[Important] [Security] Virtuozzo ReadyKernel patch 142.0 for Virtuozzo Server 7.0, 7.5

Issue date: 2022-05-25

Applies to: Virtuozzo Server 7.0, Virtuozzo Server 7.5

Virtuozzo Advisory ID: VZA-2022-015

1. Overview

The cumulative Virtuozzo ReadyKernel patch was updated with stability fixes. The patch applies to all supported kernels of Virtuozzo Server 7.x.

2. Security Fixes

  • [Important] [3.10.0-1127.8.2.vz7.158.8 to 3.10.0-1160.53.1.vz7.185.3] Setting release_agent could potentially lead to privilege escalation from unprivileged users inside a container to the container root. It couldn’t be exploited to escape containers. (CVE-2022-0492)

3. Installing the Update

Download, install, and immediately apply the patch to the current kernel by running readykernel update.

4. References

The new and updated packages are listed in the JSON file.