ELSA-2023-12839

ELSA-2023-12839 - kernel security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2023-09-29

Description


[4.18.0-477.27.1.el8_8.OL8]
- x86/microcode/intel: Expose collect_cpu_info_early() for IFS
- x86/cpu: Load microcode during restore_processor_state()
- x86/microcode: Deprecate MICROCODE_OLD_INTERFACE
- x86/microcode: Rip out the OLD_INTERFACE
- x86/microcode: Default-disable late loading
- x86/microcode: Taint and warn on late loading
- x86/microcode: Remove unnecessary perf callback
- x86/microcode: Print previous version of microcode after reload
- x86/microcode: Rip out the subsys interface gunk
- x86/microcode: Simplify init path even more
- x86/microcode/AMD: Rename a couple of functions {CVE-2023-20593}
- x86/microcode: Add a parameter to microcode_check() to store CPU capabilities {CVE-2023-20593}
- x86/microcode: Check CPU capabilities after late microcode update correctly {CVE-2023-20593}
- x86/microcode: Adjust late loading result reporting message {CVE-2023-20593}
- x86/amd: Cache debug register values in percpu variables {CVE-2023-20593}
- x86/microcode: Remove ->request_microcode_user()
- x86/microcode: Kill refresh_fw
- x86/microcode/amd: Remove load_microcode_amd()'s bsp parameter {CVE-2023-20593}
- x86/microcode: Drop struct ucode_cpu_info.valid
- x86/microcode/AMD: Add a @cpu parameter to the reloading functions {CVE-2023-20593}
- x86/microcode/AMD: Track patch allocation size explicitly
- x86/microcode/AMD: Fix mixed steppings support {CVE-2023-20593}
- x86/microcode/core: Return an error only when necessary {CVE-2023-20593}
- x86/apic: Don't disable x2APIC if locked
- x86/cpu/amd: Move the errata checking functionality up {CVE-2023-20593}
- x86/cpu: Remove redundant extern x86_read_arch_cap_msr()
- x86/cpu, kvm: Add support for CPUID_80000021_EAX
- KVM: x86: Advertise that the SMM_CTL MSR is not supported
- KVM: x86: Move open-coded CPUID leaf 0x80000021 EAX bit propagation code
- x86/cpu, kvm: Add the NO_NESTED_DATA_BP feature
- x86/bugs: Make sure MSR_SPEC_CTRL is updated properly upon resume from S3
- x86/cpu: Support AMD Automatic IBRS
- x86/CPU/AMD: Make sure EFER[AIBRSE] is set
- x86/cpu/amd: Add a Zenbleed fix {CVE-2023-20593}
- netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE {CVE-2023-3390}


Related CVEs


CVE-2023-3390
CVE-2023-20593

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-4.18.0-477.27.1.el8_8.src.rpmc141868b2d8368589ffaf4f224a498e2-ol8_aarch64_baseos_latest
kernel-4.18.0-477.27.1.el8_8.src.rpmc141868b2d8368589ffaf4f224a498e2-ol8_aarch64_codeready_builder
kernel-4.18.0-477.27.1.el8_8.src.rpmc141868b2d8368589ffaf4f224a498e2-ol8_aarch64_u8_baseos_patch
bpftool-4.18.0-477.27.1.el8_8.aarch64.rpm174f8fd0162c2a94b7cdeeff0d72956e-ol8_aarch64_baseos_latest
bpftool-4.18.0-477.27.1.el8_8.aarch64.rpm174f8fd0162c2a94b7cdeeff0d72956e-ol8_aarch64_u8_baseos_patch
kernel-cross-headers-4.18.0-477.27.1.el8_8.aarch64.rpmba22709b50edb454897262d49b9cd1cb-ol8_aarch64_baseos_latest
kernel-cross-headers-4.18.0-477.27.1.el8_8.aarch64.rpmba22709b50edb454897262d49b9cd1cb-ol8_aarch64_u8_baseos_patch
kernel-headers-4.18.0-477.27.1.el8_8.aarch64.rpm874781b0ecd828443dea4081bfeeae6d-ol8_aarch64_baseos_latest
kernel-headers-4.18.0-477.27.1.el8_8.aarch64.rpm874781b0ecd828443dea4081bfeeae6d-ol8_aarch64_u8_baseos_patch
kernel-tools-4.18.0-477.27.1.el8_8.aarch64.rpm8817f4da309602a95f05bd92190867c7-ol8_aarch64_baseos_latest
kernel-tools-4.18.0-477.27.1.el8_8.aarch64.rpm8817f4da309602a95f05bd92190867c7-ol8_aarch64_u8_baseos_patch
kernel-tools-libs-4.18.0-477.27.1.el8_8.aarch64.rpm3585967ce3dbdca689eb1e5dafb5204e-ol8_aarch64_baseos_latest
kernel-tools-libs-4.18.0-477.27.1.el8_8.aarch64.rpm3585967ce3dbdca689eb1e5dafb5204e-ol8_aarch64_u8_baseos_patch
kernel-tools-libs-devel-4.18.0-477.27.1.el8_8.aarch64.rpm9e4065db43ce56cd0ed00f0a715b78f3-ol8_aarch64_codeready_builder
perf-4.18.0-477.27.1.el8_8.aarch64.rpm90c36c2fab9454eab070f42d849ff708-ol8_aarch64_baseos_latest
perf-4.18.0-477.27.1.el8_8.aarch64.rpm90c36c2fab9454eab070f42d849ff708-ol8_aarch64_u8_baseos_patch
python3-perf-4.18.0-477.27.1.el8_8.aarch64.rpma724ff0199e3ebe4ea1527d415dd4567-ol8_aarch64_baseos_latest
python3-perf-4.18.0-477.27.1.el8_8.aarch64.rpma724ff0199e3ebe4ea1527d415dd4567-ol8_aarch64_u8_baseos_patch
Oracle Linux 8 (x86_64) kernel-4.18.0-477.27.1.el8_8.src.rpmc141868b2d8368589ffaf4f224a498e2-ol8_x86_64_baseos_latest
kernel-4.18.0-477.27.1.el8_8.src.rpmc141868b2d8368589ffaf4f224a498e2-ol8_x86_64_codeready_builder
kernel-4.18.0-477.27.1.el8_8.src.rpmc141868b2d8368589ffaf4f224a498e2-ol8_x86_64_u8_baseos_patch
bpftool-4.18.0-477.27.1.el8_8.x86_64.rpmd199043a508c69ca59e2b11fc487dd16-ol8_x86_64_baseos_latest
bpftool-4.18.0-477.27.1.el8_8.x86_64.rpmd199043a508c69ca59e2b11fc487dd16-ol8_x86_64_u8_baseos_patch
kernel-4.18.0-477.27.1.el8_8.x86_64.rpmd3f870095fcd72ed43a798e204154a10-ol8_x86_64_baseos_latest
kernel-4.18.0-477.27.1.el8_8.x86_64.rpmd3f870095fcd72ed43a798e204154a10-ol8_x86_64_u8_baseos_patch
kernel-abi-stablelists-4.18.0-477.27.1.el8_8.noarch.rpme7a61d8e37b4ca3724fe46dab92d07d4-ol8_x86_64_baseos_latest
kernel-abi-stablelists-4.18.0-477.27.1.el8_8.noarch.rpme7a61d8e37b4ca3724fe46dab92d07d4-ol8_x86_64_u8_baseos_patch
kernel-core-4.18.0-477.27.1.el8_8.x86_64.rpme7d161a86eac2f70774226a3b4f28e41-ol8_x86_64_baseos_latest
kernel-core-4.18.0-477.27.1.el8_8.x86_64.rpme7d161a86eac2f70774226a3b4f28e41-ol8_x86_64_u8_baseos_patch
kernel-cross-headers-4.18.0-477.27.1.el8_8.x86_64.rpm4ad1425e46a6c4f6f30a67b0e7292e55-ol8_x86_64_baseos_latest
