kernel security updates from RHSA-2022:8685.