Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (34)
📋 Description
CVE-2020-36516 — kernel: off-path attacker may inject data or terminate victim's TCP session CVE-2020-36558 — kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference CVE-2021-3640 — kernel: use-after-free vulnerability in function sco_sock_sendmsg() CVE-2021-30002 — kernel: memory leak for large arguments in video_usercopy function in drivers/media/v4l2-core/v4l2-ioctl.c CVE-2021-47099 — kernel: veth: ensure skb entering GRO are not cloned. CVE-2021-47580 — kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB CVE-2022-0168 — kernel: smb2_ioctl_query_info NULL pointer dereference CVE-2022-0617 — kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback CVE-2022-0854 — kernel: swiotlb information leak with DMA_FROM_DEVICE CVE-2022-1016 — kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM CVE-2022-1048 — kernel: race condition in snd_pcm_hw_free leading to use-after-free CVE-2022-1055 — kernel: use-after-free in tc_new_tfilter() in net/sched/cls_api.c CVE-2022-1158 — kernel: KVM: cmpxchg_gpte can write to pfns outside the userspace region CVE-2022-1184 — kernel: use-after-free and memory errors in ext4 when mounting and operating on a corrupted image CVE-2022-1263 — kernel: KVM: NULL pointer dereference in kvm_dirty_ring_push in virt/kvm/dirty_ring.c CVE-2022-1852 — kernel: NULL pointer dereference in x86_emulate_insn may lead to DoS CVE-2022-2078 — kernel: buffer overflow in nft_set_desc_concat_parse() CVE-2022-2153 — kernel: KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() CVE-2022-2503 — kernel: LoadPin bypass via dm-verity table reload CVE-2022-2586 — kernel: nf_tables cross-table potential use-after-free may lead to local privilege escalation CVE-2022-2639 — kernel: openvswitch: integer underflow leads to out-of-bounds write in reserve_sfa_size() CVE-2022-2938 — kernel: use-after-free when psi trigger is destroyed while being polled CVE-2022-3107 — kernel: hv_netvsc: NULL pointer dereference in netvsc_get_ethtool_stats() CVE-2022-20368 — kernel: net/packet: slab-out-of-bounds access in packet_recvmsg() CVE-2022-20572 — kernel: missing DM_TARGET_IMMUTABLE feature flag in verity_target in drivers/md/dm-verity-target.c CVE-2022-21499 — kernel: possible to use the debugger to write zero into a location of choice CVE-2022-24448 — kernel: nfs_atomic_open() returns uninitialized data instead of ENOTDIR CVE-2022-26373 — hw: cpu: Intel: Post-barrier Return Stack Buffer Predictions CVE-2022-27950 — kernel: memory leak in drivers/hid/hid-elo.c CVE-2022-28390 — kernel: double free in ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c CVE-2022-28893 — kernel: use after free in SUNRPC subsystem CVE-2022-29581 — kernel: use-after-free due to improper update of reference count in net/sched/cls_u32.c CVE-2022-36946 — kernel: DoS in nfqnl_mangle in net/netfilter/nfnetlink_queue.c CVE-2022-48918 — kernel: iwlwifi: mvm: check debugfs_dir ptr before use
🎯 Affected products32
- Red Hat Enterprise Linux Real Time (v. 8)
- Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-0:4.18.0-425.3.1.rt7.213.el8.src as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-0:4.18.0-425.3.1.rt7.213.el8.src as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-core-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-core-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-core-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-devel-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-modules-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debuginfo-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-devel-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-devel-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-kvm-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-modules-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-modules-0:4.18.0-425.3.1.rt7.213.el8.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the module v4l2-common from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As the UDF module (udf.ho) will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install udf /bin/true" >> /etc/modprobe.d/disable-udf.conf If the system requires this module t\work correctly, this mitigation may not be suitable. If you need further assistance, see the KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: On non-containerized deployments of Red Hat Enterprise Linux, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled. Workaround: To mitigate this issue, prevent the module snd-pcm from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: This flaw can be mitigated by preventing the affected KVM module from loading during the boot time, and ensuring the module is added to the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, it is possible to prevent the affected code from being loaded by blocklisting the openvswitch kernel module. For instructions relating to blocklisting a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: The mitigation is to disable CAP_NET_RAW capability for regular users and executables to prevent access to raw packet sockets (AF_PACKET). On Red Hat Enterprise Linux 8, the mitigation is to either disable unprivileged user namespaces with `sysctl -w user.max_user_namespaces=0` or network namespaces with `sysctl -w user.max_net_namespaces=0`. For more information on how to set sysctl variables on Red Hat Enterprise Linux, please refer to https://access.redhat.com/solutions/2587. Workaround: This flaw can be mitigated by preventing the affected SUNRPC driver (sunrpc) kernel module from loading during the boot time, ensuring the module is added to the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent the module cls_u32 from being loaded by blacklisting the module to prevent it from loading automatically. ~~~ https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent the module nfnetlink_queue from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blocklist a kernel module to prevent it from loading automatically.
🔗 References (31)
- selfhttps://access.redhat.com/errata/RHSA-2022:7444
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.7_release_notes/index
- externalhttps://access.redhat.com/solutions/6971358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1946279
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1980646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2058395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2059928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069408
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2070205
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2070220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2073064
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074208
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084183
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2112693
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2114878
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2115065
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2115278
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2120175
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2123695
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7444.json