Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (67)
📋 Description
CVE-2020-0404 — kernel: avoid cyclic entity chains due to malformed USB descriptors CVE-2020-4788 — kernel: speculation on incompletely validated data on IBM Power9 CVE-2020-13974 — kernel: integer overflow in k_ascii() in drivers/tty/vt/keyboard.c CVE-2020-27820 — kernel: use-after-free in nouveau kernel module CVE-2021-0941 — kernel: out-of-bounds read in bpf_skb_change_head() of filter.c due to a use-after-free CVE-2021-3612 — kernel: joydev: zero size passed to joydev_handle_JSIOCSBTNMAP() CVE-2021-3669 — kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts CVE-2021-3743 — kernel: out-of-bound Read in qrtr_endpoint_post in net/qrtr/qrtr.c CVE-2021-3744 — kernel: crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd() CVE-2021-3752 — kernel: possible use-after-free in bluetooth module CVE-2021-3759 — kernel: unaccounted ipc objects in Linux kernel lead to breaking memcg limits and DoS attacks CVE-2021-3764 — kernel: DoS in ccp_run_aes_gcm_cmd() function CVE-2021-3772 — kernel: sctp: Invalid chunks may be used to remotely remove existing associations CVE-2021-3773 — kernel: lack of port sanity checking in natd and netfilter leads to exploit of OpenVPN clients CVE-2021-3923 — kernel: stack information leak in infiniband RDMA CVE-2021-4002 — kernel: possible leak or coruption of data residing on hugetlbfs CVE-2021-4037 — kernel: security regression for CVE-2018-13405 CVE-2021-4083 — kernel: fget: check that the fd still exists after getting a ref to it CVE-2021-4093 — kernel: KVM: SVM: out-of-bounds read/write in sev_es_string_io CVE-2021-4157 — kernel: Buffer overwrite in decode_nfs_fh function CVE-2021-4197 — kernel: cgroup: Use open-time creds and namespace for migration perm checks CVE-2021-4203 — kernel: Race condition in races in sk_peer_pid and sk_peer_cred accesses CVE-2021-4460 — kernel: Linux kernel: integer overflow and information disclosure via undefined shift operation in drm/amdkfd CVE-2021-20322 — kernel: new DNS Cache Poisoning Attack based on ICMP fragment needed packets replies CVE-2021-21781 — kernel: arm: SIGPAGE information disclosure vulnerability CVE-2021-26401 — hw: cpu: LFENCE/JMP Mitigation Update for CVE-2017-5715 CVE-2021-29154 — kernel: Local privilege escalation due to incorrect BPF JIT branch displacement computation CVE-2021-37159 — kernel: use-after-free in hso_free_net_device() in drivers/net/usb/hso.c CVE-2021-40490 — kernel: race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem CVE-2021-41864 — kernel: eBPF multiplication integer overflow in prealloc_elems_and_freelist() in kernel/bpf/stackmap.c leads to out-of-bounds write CVE-2021-42739 — kernel: Heap buffer overflow in firedtv driver CVE-2021-43056 — kernel: ppc: kvm: allows a malicious KVM guest to crash the host CVE-2021-43389 — kernel: an array-index-out-bounds in detach_capi_ctr in drivers/isdn/capi/kcapi.c CVE-2021-43976 — kernel: mwifiex_usb_recv() in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker to cause DoS via crafted USB device CVE-2021-44733 — kernel: use-after-free in the TEE subsystem CVE-2021-45485 — kernel: information leak in the IPv6 implementation CVE-2021-45486 — kernel: information leak in the IPv4 implementation CVE-2021-47076 — kernel: RDMA/rxe: Return CQE error if invalid lkey was supplied CVE-2021-47178 — kernel: scsi: target: core: Avoid smp_processor_id() in preemptible code CVE-2021-47203 — kernel: scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() CVE-2021-47301 — kernel: igb: Fix use-after-free error during reset CVE-2021-47435 — kernel: dm: fix mempool NULL pointer race when completing IO CVE-2021-47498 — kernel: dm rq: don't queue request to blk-mq during DM suspend CVE-2021-47501 — kernel: i40e: Fix NULL pointer dereference in i40e_dbg_dump_desc CVE-2021-47544 — kernel: tcp: fix page frag corruption on page fault CVE-2021-47556 — kernel: ethtool: ioctl: fix potential NULL deref in ethtool_set_coalesce() CVE-2021-47590 — kernel: mptcp: fix deadlock in __mptcp_push_pending() CVE-2021-47614 — kernel: RDMA/irdma: Fix a user-after-free in add_pble_prm CVE-2022-0001 — hw: cpu: intel: Branch History Injection (BHI) CVE-2022-0002 — hw: cpu: intel: Intra-Mode BTI CVE-2022-0286 — kernel: Local denial of service in bond_ipsec_add_sa CVE-2022-0322 — kernel: DoS in sctp_addto_chunk in net/sctp/sm_make_chunk.c CVE-2022-0850 — kernel: information leak in copy_page_to_iter() in iov_iter.c CVE-2022-1011 — kernel: FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes CVE-2022-3105 — kernel: RDMA/uverbs: NULL pointer dereference in uapi_finalize() CVE-2022-3106 — kernel: sfc_ef100: NULL pointer dereference in ef100_update_stats() CVE-2022-3108 — kernel: drm/amdkfd: NULL pointer dereference in kfd_parse_subtype_iolink() CVE-2022-48771 — kernel: drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-48904 — kernel: iommu/amd: Fix I/O page table memory leak CVE-2022-49227 — kernel: igc: avoid kernel warning when changing RX ring parameters CVE-2022-50131 — kernel: HID: mcp2221: prevent a buffer overflow in mcp_smbus_write() CVE-2022-50475 — kernel: RDMA/core: Make sure "ib_port" is valid when access sysfs node CVE-2022-50510 — kernel: perf/smmuv3: Fix hotplug callback leak in arm_smmu_pmu_init() CVE-2022-50536 — kernel: bpf, sockmap: Fix repeated calls to sock_put() when msg has more_data CVE-2023-0459 — kernel: Copy_from_user on 64-bit versions may leak kernel information CVE-2023-53570 — kernel: wifi: nl80211: fix integer overflow in nl80211_parse_mbssid_elems() CVE-2023-53649 — kernel: perf trace: Really free the evsel->priv area
🎯 Affected products122
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux CRB (v. 8)
