[Important] [Security] Virtuozzo ReadyKernel Patch 155.1 for Virtuozzo Server 7.5

Issue date: 2023-03-27

Applies to: Virtuozzo Server 7.5

Virtuozzo Advisory ID: VZA-2023-007

1. Overview

The cumulative Virtuozzo ReadyKernel patch was updated with security fixes. The patch applies to all supported kernels of Virtuozzo Server 7.5.

2. Security Fixes

  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A Bluetooth use-after-free in the Bluetooth l2cap_rx_state_recv. (CVE-2022-3564)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A netfilter fix in the IRC helper. (CVE-2022-2663)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A use-after-free in the NFP device driver. (CVE-2022-3545)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] NFSv4.1 double svc_xprt_put if rpc_create failures. (CVE-2022-4379)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] A proc string out of bound in proc_skip_spaces(). (CVE-2022-4378)
  • [Important] [3.10.0-1160.41.1.vz7.183.5 to 3.10.0-1160.80.1.vz7.191.4] xprtrdma incorrect header size calculations. (CVE-2022-0812)

3. Installing the Update

Download, install, and immediately apply the patch to the current kernel by running readykernel update.

4. References

The new and updated packages are listed in the JSON file.