ELSA-2019-4509

ELSA-2019-4509 - Unbreakable Enterprise kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2019-01-15

Description


[4.14.35-1844.1.3]
- net: rds: fix rds_ib_sysctl_max_recv_allocation error (Zhu Yanjun) [Orabug: 29003422]
- nfs: dont dirty kernel pages read by direct-io (Dave Kleikamp) [Orabug: 29122062]
- KVM: X86: Fix scan ioapic use-before-initialization (Wanpeng Li) [Orabug: 29026132] {CVE-2018-19407}
- hugetlb: take PMD sharing into account when flushing tlb/caches (Mike Kravetz) [Orabug: 28951436]
- mm: migration: fix migration of huge PMD shared pages (Mike Kravetz) [Orabug: 28951436]
- mm/mmu_notifier: avoid double notification when it is useless (Jerome Glisse) [Orabug: 28951436]

[4.14.35-1844.1.2]
- ALSA: usb-audio: Fix UAF decrement if card has no live interfaces in card.c (Hui Peng) [Orabug: 29042979] {CVE-2018-19824}
- arm64/kernel: kaslr: reduce module randomization range to 4 GB (Ard Biesheuvel) [Orabug: 28954789]
- xfs: enhance dinode verifier (Eric Sandeen) [Orabug: 28997653] {CVE-2018-10322}
- xfs: move inode fork verifiers to xfs_dinode_verify (Darrick J. Wong) [Orabug: 28997653] {CVE-2018-10322}
- Revert 'xfs: move inode fork verifiers to xfs_dinode_verify' (Shan Hai) [Orabug: 28997653]
- Revert 'xfs: enhance dinode verifier' (Shan Hai) [Orabug: 28997653]

[4.14.35-1844.1.1]
- arm64: disable /dev/port on 64 bit ARM (Eric Saint-Etienne) [Orabug: 28961247]
- crypto: ccp - add timeout support in the SEV command (Brijesh Singh) [Orabug: 29029018]
- crypto: ccp - Add GET_ID SEV command (Janakarajan Natarajan) [Orabug: 29029018]
- crypto: ccp - Add DOWNLOAD_FIRMWARE SEV command (Janakarajan Natarajan) [Orabug: 29029018]
- net: phy: mdio-bcm-unimac: fix potential NULL dereference in unimac_mdio_probe() (Wei Yongjun) [Orabug: 27677743] {CVE-2018-8043}
- vti6: remove !skb->ignore_df check from vti6_xmit() (Alexey Kodanev) [Orabug: 28940590]
- A/A failback does not work in concert with ibacm (Hakon Bugge) [Orabug: 28972800]
- ACPICA: Reference Counts: increase max to 0x4000 for large servers (Erik Schmauss) [Orabug: 29019053]

[4.14.35-1844.1.0]
- wil6210: missing length check in wmi_set_ie (Lior David) [Orabug: 28951264] {CVE-2018-5848}
- [PATCH UEK5 u1 v3] dtrace: add DTRACEACT_PCAP for packet capture for later pcap_dump() (Alan Maguire) [Orabug: 28951771]
- floppy: Do not copy a kernel pointer to user memory in FDGETPRM ioctl (Andy Whitcroft) {CVE-2018-7755} {CVE-2018-7755}
- [PATCH UEK5 u1 v2] dtrace: fix ip provider inconsistencies between IPv4/IPv6 (Alan Maguire) [Orabug: 28956807]
- x86/speculation: Make enhanced IBRS the default spectre v2 mitigation (Alejandro Jimenez) [Orabug: 28992002]
- x86/speculation: Enable enhanced IBRS usage (Alejandro Jimenez) [Orabug: 28992002]
- x86/speculation: functions for supporting enhanced IBRS (Alejandro Jimenez) [Orabug: 28992002]
- Add forward declaration of tlb_flush, required for asm-generic. (Jack Vogel) [Orabug: 28866513]
- x86/mm: Page size aware flush_tlb_mm_range() (Peter Zijlstra) [Orabug: 28866513]
- mm/memory: Move mmu_gather and TLB invalidation code into its own file (Peter Zijlstra) [Orabug: 28866513]
- asm-generic/tlb: Track which levels of the page tables have been cleared (Will Deacon) [Orabug: 28866513]
- asm-generic/tlb: Track freeing of page-table directories in struct mmu_gather (Peter Zijlstra) [Orabug: 28866513]
- mm: mmu_notifier fix for tlb_end_vma (Nicholas Piggin) [Orabug: 28866513]
- mm: update comment describing tlb_gather_mmu (Mike Rapoport) [Orabug: 28866513]


Related CVEs


CVE-2018-10322
CVE-2018-8043
CVE-2018-19407
CVE-2018-7755
CVE-2018-19824
CVE-2018-5848

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (aarch64) kernel-uek-4.14.35-1844.1.3.el7uek.src.rpmf3122334d115e37e8c1006df93f9cd5305e8e02f756b5b9be3b981e5fbad2212ELSA-2025-20190ol7_aarch64_latest
kernel-uek-4.14.35-1844.1.3.el7uek.aarch64.rpm24627a8d23dcb16025ba8dd0657d0f175d0f7d0f1abcaef3017e93dd8c092bc5ELSA-2025-20190ol7_aarch64_latest
kernel-uek-debug-4.14.35-1844.1.3.el7uek.aarch64.rpme6af266e75239dae6e43742a5722da921c35f57a44a27a421b5993f0dc8bd413ELSA-2025-20190ol7_aarch64_latest
kernel-uek-debug-devel-4.14.35-1844.1.3.el7uek.aarch64.rpm45de11eac8a21cba1cef9636b9f9f908bc0f5c1f4cdb61a11fe8cca190f31166ELSA-2025-20190ol7_aarch64_latest
kernel-uek-devel-4.14.35-1844.1.3.el7uek.aarch64.rpm338b4a287f172f8e3aa26eba1df10000ef45981675ff550010a541280c6a123cELSA-2025-20190ol7_aarch64_latest
kernel-uek-headers-4.14.35-1844.1.3.el7uek.aarch64.rpm8af3a28c4a3fbd6eec91669a01192fd1be2be7d2ba09675e8c915efce198d32eELBA-2025-20014ol7_aarch64_latest
kernel-uek-tools-4.14.35-1844.1.3.el7uek.aarch64.rpm8c242f0bbec6676ea5baf51811ac7d0f930d19f823f1fc8f758e92e84b3b6a39ELSA-2025-20190ol7_aarch64_latest
kernel-uek-tools-libs-4.14.35-1844.1.3.el7uek.aarch64.rpmc1c9ec23187a8213d191cef78b16c7ee13a5d606f0b8ace0d8233bed13e3fd85ELSA-2025-20019ol7_aarch64_latest
kernel-uek-tools-libs-devel-4.14.35-1844.1.3.el7uek.aarch64.rpm71954644963e3f37adb21789809a8c7a6e73915213854a3ade5806bd826928a3ELBA-2025-20014ol7_aarch64_latest
perf-4.14.35-1844.1.3.el7uek.aarch64.rpm5e9514a2739322fc27068b43816d04b6faf4463affab022d42dbd009227eaff7ELSA-2025-20019ol7_aarch64_latest
python-perf-4.14.35-1844.1.3.el7uek.aarch64.rpm730b50146a0e7aefeec7d504a4b6c445df0389213283dfcb141536050a6bfdd0ELSA-2025-20019ol7_aarch64_latest
Oracle Linux 7 (x86_64) kernel-uek-4.14.35-1844.1.3.el7uek.src.rpmf3122334d115e37e8c1006df93f9cd5305e8e02f756b5b9be3b981e5fbad2212ELSA-2025-20190ol7_x86_64_UEKR5_archive
kernel-uek-4.14.35-1844.1.3.el7uek.x86_64.rpm52e340a376a7e0ba85532e686e78adbc0afc93cc3a8ced98819c5a72d2f64141ELSA-2025-20190ol7_x86_64_UEKR5_archive
kernel-uek-debug-4.14.35-1844.1.3.el7uek.x86_64.rpm318c7b7e283796eda338deb2834590b92c22b7b3e72c19fdccba3656683c6f3dELSA-2025-20190ol7_x86_64_UEKR5_archive
kernel-uek-debug-devel-4.14.35-1844.1.3.el7uek.x86_64.rpm093dc6f52151010cfe79ac11963490a40b80be91c6d9a5558b35282a6ae572bcELSA-2025-20190ol7_x86_64_UEKR5_archive
kernel-uek-devel-4.14.35-1844.1.3.el7uek.x86_64.rpmb92cc821da25bf2482c717e84c9c33acfa6b6be966b172774bb412ff19a4aac3ELSA-2025-20190ol7_x86_64_UEKR5_archive
kernel-uek-doc-4.14.35-1844.1.3.el7uek.noarch.rpm39cb5d89384b47378fe403152b35b354e8f16a360edc4d1a3169a3ec7366a1f0ELSA-2025-20190ol7_x86_64_UEKR5_archive
kernel-uek-tools-4.14.35-1844.1.3.el7uek.x86_64.rpm441f72ef70fc34746dc2a4315e93d26015834329c94a03320d15e5f3b4d237ccELSA-2025-20190ol7_x86_64_UEKR5_archive



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete