[Important] [Security] Virtuozzo ReadyKernel patch 138.0 for Virtuozzo Hybrid Server 7.0, 7.5

Issue date: 2022-01-11

Applies to: Virtuozzo Hybrid Server 7.0, Virtuozzo Hybrid Server 7.5

Virtuozzo Advisory ID: VZA-2022-002

1. Overview

The cumulative Virtuozzo ReadyKernel patch was updated with a security fix. The patch applies to all supported kernels of Virtuozzo Hybrid Server 7.x.

2. Security Fixes

  • [Important] [3.10.0-1127.8.2.vz7.151.14 to 3.10.0-1160.41.1.vz7.183.5] A flaw in XFS allows non-root users to read raw data from a mounted block device. (PSBM-136140)

3. Installing the Update

Download, install, and immediately apply the patch to the current kernel by running readykernel update.