Security Vulnerabilities fixed in kpatch-patch-4_18_0 RHSA-2022:1535

description-logoDescription

This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Security Fix(es): kernel: use-after-free in RDMA listen() (CVE-2021-4028) kernel: heap out of bounds write in nf_dup_netdev.c (CVE-2022-25636) kernel: use-after-free in RDMA listen() (CVE-2021-4028) kernel: heap out of bounds write in nf_dup_netdev.c (CVE-2022-25636) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. SolutionFor details on how to apply this update, which includes the changes described in this advisory, refer to:https://access.redhat.com/articles/11258

affected-products-logoAffected Applications

kpatch-patch-4_18_0

CVE References

CVE-2021-4028 CVE-2022-25636