RHSA-2022:7933MediumCVSS 8.2

Red Hat Security Advisory: kernel-rt security and bug fix update

Published
November 15, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (49)

📋 Description

CVE-2020-36516 — kernel: off-path attacker may inject data or terminate victim's TCP session CVE-2021-3640 — kernel: use-after-free vulnerability in function sco_sock_sendmsg() CVE-2021-47099 — kernel: veth: ensure skb entering GRO are not cloned. CVE-2021-47556 — kernel: ethtool: ioctl: fix potential NULL deref in ethtool_set_coalesce() CVE-2021-47580 — kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB CVE-2022-0168 — kernel: smb2_ioctl_query_info NULL pointer dereference CVE-2022-0617 — kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback CVE-2022-0854 — kernel: swiotlb information leak with DMA_FROM_DEVICE CVE-2022-1016 — kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM CVE-2022-1048 — kernel: race condition in snd_pcm_hw_free leading to use-after-free CVE-2022-1158 — kernel: KVM: cmpxchg_gpte can write to pfns outside the userspace region CVE-2022-1184 — kernel: use-after-free and memory errors in ext4 when mounting and operating on a corrupted image CVE-2022-1263 — kernel: KVM: NULL pointer dereference in kvm_dirty_ring_push in virt/kvm/dirty_ring.c CVE-2022-1280 — kernel: concurrency use-after-free between drm_setmaster_ioctl and drm_mode_getresources CVE-2022-1353 — kernel: kernel info leak issue in pfkey_register CVE-2022-1679 — kernel: use-after-free in ath9k_htc_probe_device() could cause an escalation of privileges CVE-2022-1852 — kernel: NULL pointer dereference in x86_emulate_insn may lead to DoS CVE-2022-1998 — kernel: fanotify misuses fd_install() which could lead to use-after-free CVE-2022-2153 — kernel: KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() CVE-2022-2503 — kernel: LoadPin bypass via dm-verity table reload CVE-2022-2586 — kernel: nf_tables cross-table potential use-after-free may lead to local privilege escalation CVE-2022-2639 — kernel: openvswitch: integer underflow leads to out-of-bounds write in reserve_sfa_size() CVE-2022-3107 — kernel: hv_netvsc: NULL pointer dereference in netvsc_get_ethtool_stats() CVE-2022-3108 — kernel: drm/amdkfd: NULL pointer dereference in kfd_parse_subtype_iolink() CVE-2022-3239 — kernel: media: em28xx: initialize refcount before kref_get CVE-2022-20368 — kernel: net/packet: slab-out-of-bounds access in packet_recvmsg() CVE-2022-20572 — kernel: missing DM_TARGET_IMMUTABLE feature flag in verity_target in drivers/md/dm-verity-target.c CVE-2022-21123 — hw: cpu: incomplete clean-up of multi-core shared buffers (aka SBDR) CVE-2022-21125 — hw: cpu: incomplete clean-up of microarchitectural fill buffers (aka SBDS) CVE-2022-21166 — hw: cpu: incomplete clean-up in specific special register write operations (aka DRPW) CVE-2022-21499 — kernel: possible to use the debugger to write zero into a location of choice CVE-2022-23816 — hw: cpu: AMD: RetBleed Arbitrary Speculative Code Execution with Return Instructions CVE-2022-23825 — hw: cpu: AMD: Branch Type Confusion (non-retbleed) CVE-2022-24448 — kernel: nfs_atomic_open() returns uninitialized data instead of ENOTDIR CVE-2022-26373 — hw: cpu: Intel: Post-barrier Return Stack Buffer Predictions CVE-2022-28390 — kernel: double free in ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c CVE-2022-28693 — hw: cpu: Intel: information disclosure via local access CVE-2022-28893 — kernel: use after free in SUNRPC subsystem CVE-2022-29581 — kernel: use-after-free due to improper update of reference count in net/sched/cls_u32.c CVE-2022-29900 — hw: cpu: AMD: RetBleed Arbitrary Speculative Code Execution with Return Instructions CVE-2022-29901 — hw: cpu: Intel: RetBleed Arbitrary Speculative Code Execution with Return Instructions CVE-2022-36946 — kernel: DoS in nfqnl_mangle in net/netfilter/nfnetlink_queue.c CVE-2022-39190 — kernel: nf_tables disallow binding to already bound chain CVE-2022-42432 — kernel: netfilter: nfnetlink_osf: uninitialized variable information disclosure vulnerability CVE-2022-48905 — kernel: ibmvnic: free reset-work-item when flushing CVE-2022-48918 — kernel: iwlwifi: mvm: check debugfs_dir ptr before use CVE-2022-48936 — kernel: gso: do not skip outer ip header in case of ipip and net_failover CVE-2023-1095 — kernel: netfilter: NULL pointer dereference in nf_tables due to zeroed list head CVE-2023-2008 — kernel: udmabuf: improper validation of array index leading to local privilege escalation

🎯 Affected products32

  • Red Hat Enterprise Linux Real Time (v. 9)
  • Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1.src as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1.src as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-core-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-core-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debug-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-core-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debug-core-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-debuginfo-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debug-debuginfo-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-devel-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debug-devel-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-kvm-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-modules-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debug-modules-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debug-modules-extra-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debug-modules-extra-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debuginfo-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debuginfo-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-devel-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-devel-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-kvm-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-rt-modules-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-rt-modules-0:5.14.0-162.6.1.rt21.168.el9_1.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • +2 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As the UDF module (udf.ho) will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install udf /bin/true" >> /etc/modprobe.d/disable-udf.conf If the system requires this module t\work correctly, this mitigation may not be suitable. If you need further assistance, see the KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: On non-containerized deployments of Red Hat Enterprise Linux, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled. Workaround: To mitigate this issue, prevent the module snd-pcm from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, prevent the module ath9k from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected KVM module from loading during the boot time, and ensuring the module is added to the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, it is possible to prevent the affected code from being loaded by blocklisting the openvswitch kernel module. For instructions relating to blocklisting a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: To mitigate this issue, prevent module em28xx from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: The mitigation is to disable CAP_NET_RAW capability for regular users and executables to prevent access to raw packet sockets (AF_PACKET). On Red Hat Enterprise Linux 8, the mitigation is to either disable unprivileged user namespaces with `sysctl -w user.max_user_namespaces=0` or network namespaces with `sysctl -w user.max_net_namespaces=0`. For more information on how to set sysctl variables on Red Hat Enterprise Linux, please refer to https://access.redhat.com/solutions/2587. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation baser or stability. Workaround: This flaw can be mitigated by preventing the affected SUNRPC driver (sunrpc) kernel module from loading during the boot time, ensuring the module is added to the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent the module cls_u32 from being loaded by blacklisting the module to prevent it from loading automatically. ~~~ https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent the module nfnetlink_queue from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blocklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected netfilter kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

🔗 References (35)