- bpftool-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-372.9.1.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-372.9.1.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-372.9.1.el8.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- kernel-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-372.9.1.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-372.9.1.el8.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-372.9.1.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-abi-stablelists-0:4.18.0-372.9.1.el8.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-372.9.1.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-372.9.1.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-372.9.1.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-372.9.1.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-372.9.1.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-372.9.1.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-372.9.1.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- +92 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this issue, prevent the module uvcvideo from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the module nouveau from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent the module joydev from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation baser or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation baser or stability. The possible solution is to disable Bluetooth completely: https://access.redhat.com/solutions/2682931 Workaround: As the SCTP module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: if # echo "install sctp /bin/true" >> /etc/modprobe.d/disable-sctp.conf The system will need to be restarted if the SCTP modules are loaded. In most circumstances, the SCTP kernel modules will be unable to be unloaded while any network interfaces are active and the protocol is in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The mitigation not known. However, for the default configuration of the Red Hat Enterprise Linux it is not possible to trigger this vulnerability: if control groups (cgroups) not being used or being used with the default configuration or being used some other configuration where for example similar privileges for all processes (both for parent and for child processes), then no way to trigger this vulnerability. Workaround: To mitigate this issue, the `amdkfd` kernel module can be prevented from loading by blacklisting it. Create a file `/etc/modprobe.d/blacklist-amdkfd.conf` with the content `blacklist amdkfd`. A system reboot is required for this change to take effect. This may impact functionality that relies on the AMDGPU kernel graphics driver. Workaround: AMD recommends mitigation that uses generic retpoline. Workaround: This issue does not affect most systems by default. An administrator would need to have enabled the BPF JIT to be affected. It can be disabled immediately with the command: # echo 0 > /proc/sys/net/core/bpf_jit_enable Or it can be disabled for all subsequent boots of the system by setting a value in /etc/sysctl.d/44-bpf-jit-disable ## start file ## net.core.bpf_jit_enable=0 ## end file ## Workaround: To mitigate this issue, prevent the module hso from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the module firedtv from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the module isdn from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the modules tee, trusted_tee from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Disabling unprivileged eBPF effectively mitigates the known attack vectors for exploiting intra-mode branch injections attacks. The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. For the Red Hat Enterprise Linux 7, the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. Continue to enable SMEP and Enhanced IBRS. This is the default setting on eligible CPUs. Workaround: Disabling unprivileged eBPF effectively mitigates the known attack vectors for exploiting intra-mode branch injections attacks. The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. Continue to enable SMEP and Enhanced IBRS. This is the default setting on eligible CPUs. Workaround: To mitigate this issue, prevent the module bonding from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is to skip loading the affected module SCTP onto the system. Until we have a fix available, this can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent module arm_smmuv3_pmu from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module bpf from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (60)
- selfhttps://access.redhat.com/errata/RHSA-2022:1988
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.6_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1888433
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1901726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1919791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1946684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1951739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1957375
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1974079
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1978123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981950
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1983894
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1985353
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1994390
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997338
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997467
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000627
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000694
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2009312
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2009521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011104
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2013180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014230
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2015525
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2015755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2016169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2017073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2017796
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2018205
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2022814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2025003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2025726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2027239
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2029923
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030476
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030747
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2035652
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2036934
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037019
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042798
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2046021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048251
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061700
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064855
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1988.json