Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2019-20934 — kernel: use-after-free in show_numa_stats function CVE-2020-11668 — kernel: mishandles invalid descriptors in drivers/media/usb/gspca/xirlink_cit.c CVE-2021-33033 — kernel: use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c CVE-2021-33034 — kernel: use-after-free in net/bluetooth/hci_event.c when destroying an hci_chan CVE-2021-33909 — kernel: size_t-to-int conversion vulnerability in the filesystem layer
🎯 Affected products32
- Red Hat Enterprise Linux for Real Time (v. 7)
- Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-0:3.10.0-1160.36.2.rt56.1179.el7.src as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-0:3.10.0-1160.36.2.rt56.1179.el7.src as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debug-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-debug-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debug-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-debug-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debug-devel-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-debug-devel-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debug-kvm-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debug-kvm-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-debuginfo-common-x86_64-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-debuginfo-common-x86_64-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-devel-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-devel-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-doc-0:3.10.0-1160.36.2.rt56.1179.el7.noarch as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-doc-0:3.10.0-1160.36.2.rt56.1179.el7.noarch as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-kvm-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-kvm-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-trace-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-trace-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-trace-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-trace-debuginfo-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- kernel-rt-trace-devel-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time (v. 7)
- kernel-rt-trace-devel-0:3.10.0-1160.36.2.rt56.1179.el7.x86_64 as a component of Red Hat Enterprise Linux for Real Time for NFV (v. 7)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: As the NUMA features are built-in and enabled by default, the NUMA functionality can be disabled at boot time by providing the kernel parameter, numa=off. The method of providing this parameter depends on the operating system version, see KCS article https://access.redhat.com/solutions/23216. Disabling this feature may have significant performance impacts and the administrator should consider if the performance penalty is a problem. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Mitigation for this issue is to skip loading the affected module 'xirlink-cit' onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: The mitigation would be not allowing CIPSO labeling for the inbound network connections. For the most of the default configurations both for network routers and for the Linux servers itself it is disabled by default. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2021:2726
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2021-006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1824792
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1902788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1961300
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1961305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1970273
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2726.json