ELSA-2018-4261

ELSA-2018-4261 - Unbreakable Enterprise kernel security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2018-10-24

Description


[4.1.12-124.20.7]
- Revert 'rds: RDS (tcp) hangs on sendto() to unresponding address' (Brian Maly) [Orabug: 28837953]

[4.1.12-124.20.6]
- x86/speculation: Retpoline should always be available on Skylake (Alexandre Chartre) [Orabug: 28801831]

[4.1.12-124.20.5]
- x86/speculation: Add sysfs entry to enable/disable retpoline (Alexandre Chartre) [Orabug: 28607548]
- x86/speculation: Switch to IBRS when loading a non-retpoline module (Alexandre Chartre) [Orabug: 28607548]
- x86/speculation: Remove unnecessary retpoline alternatives (Alexandre Chartre) [Orabug: 28607548]
- x86/speculation: Use static key to enable/disable retpoline (Alexandre Chartre) [Orabug: 28607548]
- locking/static_keys: Provide DECLARE and well as DEFINE macros (Tony Luck) [Orabug: 28607548]
- jump_label: remove bug.h, atomic.h dependencies for HAVE_JUMP_LABEL (Jason Baron) [Orabug: 28607548]
- locking/static_key: Fix concurrent static_key_slow_inc() (Paolo Bonzini) [Orabug: 28607548]
- jump_label: make static_key_enabled() work on static_key_true/false types too (Tejun Heo) [Orabug: 28607548]
- locking/static_keys: Fix up the static keys documentation (Jonathan Corbet) [Orabug: 28607548]
- locking/static_keys: Fix a silly typo (Jonathan Corbet) [Orabug: 28607548]
- jump label, locking/static_keys: Update docs (Jason Baron) [Orabug: 28607548]
- x86/asm: Add asm macros for static keys/jump labels (Andy Lutomirski) [Orabug: 28607548]
- x86/asm: Error out if asm/jump_label.h is included inappropriately (Andy Lutomirski) [Orabug: 28607548]
- jump_label/x86: Work around asm build bug on older/backported GCCs (Peter Zijlstra) [Orabug: 28607548]
- locking/static_keys: Add a new static_key interface (Peter Zijlstra) [Orabug: 28607548]
- locking/static_keys: Rework update logic (Peter Zijlstra) [Orabug: 28607548]
- jump_label: Add jump_entry_key() helper (Peter Zijlstra) [Orabug: 28607548]
- jump_label, locking/static_keys: Rename JUMP_LABEL_TYPE_* and related helpers to the static_key* pattern (Peter Zijlstra) [Orabug: 28607548]
- jump_label: Rename JUMP_LABEL_{EN,DIS}ABLE to JUMP_LABEL_{JMP,NOP} (Peter Zijlstra) [Orabug: 28607548]
- module, jump_label: Fix module locking (Peter Zijlstra) [Orabug: 28607548]
- x86/speculation: Protect against userspace-userspace spectreRSB (Jiri Kosina) [Orabug: 28631590] {CVE-2018-15572}
- x86/spectre_v2: Remove remaining references to lfence mitigation (Alejandro Jimenez) [Orabug: 28631590] {CVE-2018-15572}
- Revert 'md: allow a partially recovered device to be hot-added to an array.' (NeilBrown) [Orabug: 28702623]
- x86/bugs: ssbd_ibrs_selected called prematurely (Daniel Jordan) [Orabug: 28788839]
- net/mlx4_core: print firmware version during driver loading (Qing Huang) [Orabug: 28809377]
- mm: numa: Do not trap faults on shared data section pages. (Henry Willard) [Orabug: 28814880]
- hugetlbfs: dirty pages as they are added to pagecache (Mike Kravetz) [Orabug: 28813968]

[4.1.12-124.20.4]
- rds: RDS (tcp) hangs on sendto() to unresponding address (Ka-Cheong Poon) [Orabug: 28762608]
- nfs: fix a deadlock in nfs client initialization (Scott Mayhew) [Orabug: 28486463]
- infiniband: fix a possible use-after-free bug (Cong Wang) [Orabug: 28774517] {CVE-2018-14734}


Related CVEs


CVE-2018-14734
CVE-2018-15572

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (x86_64) kernel-uek-4.1.12-124.20.7.el6uek.src.rpma1f786d1d5e2906567d2386fd7678397-
kernel-uek-4.1.12-124.20.7.el6uek.x86_64.rpm5a23dbc1a2f4d3e5bcbbf9730a52e663-
kernel-uek-debug-4.1.12-124.20.7.el6uek.x86_64.rpm3c258f180a3117ee0c6db005b7ef569c-
kernel-uek-debug-devel-4.1.12-124.20.7.el6uek.x86_64.rpma307305a2e2c9ac67c1f7ea41293e855-
kernel-uek-devel-4.1.12-124.20.7.el6uek.x86_64.rpmec93c04b3f59e8a612384dfa576e69cc-
kernel-uek-doc-4.1.12-124.20.7.el6uek.noarch.rpm0bad836d35fd3067553603f3715e5373-
kernel-uek-firmware-4.1.12-124.20.7.el6uek.noarch.rpma8ae6d95d84eeb256c57609cf54926fd-
Oracle Linux 7 (x86_64) kernel-uek-4.1.12-124.20.7.el7uek.src.rpm9ca6954cb72f0714d3badefe1665f945-
kernel-uek-4.1.12-124.20.7.el7uek.x86_64.rpma17240f6d84f0e205ef11d99892efd1b-
kernel-uek-debug-4.1.12-124.20.7.el7uek.x86_64.rpm2061804ab582b03c5aa52885b35111df-
kernel-uek-debug-devel-4.1.12-124.20.7.el7uek.x86_64.rpm59a1e19571cb524a031e68b001e4aa0d-
kernel-uek-devel-4.1.12-124.20.7.el7uek.x86_64.rpm72353c95c8a3656d4b37df37e260d66e-
kernel-uek-doc-4.1.12-124.20.7.el7uek.noarch.rpm61c9c921928bbe6a7e874c5499b9f3ef-
kernel-uek-firmware-4.1.12-124.20.7.el7uek.noarch.rpm294f0f7270af55e5de53c931b7202ffa-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete