[Important] [Security] Virtuozzo ReadyKernel patch 139.0 for Virtuozzo Server 7.0, 7.5

Issue date: 2022-03-29

Applies to: Virtuozzo Server 7.0, Virtuozzo Server 7.5

Virtuozzo Advisory ID: VZA-2022-010

1. Overview

The cumulative Virtuozzo ReadyKernel patch was updated with a security fix. The patch applies to all supported kernels of Virtuozzo Server 7.x.

2. Security Fixes

  • [Important] [3.10.0-1127.8.2.vz7.151.14 to 3.10.0-1160.53.1.vz7.185.3] Potential use-after-free in the ‘recv’ operation of UNIX domain sockets. Race condition between the garbage collector and the ‘recv’ operation with MSG_PEEK flag was found in the implementation of UNIX domain sockets. It could result in use-after-free and could potentially allow a local attacker to escalate their privileges in the system. (CVE-2021-0920)

3. Installing the Update

Download, install, and immediately apply the patch to the current kernel by running readykernel update.

4. References

The new and updated packages are listed in the JSON file.