RHSA-2022:8974: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: KVM: cmpxchggpte can write to pfns outside the userspace region (CVE-2022-1158) kernel: openvswitch: integer underflow leads to out-of-bounds write in reservesfasize() (CVE-2022-2639) kernel: watch queue race condition can lead to privilege escalation (CVE-2022-2959) kernel: nfsd buffer overflow by RPC message over TCP with garbage data (CVE-2022-43945) hw: cpu: incomplete clean-up of multi-core shared buffers (aka SBDR) (CVE-2022-21123) hw: cpu: incomplete clean-up of microarchitectural fill buffers (aka SBDS) (CVE-2022-21125) hw: cpu: incomplete clean-up in specific special register write operations (aka DRPW) (CVE-2022-21166) hw: cpu: AMD: RetBleed Arbitrary Speculative Code Execution with Return Instructions (CVE-2022-23816, CVE-2022-29900) hw: cpu: AMD: Branch Type Confusion (non-retbleed) (CVE-2022-23825) hw: cpu: Intel: Post-barrier Return Stack Buffer Predictions (CVE-2022-26373) hw: cpu: Intel: RetBleed Arbitrary Speculative Code Execution with Return Instructions (CVE-2022-29901) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the latest RHEL-9.0.z5 Batch (BZ#2137580) [DELL EMC 9.0-RT BUG] System is not booting into RT Kernel with perc12 [kernel-rt] (BZ#2139864)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8974?
The severity of RHSA-2022:8974 is critical due to a significant vulnerability in the kernel-rt packages.
How do I fix RHSA-2022:8974?
You can fix RHSA-2022:8974 by updating to kernel-rt version 5.14.0-70.36.1.rt21.108.el9_0 and its related packages.
What vulnerability is addressed in RHSA-2022:8974?
RHSA-2022:8974 addresses CVE-2022-1158, which allows KVM to write to page frame numbers outside the userspace region.
Which systems are affected by RHSA-2022:8974?
RHSA-2022:8974 affects systems using the Real Time Linux Kernel, specifically kernel-rt package versions prior to 5.14.0-70.36.1.rt21.108.el9_0.
Is there a workaround for RHSA-2022:8974?
There are no specific workarounds for RHSA-2022:8974; the recommended action is to apply the necessary updates.