Friday, April 8, 2022

Centos Linux: CVE-2021-4028: Important: kpatch-patch security update (Multiple Advisories)

Description
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
Solution(s)
  • centos-upgrade-kernel
  • centos-upgrade-kernel-rt
  • centos-upgrade-kpatch-patch-3_10_0-1160_24_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_24_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_25_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_25_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_31_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_31_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_36_2
  • centos-upgrade-kpatch-patch-3_10_0-1160_36_2-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_41_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_41_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_42_2
  • centos-upgrade-kpatch-patch-3_10_0-1160_42_2-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_45_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_45_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_49_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_49_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_53_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_53_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_59_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_59_1-debuginfo


  • References
  • CESA-2022:1185
  • CESA-2022:1198
  • CESA-2022:1199
  • CVE-2021-4028




  •  

    Copyright © 2021 Vulnerability Database | Cyber Details™

    thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore