ELSA-2021-1071

ELSA-2021-1071 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2021-04-07

Description


[3.10.0-1160.24.1.OL7]
- Update Oracle Linux certificates (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was compiled into kernel (olkmod_signing_key.x509)(alexey.petrenko@oracle.com)
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-2.0.9
- Update oracle(kernel-sig-key) value to match new certificate (Ilya Okomin)

[3.10.0-1160.24.1]
- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)

[3.10.0-1160.23.1]
- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]

[3.10.0-1160.22.1]
- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]


Related CVEs


CVE-2021-27363
CVE-2021-27364
CVE-2021-27365

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) kernel-3.10.0-1160.24.1.el7.src.rpm54e3b9ea45f72ead37d5ee0cd3f72eff-
bpftool-3.10.0-1160.24.1.el7.x86_64.rpm8182d39906d9404142977641367b8a1c-
kernel-3.10.0-1160.24.1.el7.x86_64.rpm7c752769d31b63003afdb0023632a935-
kernel-abi-whitelists-3.10.0-1160.24.1.el7.noarch.rpm5d2150ffcd28266b20952fa8f215e0bc-
kernel-debug-3.10.0-1160.24.1.el7.x86_64.rpmeeed6354fb637d7d6dc49dc2a15b9e09-
kernel-debug-devel-3.10.0-1160.24.1.el7.x86_64.rpmb99517f4a1b720bdddfd6d00441ad318-
kernel-devel-3.10.0-1160.24.1.el7.x86_64.rpm2643719310ea58dc066437df808f4497-
kernel-doc-3.10.0-1160.24.1.el7.noarch.rpm2a3db8328f6abcb0bdde6885308dd1a0-
kernel-headers-3.10.0-1160.24.1.el7.x86_64.rpmb8f5697a4c92b2f3a4e24321a3f0639b-
kernel-tools-3.10.0-1160.24.1.el7.x86_64.rpmdb090fb87108d69f5660e128b5d54042-
kernel-tools-libs-3.10.0-1160.24.1.el7.x86_64.rpmfadd9bbaf9861d0904de45bead4f5e1e-
kernel-tools-libs-devel-3.10.0-1160.24.1.el7.x86_64.rpme79bec11f52bedeaeba4ab8d0eb4b279-
perf-3.10.0-1160.24.1.el7.x86_64.rpm15d54e0caf8b208174170c30755ff98e-
python-perf-3.10.0-1160.24.1.el7.x86_64.rpm7104b981b14cf6a0812402a4ca4acc28-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete