ELBA-2018-4212

ELBA-2018-4212 - Unbreakable Enterprise kernel bug fix update

Type:BUG
Severity:NA
Release Date:2018-09-10

Description


[4.14.35-1818.2.1]
- CVE-2018-15471 XSA-270 Linux netback driver OOB access in hash handling (Jan Beulich) [Orabug: 28460239] {CVE-2018-15471}
- x86/paravirt: Fix spectre-v2 mitigations for paravirt guests (Peter Zijlstra) [Orabug: 28474644]
- sym53c8xx: fix NULL pointer dereference panic in sym_int_sir() in sym_hipd.c (George Kennedy) [Orabug: 28481892]
- xen-netfront: fix warn message as irq device name has '/' (Xiao Liang) [Orabug: 28515370]
- xen-netfront: fix queue name setting (Vitaly Kuznetsov) [Orabug: 28515370]
- uek-rpm: Enable MPLS suppoprt (Victor Erminpour) [Orabug: 28550407]
- x86/spectrev2: Dont set mode to SPECTRE_V2_NONE when retpoline is available. (Boris Ostrovsky) [Orabug: 28544532]

[4.14.35-1818.2.0]
- uek-rpm: Show UEK Release Number in RPM summary (Victor Erminpour) [Orabug: 28328975]
- uek-rpm: aarch64: enable building SHA3 algorithms (Henry Willard) [Orabug: 28067833]
- uek-rpm: config-debug: Turn off torture testing by default (Knut Omang) [Orabug: 28261889]
- nfsd: give out fewer session slots as limit approaches (J. Bruce Fields) [Orabug: 28427496]
- nfsd: increase DRC cache limit (J. Bruce Fields) [Orabug: 28427496]
- scsi: libsas: defer ata device eh commands to libata (Jason Yan) [Orabug: 28459683] {CVE-2018-10021}
- Fix up non-directory creation in SGID directories (Linus Torvalds) [Orabug: 28459475] {CVE-2018-13405}
- rds: Avoid compiler warning in ib_send.c (Knut Omang) [Orabug: 28465601]
- uek-rpm: Enable perf stripped binary (Victor Erminpour) [Orabug: 28469291]
- qla2xxx: Update the version to 10.00.00.07-k1. (Giridhar Malavali) [Orabug: 28497114]
- qla2xxx: Utilize complete local DMA buffer for DIF PI inforamtion. (Giridhar Malavali) [Orabug: 28497114]
- qla2xxx: Correction to total data segment count when local DMA buffers used for DIF PI. (Giridhar Malavali) [Orabug: 28497114]
- fuse: dont keep dead fuse_conn at fuse_fill_super(). (Tetsuo Handa) [Orabug: 28434194]
- fuse: fix control dir setup and teardown (Miklos Szeredi) [Orabug: 28434194]
- fuse: fix congested state leak on aborted connections (Tejun Heo) [Orabug: 28434194]
- fuse: Allow fully unprivileged mounts (Eric W. Biederman) [Orabug: 28434194]
- fuse: Ensure posix acls are translated outside of init_user_ns (Eric W. Biederman) [Orabug: 28434194]
- fuse: define the filesystem as untrusted (Mimi Zohar) [Orabug: 28434194]
- ima: fail file signature verification on non-init mounted filesystems (Mimi Zohar) [Orabug: 28434194]
- fuse: add writeback documentation (Miklos Szeredi) [Orabug: 28434194]
- fuse: honor AT_STATX_FORCE_SYNC (Miklos Szeredi) [Orabug: 28434194]
- fuse: honor AT_STATX_DONT_SYNC (Miklos Szeredi) [Orabug: 28434194]
- fuse: Restrict allow_other to the superblocks namespace or a descendant (Seth Forshee) [Orabug: 28434194]
- fuse: Support fuse filesystems outside of init_user_ns (Eric W. Biederman) [Orabug: 28434194]
- fuse: Fail all requests with invalid uids or gids (Eric W. Biederman) [Orabug: 28434194]
- fuse: Remove the buggy retranslation of pids in fuse_dev_do_read (Eric W. Biederman) [Orabug: 28434194]
- fuse: return -ECONNABORTED on /dev/fuse read after abort (Szymon Lukasz) [Orabug: 28434194]
- fuse: atomic_o_trunc should truncate pagecache (Miklos Szeredi) [Orabug: 28434194]
- fs: fuse: account fuse_inode slab memory as reclaimable (Johannes Weiner) [Orabug: 28434194]




Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete