Lucene search

K
redhatRedHatRHSA-2022:7338
HistoryNov 02, 2022 - 4:04 p.m.

(RHSA-2022:7338) Important: kernel-rt security and bug fix update

2022-11-0216:04:02
access.redhat.com
24
kernel-rt
security fix
bug fix
use-after-free
speculative code execution
branch type confusion
rhel7.9.z18
determinism

0.001 Low

EPSS

Percentile

31.2%

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • A use-after-free in cls_route filter implementation may lead to privilege escalation (CVE-2022-2588)

  • RetBleed Arbitrary Speculative Code Execution with Return Instructions (CVE-2022-23816, CVE-2022-29900)

  • Branch Type Confusion (non-retbleed) (CVE-2022-23825)

  • Intel: Post-barrier Return Stack Buffer Predictions (CVE-2022-26373)

  • Intel: RetBleed Arbitrary Speculative Code Execution with Return Instructions (CVE-2022-29901)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Update to the latest RHEL7.9.z18 source tree (BZ#2117337)