Lucene search

K
osvGoogleOSV:RLSA-2021:4646
HistoryNov 15, 2021 - 9:56 a.m.

Important: kernel-rt security and bug fix update

2021-11-1509:56:17
Google
osv.dev
14
kernel-rt package
real time linux kernel
msg_crypto message type
timer tree corruption
security update
bug fix
rocky linux-8.5.z source tree

AI Score

9.7

Confidence

High

EPSS

0.048

Percentile

92.8%

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: Insufficient validation of user-supplied sizes for the MSG_CRYPTO message type (CVE-2021-43267)

  • kernel: timer tree corruption leads to missing wakeup and system freeze (CVE-2021-20317)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • kernel-rt: update RT source tree to the Rocky Linux-8.5.z source tree (BZ#2020036)