RHSA-2023:1988: Moderate: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: memory corruption in usbmon driver (CVE-2022-43750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): decandlock: module license 'unspecified' taints kernel. (BZ#2161435) kernel-rt: update to the latest RHEL7.9.z22 source tree (BZ#2171976)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-debugto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-docto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-traceto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-trace-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-trace-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-debug-kvmto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-debug-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-kvmto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-trace-kvmto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7 - Upgrade
Upgrade
redhat/kernel-rt-trace-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.90.1.rt56.1235.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1988?
The severity of RHSA-2023:1988 is classified as moderate.
How do I fix RHSA-2023:1988?
To fix RHSA-2023:1988, update the kernel-rt packages to version 3.10.0-1160.90.1.rt56.1235.el7.
What types of systems are affected by RHSA-2023:1988?
RHSA-2023:1988 affects systems using the Real Time Linux Kernel, specifically ones running the specified version of kernel-rt.
What vulnerability is addressed by RHSA-2023:1988?
RHSA-2023:1988 addresses a memory corruption vulnerability in the usbmon driver identified as CVE-2022-43750.
Is RHSA-2023:1988 specific to certain architectures?
Yes, RHSA-2023:1988 applies to the x86_64 architecture of the kernel-rt packages.