First published: Wed Apr 05 2023(Updated: )
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.<br>Security Fix(es):<br><li> kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378)</li> <li> ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)</li> <li> kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386)</li> <li> kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222 (CVE-2023-1476)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kpatch-patch | <4_18_0-425_10_1-1-4.el8_7 | 4_18_0-425_10_1-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-1-2.el8_7 | 4_18_0-425_13_1-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_3_1-1-6.el8 | 4_18_0-425_3_1-1-6.el8 |
redhat/kpatch-patch | <4_18_0-425_10_1-1-4.el8_7 | 4_18_0-425_10_1-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_10_1-debuginfo-1-4.el8_7 | 4_18_0-425_10_1-debuginfo-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_10_1-debugsource-1-4.el8_7 | 4_18_0-425_10_1-debugsource-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-1-2.el8_7 | 4_18_0-425_13_1-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-debuginfo-1-2.el8_7 | 4_18_0-425_13_1-debuginfo-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-debugsource-1-2.el8_7 | 4_18_0-425_13_1-debugsource-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_3_1-1-6.el8 | 4_18_0-425_3_1-1-6.el8 |
redhat/kpatch-patch | <4_18_0-425_3_1-debuginfo-1-6.el8 | 4_18_0-425_3_1-debuginfo-1-6.el8 |
redhat/kpatch-patch | <4_18_0-425_3_1-debugsource-1-6.el8 | 4_18_0-425_3_1-debugsource-1-6.el8 |
redhat/kpatch-patch | <4_18_0-425_10_1-1-4.el8_7 | 4_18_0-425_10_1-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_10_1-debuginfo-1-4.el8_7 | 4_18_0-425_10_1-debuginfo-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_10_1-debugsource-1-4.el8_7 | 4_18_0-425_10_1-debugsource-1-4.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-1-2.el8_7 | 4_18_0-425_13_1-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-debuginfo-1-2.el8_7 | 4_18_0-425_13_1-debuginfo-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_13_1-debugsource-1-2.el8_7 | 4_18_0-425_13_1-debugsource-1-2.el8_7 |
redhat/kpatch-patch | <4_18_0-425_3_1-1-6.el8 | 4_18_0-425_3_1-1-6.el8 |
redhat/kpatch-patch | <4_18_0-425_3_1-debuginfo-1-6.el8 | 4_18_0-425_3_1-debuginfo-1-6.el8 |
redhat/kpatch-patch | <4_18_0-425_3_1-debugsource-1-6.el8 | 4_18_0-425_3_1-debugsource-1-6.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:1659 is high due to the potential for a stack overflow vulnerability in the kernel.
To fix RHSA-2023:1659, update your system to install the latest version of the kpatch-patch package recommended in the advisory.
Affected versions of kpatch-patch include 4_18_0-425_10_1-1-4.el8_7, 4_18_0-425_13_1-1-2.el8_7, and 4_18_0-425_3_1-1-6.el8.
CVE-2022-4378 is a security vulnerability that potentially allows an attacker to exploit a stack overflow in the kernel.
Yes, you can usually apply the updates without needing to reboot immediately, but a reboot is recommended to ensure the changes take effect.