| Type: | BUG |
| Impact: | NA |
| Release Date: | 2025-11-11 |
[5.14.0-570.62.1.0.2]
- Update module name for cryptographic module [Orabug: 36324521]
[5.14.0-570.62.1.0.1]
- nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
[5.14.0-570.62.1]
- redhat/configs: Enable CONFIG_MITIGATION_VMSCAPE for x86 (Waiman Long) [RHEL-114270]
- x86/vmscape: Add old Intel CPUs to affected list (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- x86/vmscape: Warn when STIBP is disabled with SMT (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- x86/bugs: Move cpu_bugs_smt_update() down (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- x86/vmscape: Enable the mitigation (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- x86/vmscape: Add conditional IBPB mitigation (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- x86/vmscape: Enumerate VMSCAPE bug (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- Documentation/hw-vuln: Add VMSCAPE documentation (Waiman Long) [RHEL-114270] {CVE-2025-40300}
- randomize_kstack: Remove non-functional per-arch entropy filtering (Waiman Long) [RHEL-114270]
- redhat/configs: Enable CONFIG_MITIGATION_TSA for x86 (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/process: Move the buffer clearing before MONITOR (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-36357 CVE-2024-36350}
- x86/microcode/AMD: Add TSA microcode SHAs (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-36357 CVE-2024-36350}
- KVM: SVM: Advertise TSA CPUID bits to guests (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-36357 CVE-2024-36350}
- x86/bugs: Add a Transient Scheduler Attacks mitigation (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-36357 CVE-2024-36350}
- x86/bugs: Rename MDS machinery to something more generic (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-36357 CVE-2024-36350}
(Waiman Long) [RHEL-83896 RHEL-83905]
- x86/idle: Remove .s output beautifying delimiters from simpler asm() templates (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/idle: Standardize argument types for MONITOR{,X} and MWAIT{,X} instruction wrappers on 'u32' (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in mwait_idle_with_hints() and prefer_mwait_c1_over_halt() (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Rename mmio_stale_data_clear to cpu_buf_vm_clear (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode: Consolidate the loader enablement checking (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Fix __apply_microcode_amd()'s return value (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2025-22047}
- x86/microcode/AMD: Add some forgotten models to the SHA check (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Load only SHA256-checksummed patches (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Add get_patch_level() (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Get rid of the _load_microcode_amd() forward declaration (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Merge early_apply_microcode() into its single callsite (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Remove unused save_microcode_in_initrd_amd() declarations (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Remove ugly linebreak in __verify_patch_section() signature (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpu: Introduce new microcode matching helper (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Remove ret local var in early_apply_microcode() (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Have __apply_microcode_amd() return bool (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Return bool from find_blobs_in_containers() (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Flush patch buffer mapping after application (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/CPU/AMD: Terminate the erratum_1386_microcode array (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-56721}
- x86/mm: Carve out INVLPG inline asm for use by others (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpu: Fix formatting of cpuid_bits[] in scattered.c (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpufeatures: Add X86_FEATURE_AMD_WORKLOAD_CLASS feature bit (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Split load_microcode_amd() (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Pay attention to the stepping dynamically (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Use code segment selector for VERW operand (Waiman Long) [RHEL-83896 RHEL-83905] {CVE-2024-50072}
- x86/microcode/AMD: Fix a -Wsometimes-uninitialized clang false positive (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/microcode/AMD: Use the family,model,stepping encoded in the patch ID (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/CPU/AMD: Improve the erratum 1386 workaround (Waiman Long) [RHEL-83896 RHEL-83905]
- x86: Add a comment about the 'magic' behind shadow sti before mwait (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Revert 'Reverse instruction order of CLEAR_CPU_BUFFERS' (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: KVM: Add support for SRSO_MSR_FIX (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpu/kvm: SRSO: Fix possible missing IBPB on VM-Exit (Waiman Long) [RHEL-83896 RHEL-83905]
- KVM: x86: Advertise SRSO_USER_KERNEL_NO to userspace (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add SRSO_USER_KERNEL_NO support (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Do not use UNTRAIN_RET with IBPB on entry (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Skip RSB fill at VMEXIT (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpufeatures: Add a IBPB_NO_RET BUG flag (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Fix handling when SRSO mitigation is disabled (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add missing NO_SSB flag (Waiman Long) [RHEL-83896 RHEL-83905]
- Documentation/srso: Document a method for checking safe RET operates properly (Waiman Long) [RHEL-83896 RHEL-83905]
- redhat/configs: Add new CONFIG_MITIGATION_* kconfig files (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for GDS (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Remove GDS Force Kconfig option (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for SSB (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for Spectre V2 (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for SRBDS (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for Spectre v1 (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for RETBLEED (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for L1TF (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for MMIO Stable Data (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for TAA (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Add a separate config for MDS (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpufeatures: Flip the /proc/cpuinfo appearance logic (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/bugs: Switch to new Intel CPU model defines (Waiman Long) [RHEL-83896 RHEL-83905]
- x86/cpu: Use EXPORT_PER_CPU_SYMBOL_GPL() for x86_spec_ctrl_current (Waiman Long) [RHEL-83896 RHEL-83905]
- docs: move x86 documentation into Documentation/arch/ (Waiman Long) [RHEL-83896 RHEL-83905]
- cxgb4: Avoid removal of uninserted tid JIRA: https://issues.redhat.com/browse/RHEL-112152 (Jakub Ramaseuski)
[5.14.0-570.61.1]
- NFS: Extend rdirplus mount option with 'force|none' (CKI Backport Bot) [RHEL-118450]
- sched: Fix stop_one_cpu_nowait() vs hotplug (Luis Claudio R. Goncalves) [RHEL-116212]
- s390/hypfs: Enable limited access during lockdown (CKI Backport Bot) [RHEL-114433]
- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (CKI Backport Bot) [RHEL-114433]
- debugfs: lockdown: Allow reading debugfs files that are not world readable (Mete Durlu) [RHEL-114433]
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
| Oracle Linux 9 (x86_64) | kernel-5.14.0-570.62.1.0.2.el9_6.src.rpm | 4762d5f56fb80c52a8b3bfe4596f69a75e86a1099e5dccb16c0bf0505d1104fb | - | ol9_x86_64_MODRHCK |
| kernel-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 44baac440cb49724cad17ae15ea33aaa12b7c3414c11b0c20fd43b13dea0edcb | - | ol9_x86_64_MODRHCK | |
| kernel-abi-stablelists-5.14.0-570.62.1.0.2.el9_6.noarch.rpm | 57a04e220fa02954536268d8061dcb94270347b72b4e7a1cb3783e5b9b85ecbe | - | ol9_x86_64_MODRHCK | |
| kernel-core-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 7eb2406defa344076a41e36552a3177260bf00f3869ef2beecfa0a18f5304929 | - | ol9_x86_64_MODRHCK | |
| kernel-cross-headers-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 1e0ad5adbf792315d7372311545c1b40368c883159bbe264bdfa6b0c3ac766c0 | - | ol9_x86_64_MODRHCK | |
| kernel-debug-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 8e75ac5b4a6be9e9da6253fb8e341fa29a70e41b7fa67cfa83dc723d04daa761 | - | ol9_x86_64_MODRHCK | |
| kernel-debug-core-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 0e893d379ba36305214dafd5708a877abc6f668e553b6cac225b01434d72ba90 | - | ol9_x86_64_MODRHCK | |
| kernel-debug-devel-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 666af089dc285ef04a1542b5983a4f3cada63ae41e1066e615f4c1776cbc792a | - | ol9_x86_64_MODRHCK | |
| kernel-debug-devel-matched-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | e07f44a97b08950df92fc9c722e8ebe3c3b7b92f531bfc9819aa49a127de276a | - | ol9_x86_64_MODRHCK | |
| kernel-debug-modules-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 610d12a14a8f6bf420d3532671baba5eb374e52285c51b76455f5cd850615770 | - | ol9_x86_64_MODRHCK | |
| kernel-debug-modules-core-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | c8548b3905c033ee75eca8d3bcd3a9d9f67bdb2b35a6699d55e1b08540beca30 | - | ol9_x86_64_MODRHCK | |
| kernel-debug-modules-extra-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 7d13089623f82080a90f6094923bec867badf0474fedbccde4250b8733233ac6 | - | ol9_x86_64_MODRHCK | |
| kernel-debug-uki-virt-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | c4debfbc836bff300a28f244de4e99a9120e44c719a4a79bd9c4136e647a6d04 | - | ol9_x86_64_MODRHCK | |
| kernel-devel-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 8a38e34c9499d16f3b532e3bef3ccca9452a32d87ff2ee4ee499986195f12955 | - | ol9_x86_64_MODRHCK | |
| kernel-devel-matched-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | e06dd5dc6f23df6152c41b428d7b114a4d888ac2d39af5c13aca9159e8282208 | - | ol9_x86_64_MODRHCK | |
| kernel-doc-5.14.0-570.62.1.0.2.el9_6.noarch.rpm | de78b40f44f0a10e98ac0267e88ebf9602c4bd2a6e36c8a04e5d51458c0b8fcb | - | ol9_x86_64_MODRHCK | |
| kernel-headers-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | b05f0289aff606c4241429e6f8d1a715cefaa70421baae9d6dd9913bf69ce795 | - | ol9_x86_64_MODRHCK | |
| kernel-modules-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 098af425955d5c0f0842fb4b287cfeace0599b4bbc3abeb9036e4cf44548b559 | - | ol9_x86_64_MODRHCK | |
| kernel-modules-core-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | efe7cbeb9962399ee04f5225446d7c35b639a2df692600529932804b66b9c22b | - | ol9_x86_64_MODRHCK | |
| kernel-modules-extra-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 62f5f4783326f1fbe07dcb8e629cc7e4cd4c22986e24af980d4861ec5763e721 | - | ol9_x86_64_MODRHCK | |
| kernel-tools-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 12cb449b5e79f8e87283e4afff9c6fa331fdc9be0e2f620c3d082dc658bd9590 | - | ol9_x86_64_MODRHCK | |
| kernel-tools-libs-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 1299e8c080a971616b345930fc290524df18d53493dd89ccb5e2747f3c9b8a5f | - | ol9_x86_64_MODRHCK | |
| kernel-tools-libs-devel-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | cd3c13cc6472f3a6134c1e8cd5dfa88c9f9efc390c9f20be344eef4b090eb926 | - | ol9_x86_64_MODRHCK | |
| kernel-uki-virt-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | a5f6bf9c3beb83ef54fbef1875973385e0aabc973aa69ebd00e2d2458dd7e1ae | - | ol9_x86_64_MODRHCK | |
| kernel-uki-virt-addons-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 8ae020cb7c3120fa4af45451d9cb09536edd3019e02104a72f7f2f820181d83a | - | ol9_x86_64_MODRHCK | |
| libperf-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 29aec88b7d5650c1d2230eccdce2d2256600f74097ba4110a5ff862cf23e518b | - | ol9_x86_64_MODRHCK | |
| perf-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | f2e6b06695fce2177d3ce1078c45718a1d5e7e9571ba019ea266e20bd3db2183 | - | ol9_x86_64_MODRHCK | |
| python3-perf-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | 14d1fb9dfc8b4bbfc8e54c1b4a84e4fd34376a424e344bfc035532214dd8847d | - | ol9_x86_64_MODRHCK | |
| rtla-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | a3f51877cb259661cbddcada6de5942cd2ccfa4f399f02fc8bfe3f374bb0ca1d | - | ol9_x86_64_MODRHCK | |
| rv-5.14.0-570.62.1.0.2.el9_6.x86_64.rpm | edea2aaf70221b8045c43ad50ed6559b89eb4cbdb4ebd4e190cf43e525b06636 | - | ol9_x86_64_MODRHCK | |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team