kernel-cross-headers-4.18.0-477.27.1.el8_8.x86_64.rpm4ad1425e46a6c4f6f30a67b0e7292e55-ol8_x86_64_u8_baseos_patch
kernel-debug-4.18.0-477.27.1.el8_8.x86_64.rpm15825f77dde75ba3c53a047539876f3f-ol8_x86_64_baseos_latest
kernel-debug-4.18.0-477.27.1.el8_8.x86_64.rpm15825f77dde75ba3c53a047539876f3f-ol8_x86_64_u8_baseos_patch
kernel-debug-core-4.18.0-477.27.1.el8_8.x86_64.rpm3b0b48bcb06ca27edbbe09af63169f17-ol8_x86_64_baseos_latest
kernel-debug-core-4.18.0-477.27.1.el8_8.x86_64.rpm3b0b48bcb06ca27edbbe09af63169f17-ol8_x86_64_u8_baseos_patch
kernel-debug-devel-4.18.0-477.27.1.el8_8.x86_64.rpm6b1c6b435c2313f0a8aee5899c41ee80-ol8_x86_64_baseos_latest
kernel-debug-devel-4.18.0-477.27.1.el8_8.x86_64.rpm6b1c6b435c2313f0a8aee5899c41ee80-ol8_x86_64_u8_baseos_patch
kernel-debug-modules-4.18.0-477.27.1.el8_8.x86_64.rpmd3bb9617524c53ca6cc061a5fd25bf54-ol8_x86_64_baseos_latest
kernel-debug-modules-4.18.0-477.27.1.el8_8.x86_64.rpmd3bb9617524c53ca6cc061a5fd25bf54-ol8_x86_64_u8_baseos_patch
kernel-debug-modules-extra-4.18.0-477.27.1.el8_8.x86_64.rpm939bc9528c5501c32fcacf3e9b874ba5-ol8_x86_64_baseos_latest
kernel-debug-modules-extra-4.18.0-477.27.1.el8_8.x86_64.rpm939bc9528c5501c32fcacf3e9b874ba5-ol8_x86_64_u8_baseos_patch
kernel-devel-4.18.0-477.27.1.el8_8.x86_64.rpmb94ea02dfceb7ec4bc2caeb47a8fcf00-ol8_x86_64_baseos_latest
kernel-devel-4.18.0-477.27.1.el8_8.x86_64.rpmb94ea02dfceb7ec4bc2caeb47a8fcf00-ol8_x86_64_u8_baseos_patch
kernel-doc-4.18.0-477.27.1.el8_8.noarch.rpme951f3c79bb64e75e9da4c94240a8612-ol8_x86_64_baseos_latest
kernel-doc-4.18.0-477.27.1.el8_8.noarch.rpme951f3c79bb64e75e9da4c94240a8612-ol8_x86_64_u8_baseos_patch
kernel-headers-4.18.0-477.27.1.el8_8.x86_64.rpme38b87c62bfbae939981b71805b4d772-ol8_x86_64_baseos_latest
kernel-headers-4.18.0-477.27.1.el8_8.x86_64.rpme38b87c62bfbae939981b71805b4d772-ol8_x86_64_u8_baseos_patch
kernel-modules-4.18.0-477.27.1.el8_8.x86_64.rpmffc072aee5fa2f604c99baa9f0aae94b-ol8_x86_64_baseos_latest
kernel-modules-4.18.0-477.27.1.el8_8.x86_64.rpmffc072aee5fa2f604c99baa9f0aae94b-ol8_x86_64_u8_baseos_patch
kernel-modules-extra-4.18.0-477.27.1.el8_8.x86_64.rpmddc08b46aead7d0c6cbc896a0df2ef84-ol8_x86_64_baseos_latest
kernel-modules-extra-4.18.0-477.27.1.el8_8.x86_64.rpmddc08b46aead7d0c6cbc896a0df2ef84-ol8_x86_64_u8_baseos_patch
kernel-tools-4.18.0-477.27.1.el8_8.x86_64.rpmb7423113c55d0f002893cc1def1f3523-ol8_x86_64_baseos_latest
kernel-tools-4.18.0-477.27.1.el8_8.x86_64.rpmb7423113c55d0f002893cc1def1f3523-ol8_x86_64_u8_baseos_patch
kernel-tools-libs-4.18.0-477.27.1.el8_8.x86_64.rpm3112f925176518fa28959a062d62c866-ol8_x86_64_baseos_latest
kernel-tools-libs-4.18.0-477.27.1.el8_8.x86_64.rpm3112f925176518fa28959a062d62c866-ol8_x86_64_u8_baseos_patch
kernel-tools-libs-devel-4.18.0-477.27.1.el8_8.x86_64.rpmb4a456041ba87d472c0f590475ea7eaa-ol8_x86_64_codeready_builder
perf-4.18.0-477.27.1.el8_8.x86_64.rpm44449e19f3dd05ff203b2cb338dc71d6-ol8_x86_64_baseos_latest
perf-4.18.0-477.27.1.el8_8.x86_64.rpm44449e19f3dd05ff203b2cb338dc71d6-ol8_x86_64_u8_baseos_patch
python3-perf-4.18.0-477.27.1.el8_8.x86_64.rpmc667e39eef243ad4edde3111c20d3fc0-ol8_x86_64_baseos_latest
python3-perf-4.18.0-477.27.1.el8_8.x86_64.rpmc667e39eef243ad4edde3111c20d3fc0-ol8_x86_64_u8_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete