ELSA-2021-2714

ELSA-2021-2714 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2021-07-21

Description


[4.18.0-305.10.2_4.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-11.0.5

[4.18.0-305.10.2_4]
- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975181 1975182] {CVE-2021-33909}

[4.18.0-305.10.1_4]
- igbvf: amend removal of MODULE_VERSION (Corinna Vinschen) [1969920 1955752]
- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971464 1971488] {CVE-2021-32399}
- scsi: ibmvfc: Free channel_setup_buf during device tear down (Steve Best) [1964697 1938102]
- i40e: Fix parameters in aq_get_phy_register() (Stefan Assmann) [1967099 1907852]

[4.18.0-305.9.1_4]
- ixgbevf: Amend commit acf03026ec5a to include a version in module info. (Ken Cox) [1969911 1955764]
- CI: Merge configuration (Veronika Kabatova)
- igc: amend removal of MODULE_VERSION (Corinna Vinschen) [1969921 1955755]
- igb: amend removal of MODULE_VERSION (Corinna Vinschen) [1969919 1955748]
- locking/qrwlock: Fix ordering in queued_write_lock_slowpath() (Waiman Long) [1964419 1950110]
- scsi: qedf: Do not put host in qedf_vport_create() unconditionally (Nilesh Javali) [1974968 1899384]

[4.18.0-305.8.1_4]
- iavf: amend removal of MODULE_VERSION (Stefan Assmann) [1969925 1955738]
- ixgbe: Amend commit acf03026ec5a to include a version string in module info. (Ken Cox) [1969922 1955759]
- i40e: amend removal of MODULE_VERSION (Stefan Assmann) [1969923 1955736]
- redhat/configs: Add CONFIG_PINCTRL_EMMITSBURG (David Arcari) [1963984 1959506]
- redhat/configs: Remove CONFIG_EMMITSBURG (David Arcari) [1963984 1959506]
- netlink: add tracepoint at NL_SET_ERR_MSG (Marcelo Ricardo Leitner) [1972938 1956983]
- Revert '[netdrv] net/intel: remove driver versions from Intel drivers' (Jonathan Toppins) [1969917 1955745]
- Amends commit ea6244cc248b to include a version string in module info. (Ken Cox) [1969915 1955726]
- Revert '[netdrv] net/broadcom: Clean broadcom code from driver versions' (Jonathan Toppins) [1969914 1955721]
- ena: revert removal of MODULE_VERSION from ena (Petr Oros) [1969913 1955712]
- fm10k: amend removal of MODULE_VERSION (Vladis Dronov) [1969910 1955730]
- net/sched: act_ct: Offload connections with commit action (Marcelo Ricardo Leitner) [1968679 1965817]
- netfilter: flowtable: Remove redundant hw refresh bit (Marcelo Ricardo Leitner) [1968679 1965817]


Related CVEs


CVE-2021-32399
CVE-2021-33909

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) kernel-4.18.0-305.10.2.el8_4.src.rpmb8026694aa5c22ebd19433ab6dc40387-
bpftool-4.18.0-305.10.2.el8_4.aarch64.rpm444053e5c5a7e44dbbbb03ebb9d790cf-
kernel-cross-headers-4.18.0-305.10.2.el8_4.aarch64.rpm8b8a22a8d006e3d0c5f8bd6f03c71785-
kernel-headers-4.18.0-305.10.2.el8_4.aarch64.rpmc8b6f29e4f9b497c2d5326f5f089c16d-
kernel-tools-4.18.0-305.10.2.el8_4.aarch64.rpm665beef85ec5cb781b836bad11b698ce-
kernel-tools-libs-4.18.0-305.10.2.el8_4.aarch64.rpm6128610fd5f58d2803c7b6393ce26b18-
kernel-tools-libs-devel-4.18.0-305.10.2.el8_4.aarch64.rpmf4fa1f7da6f9722ea68bb92c61b7a571-
perf-4.18.0-305.10.2.el8_4.aarch64.rpm1a4d3ec0bc5465d1bfd2cb4e256e5fad-
python3-perf-4.18.0-305.10.2.el8_4.aarch64.rpmf3c381880ec9f287e6268e1c62732c54-
Oracle Linux 8 (x86_64) kernel-4.18.0-305.10.2.el8_4.src.rpmb8026694aa5c22ebd19433ab6dc40387-
bpftool-4.18.0-305.10.2.el8_4.x86_64.rpm201710537471866b9634c6614f48c1f7-
kernel-4.18.0-305.10.2.el8_4.x86_64.rpmc03015f5477a31e5246f10cc27b16fe2-
kernel-abi-stablelists-4.18.0-305.10.2.el8_4.noarch.rpma179046a71f1606c0f5d8271d6ad1ba9-
kernel-core-4.18.0-305.10.2.el8_4.x86_64.rpm35d64c9783a800a0104c0c4a82604dc6-
kernel-cross-headers-4.18.0-305.10.2.el8_4.x86_64.rpm00180ace6a785ee4407ff5ce8d5f0dd1-
kernel-debug-4.18.0-305.10.2.el8_4.x86_64.rpmd41331e780ded17acef90da5039319b1-
kernel-debug-core-4.18.0-305.10.2.el8_4.x86_64.rpmeb838b51b17ee88b4201bbaebbfebb05-
kernel-debug-devel-4.18.0-305.10.2.el8_4.x86_64.rpm59b6483f81d9a72dd36627424a0f2a50-
kernel-debug-modules-4.18.0-305.10.2.el8_4.x86_64.rpm662c6411a536ee1f073b85ee7e09ca6d-
kernel-debug-modules-extra-4.18.0-305.10.2.el8_4.x86_64.rpm8a86a52849ce9fb94b9a86c473510a73-
kernel-devel-4.18.0-305.10.2.el8_4.x86_64.rpmb4759d05de5f8046651ddcd7c2bd7fe3-
kernel-doc-4.18.0-305.10.2.el8_4.noarch.rpm267d6f42926292e110cb558423ba104f-
kernel-headers-4.18.0-305.10.2.el8_4.x86_64.rpm88d24ce96bf5323251064ca669431dad-
kernel-modules-4.18.0-305.10.2.el8_4.x86_64.rpm317f6e6d98ff15b3b4b738a2a971201e-
kernel-modules-extra-4.18.0-305.10.2.el8_4.x86_64.rpm48a373bf4e61d8726a069e839d934a29-
kernel-tools-4.18.0-305.10.2.el8_4.x86_64.rpm9f71526b4184921b84f9ccce513f9b1d-
kernel-tools-libs-4.18.0-305.10.2.el8_4.x86_64.rpma73c0ffbd95d7980ab464f5af0d63f35-
kernel-tools-libs-devel-4.18.0-305.10.2.el8_4.x86_64.rpm50fc3980abdda6573e2fb18601ac5cf7-
perf-4.18.0-305.10.2.el8_4.x86_64.rpmfae9607309bc8797e7e468daa9e97400-
python3-perf-4.18.0-305.10.2.el8_4.x86_64.rpma8fc30aca156cdef7e4fe5f0c7a05936-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete