-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
8.x, 9.x
-
None
-
rhel-sst-ccs
-
ssg_core_kernel
-
None
-
False
-
False
-
-
None
-
Red Hat Enterprise Linux
-
None
-
None
-
Required
-
Required
-
Unspecified
Document link: [Managing, monitoring, and updating the kernel | Red Hat Enterprise Linux | 9 | Red Hat Documentation|https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html-single/managing_monitoring_and_updating_the_kernel/index#automatically-subscribing-any-future-kernel-to-the-live-patching-stream_applying-patches-with-kernel-live-patching]
Section number and name: 8.6. Automatically subscribing any future kernel to the live patching stream
Describe the issue:
When you subscribe to future live patching streams the way it's written this section makes it seem as if any future kernel that's installed will automatically be subscribed to live kernel patch streams. But this is not the case ever since the "Live Kernel Patch Support Cadence Update" Kernel Live Patch Support Cadence - Red Hat Customer Portal.
Impact of this issue:
System administrators may enable kernel live patching thinking this will apply to all future kernels that are installed. But then if the system is subsequently updated, when/if the system is rebooted and if any new kernel that's installed is not part of the live kernel patching support stream, they will find themselves with a system that's not able to receive live kernel security patches. In production environments this can be exceptionally disruptive because another reboot is required to remediate to a supported kernel release.
Suggestions for improvement:
Recommend edit/rewrite this section to setup the dnf "auto-filter" plugin as documented in Kernel Live Patch Support Cadence - Red Hat Customer Portal. This limitation should also be noted in the 8.1. Limitations of kpatch
section.
Recommend citing Kernel Live Patch life cycles - Red Hat Customer Portal to inform of supported kernel releases for 8.x and 9.x minor releases.