RHSA-2023:1220: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: use-after-free caused by l2capreassemblesdu() in net/bluetooth/l2capcore.c (CVE-2022-3564) kernel: stack overflow in doprocdointvec and procskipspaces (CVE-2022-4378) kernel: net: CPU soft lockup in TC mirred egress-to-ingress action (CVE-2022-4269) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the RHEL-8.4.z15 source tree. (BZ#2162415)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1220?
The severity of RHSA-2023:1220 is considered critical due to the use-after-free vulnerability that can be exploited remotely.
How do I fix RHSA-2023:1220?
To fix RHSA-2023:1220, update the kernel-rt packages to version 4.18.0-305.82.1.rt7.154.el8_4 or later.
What systems are affected by RHSA-2023:1220?
RHSA-2023:1220 affects various versions of the kernel-rt packages on Red Hat Enterprise Linux 8 systems.
What vulnerability is addressed in RHSA-2023:1220?
RHSA-2023:1220 addresses a use-after-free vulnerability caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c.
Is there any risk if I do not apply the RHSA-2023:1220 update?
Not applying the RHSA-2023:1220 update poses a significant risk as it could allow attackers to exploit the use-after-free vulnerability.