Red Hat released RHBA-2022:5088 for Red Hat OpenShift Enterprise ASYNC Stream container images, incorporating the Linux kernel security fixes in RHSA-2022:1988. The update affects OpenShift Container Platform 4.7 on RHEL 8 x86_64; Red Hat directed customers to upgrade the images and rebuild dependent container images.
The bundled fixes address, among other issues, CVE-2021-42739, a heap-based buffer overflow in the FireDTV driver's CA_SEND_MSG ioctl that could enable a local crash or privilege escalation, and CVE-2021-3669, a denial-of-service condition caused by non-scalable /proc/sysvipc/shm reads with exceptionally large shared-memory segment counts. Organizations unable to patch the FireDTV issue immediately can reduce exposure by preventing the firedtv kernel module from loading.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2022:5088 for OpenShift Enterprise ASYNC Stream container images, incorporating the security fixes covered by RHSA-2022:1988 for affected OpenShift Container Platform 4.7 on RHEL 8 x86_64. Red Hat advised customers to upgrade the images and rebuild dependent container images.
Red Hat issued RHBA-2022:4630 to update CodeReady Workspaces 2.0 container images with backported security fixes from RHSA-2022:1988, including fixes for CVE-2021-42739 and CVE-2021-21781. Users were advised to upgrade the images and rebuild dependent container images.
Red Hat closed Bugzilla 1986473, its tracking record for CVE-2021-3669. The issue was addressed for RHEL 8 through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat addressed CVE-2021-42739 in RHEL 8 through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat issued RHEL 7 fixes for the FireDTV heap-buffer-overflow vulnerability through RHSA-2022:0063 and RHSA-2022:0065.
Red Hat closed Bugzilla 1951739, its tracking record for CVE-2021-42739. The recommended mitigation was to prevent the firedtv kernel module from loading.
Red Hat stated that CVE-2021-3669 had not been reported upstream and that patches were being developed. It assessed exploitation as having limited practical impact because it requires exceptionally large numbers of shared-memory segments.
Guilherme de Almeida Suckevicz reported CVE-2021-3669, in which non-scalable reads of /proc/sysvipc/shm with very large numbers of shared-memory segments can cause resource exhaustion and denial of service.
Guilherme de Almeida Suckevicz reported CVE-2021-21781, a medium-severity Linux ARM SIGPAGE flaw through which a local attacker could read signal-page contents at a specific process-memory offset and potentially disclose kernel-memory data.
Pedro Sampaio reported Red Hat Bugzilla 1951739 for CVE-2021-42739, a heap-based buffer overflow in the Linux FireDTV driver that a local user could trigger through the CA_SEND_MSG ioctl.
Fedora received a fix for the /proc/sysvipc/shm resource-exhaustion issue through 5.15.x kernel rebases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.