Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (7)
📋 Description
CVE-2022-2873 — kernel: an out-of-bounds vulnerability in i2c-ismt driver CVE-2022-41222 — kernel: mm/mremap.c use-after-free vulnerability CVE-2022-43945 — kernel: nfsd buffer overflow by RPC message over TCP with garbage data CVE-2022-50235 — kernel: NFSD: Protect against send buffer overflow in NFSv2 READDIR CVE-2022-50410 — kernel: NFSD: Protect against send buffer overflow in NFSv2 READ CVE-2022-50482 — kernel: iommu/vt-d: Clean up si_domain in the init_dmars() error path CVE-2022-50487 — kernel: NFSD: Protect against send buffer overflow in NFSv3 READDIR
🎯 Affected products122
- Red Hat CodeReady Linux Builder (v. 8)
- Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-425.13.1.el8_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-425.13.1.el8_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 8)
- bpftool-debuginfo-0:4.18.0-425.13.1.el8_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-425.13.1.el8_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-425.13.1.el8_7.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-425.13.1.el8_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-abi-stablelists-0:4.18.0-425.13.1.el8_7.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-425.13.1.el8_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-425.13.1.el8_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-425.13.1.el8_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-425.13.1.el8_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-425.13.1.el8_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-425.13.1.el8_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-425.13.1.el8_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- +92 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this issue, prevent module i2c-ismt from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:0832
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119048
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2138818
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2141752
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0832.json