Lucene search

K
osvGoogleOSV:RLSA-2021:4088
HistoryNov 02, 2021 - 9:33 a.m.

Important: kernel-rt security and bug fix update

2021-11-0209:33:51
Google
osv.dev
7

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.6%

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after-free (CVE-2020-36385)

  • kernel: out-of-bounds write due to a heap buffer overflow in __hidinput_change_resolution_multipliers() of hid-input.c (CVE-2021-0512)

  • kernel: SVM nested virtualization issue in KVM (VMLOAD/VMSAVE) (CVE-2021-3656)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • kernel-rt: update RT source tree to the Rocky Linux-8.4.z source tree (BZ#2004117)