CVE-2022-21123

medium
Published 2022-11-15 Β· Modified 2022-11-18
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: kernel security, bug fix, and enhancement update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description hw: cpu: incomplete clean-up of multi-core shared buffers (aka SBDR) Red Hat statement Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party…

Description

hw: cpu: incomplete clean-up of multi-core shared buffers (aka SBDR)

Red Hat statement

Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party vendor and Red Hat customers with no possibility of influencing or even documenting the changes. Unless explicitly stated, the level of insight, oversight, and control Red Hat has does not meet the criteria required (in terms of Red Hat ownership of development processes, QA, and documentation) for releasing this content as RHSA. For more information please contact the binary content vendor.

CVSS v3: 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7kernel-rt-0:3.10.0-1160.76.1.rt56.1220.el7RHSA-2022:59392022-08-09T00:00:00Z
Red Hat Enterprise Linux 7kernel-0:3.10.0-1160.76.1.el7RHSA-2022:59372022-08-09T00:00:00Z
Red Hat Enterprise Linux 8kernel-rt-0:4.18.0-372.26.1.rt7.183.el8_6RHSA-2022:64372022-09-13T00:00:00Z
Red Hat Enterprise Linux 8kernel-0:4.18.0-372.26.1.el8_6RHSA-2022:64602022-09-13T00:00:00Z
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionskernel-0:4.18.0-147.76.1.el8_1RHSA-2022:68722022-10-11T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportkernel-0:4.18.0-193.93.1.el8_2RHSA-2022:72792022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rt-0:4.18.0-193.93.1.rt13.143.el8_2RHSA-2022:72802022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-0:4.18.0-193.93.1.el8_2RHSA-2022:72792022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionskernel-0:4.18.0-193.93.1.el8_2RHSA-2022:72792022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportkernel-rt-0:4.18.0-305.65.1.rt7.137.el8_4RHSA-2022:69912022-10-18T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportkernel-0:4.18.0-305.65.1.el8_4RHSA-2022:69832022-10-18T00:00:00Z
Red Hat Enterprise Linux 9kernel-0:5.14.0-162.6.1.el9_1RHSA-2022:82672022-11-15T00:00:00Z
Red Hat Enterprise Linux 9kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1RHSA-2022:79332022-11-15T00:00:00Z
Red Hat Enterprise Linux 9kernel-0:5.14.0-162.6.1.el9_1RHSA-2022:82672022-11-15T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportkernel-0:5.14.0-70.36.1.el9_0RHSA-2022:89732022-12-13T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportkernel-rt-0:5.14.0-70.36.1.rt21.108.el9_0RHSA-2022:89742022-12-13T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8kernel-0:4.18.0-372.26.1.el8_6RHSA-2022:64602022-09-13T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 6microcode_ctlAffected
Red Hat Enterprise Linux 7microcode_ctlAffected
Red Hat Enterprise Linux 8microcode_ctlAffected
Red Hat Enterprise Linux 9microcode_ctlAffected

Apply commands

bash fix
Apply RHSA-2022:5939 for Red Hat Enterprise Linux 7
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed kernel-rt-debug-core-5.14.0-162.6.1.rt21.168.el9_1.x86_64.rpm
8 Fixed kernel-rt-debug-4.18.0-372.26.1.rt7.183.el8_6.x86_64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.20220510.1
sid Fixed 3.20220510.1
forky Fixed 3.20220510.1
bullseye Fixed 3.20220510.1~deb11u1
bookworm Fixed 3.20220510.1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.