[Important] [Security] Virtuozzo ReadyKernel Patch 156.4 for Virtuozzo Server 7.5

Issue date: 2023-05-23

Applies to: Virtuozzo Server 7.5

Virtuozzo Advisory ID: VZA-2023-015

1. Overview

The cumulative Virtuozzo ReadyKernel patch was updated with security fixes. The patch applies to all supported kernels of Virtuozzo Server 7.5.

2. Security Fixes

  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] Handle case where the lookup of a directory but the file exists. (CVE-2022-24448)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A NULL pointer dereference in a net SLIP driver. (CVE-2022-41858)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A double-free in the net vhost driver error path. (CVE-2023-1838)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A use-after-free when routing an IGMP multicast message. (CVE-2022-20141)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A memory leak in the net queue scheduler cls_u32 error handler. (CVE-2022-29581)

3. Installing the Update

Download, install, and immediately apply the patch to the current kernel by running readykernel update.

4. References

The new and updated packages are listed in the JSON file.