RHSA-2022:8809: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: KVM: cmpxchggpte can write to pfns outside the userspace region (CVE-2022-1158) kernel: openvswitch: integer underflow leads to out-of-bounds write in reservesfasize() (CVE-2022-2639) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): x86/intel: processors require energyperfbias setting (BZ#2102103) System crashes due to listadd double add at iwlmvmmacwaketxqueue+0x71 (BZ#2112264) Fix SCHEDWARNON deadlock (BZ#2125422) Starting VMs on a KVM-host with EL8.6-kernel sometimes produces timejumps into the future for other already running guest-VMs [rhel.8] (BZ#2125671) RHEL8.4 - zfcp: fix missing auto port scan and thus missing target ports (BZ#2127850) vfio zero page mappings fail after 2M instances (BZ#2128516) The kernel needs to offer a way to reseed the Crypto DRBG and atomically extract random numbers from it (BZ#2129728) ice: Driver Update up to 5.19 (BZ#2130993) virtio-net: support XDP when not more queues (BZ#2131740) VMs hang after migration (BZ#2131756) Update NVME subsystem with bug fixes and minor changes (BZ#2132555) [HPE BUG] Premature swapping with swappiness=0 while there’s still plenty of pagecache to be reclaimed. (BZ#2133831) nfconntrack causing nfs to stall (BZ#2134089) Fix issue that enables STABLEWRITES by default and causes performance regressions (BZ#2135814) [ice] Intel E810 PTP clock glitching (BZ#2136037) ice: arp replies not making it to switch (BZ#2136043) [ice]configure link-down-on-close on and change interface mtu to 9000,the interface can't up (BZ#2136217) ice: dump additional CSRs for Tx hang debugging (BZ#2136514) crypto/testmgr.c should not list dh, ecdh as .fipsallowed = 1 (BZ#2136525) FIPS module identification via name and version (BZ#2136540) FIPS self-tests for RSA pkcs7 signature verification (BZ#2137316) After upgrading to ocp4.11.1, our dpdk application using vlan strip offload is not working (BZ#2138158) WARNING: CPU: 0 PID: 9637 at kernel/time/hrtimer.c:1309 hrtimerstartrangens+0x35d/0x400 (BZ#2138954) [DELL EMC 8.6-RT BUG] System is not booting into RT Kernel with perc12. (BZ#2139217) Cannot trigger kernel dump using NMI on SNO node running PAO and RT kernel (BZ#2139581) Laser bias information can't be shown by ethtool on rhel8.6 (BZ#2139638) Nested KVM is not working on RHEL 8.6 with hardware error 0x7 (BZ#2140144)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.36.1.el8_6.aa - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2133831 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2139217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2138158 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2139581 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2137316 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2125422 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2135814 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2139638 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2140144 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2127850 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2125671 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2112264 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2129728 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2132555 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2131756 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2138954 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136037 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136525 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2130993 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136043 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2136514 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2022-2639 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2134089 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2128516 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2131740 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2102103 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2022-1158 - Operational
Reboot the system after applying this kernel security and bug fix update so the update takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8809?
The vulnerability RHSA-2022:8809 is classified as important.
How do I fix RHSA-2022:8809?
To fix RHSA-2022:8809, you should update to the kernel version 4.18.0-372.36.1.el8_6.
What components are affected by RHSA-2022:8809?
RHSA-2022:8809 affects various components, including kernel, bpftool, and their debug versions.
What vulnerabilities are addressed in RHSA-2022:8809?
RHSA-2022:8809 addresses vulnerabilities including CVE-2022-1158 related to KVM and an integer underflow in Open vSwitch.
Is there a specific system architecture affected by RHSA-2022:8809?
Yes, RHSA-2022:8809 affects both x86_64 and ppc64le architectures.