ELSA-2021-2725

ELSA-2021-2725 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2021-07-21

Description


[3.10.0-1160.36.2.OL7]
- Update Oracle Linux certificates (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was compiled into kernel (olkmod_signing_key.x509)(alexey.petrenko@oracle.com)
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-2.0.9
- Update oracle(kernel-sig-key) value to match new certificate (Ilya Okomin)

[3.10.0-1160.36.2]
- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]

[3.10.0-1160.36.1]
- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)

[3.10.0-1160.35.1]
- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]

[3.10.0-1160.34.1]
- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]

[3.10.0-1160.33.1]
- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}

[3.10.0-1160.32.1]
- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]


Related CVEs


CVE-2020-11668
CVE-2019-20934
CVE-2021-33909
CVE-2021-33034
CVE-2021-33033

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) kernel-3.10.0-1160.36.2.el7.src.rpm63dad5cb74abb5b94772b6f8e0f08621-
bpftool-3.10.0-1160.36.2.el7.x86_64.rpm125f4b296d0edeb90231249489e85894-
kernel-3.10.0-1160.36.2.el7.x86_64.rpm440e95515afa46773ae7418bf15059a6-
kernel-abi-whitelists-3.10.0-1160.36.2.el7.noarch.rpmf79a1142f2c44634c9eb6e206b81aaff-
kernel-debug-3.10.0-1160.36.2.el7.x86_64.rpm7f19cf036b7ea6e0ecf9c2cc715abc0a-
kernel-debug-devel-3.10.0-1160.36.2.el7.x86_64.rpm09a1a70509cd3d0acaf1d53c9e615fed-
kernel-devel-3.10.0-1160.36.2.el7.x86_64.rpm1e90f863c10cfb7a201b68eb72fa0314-
kernel-doc-3.10.0-1160.36.2.el7.noarch.rpma6ce45244407a3c460f85cb35a3635d7-
kernel-headers-3.10.0-1160.36.2.el7.x86_64.rpm8d11e36db88b7f3b3896d263548e6907-
kernel-tools-3.10.0-1160.36.2.el7.x86_64.rpm64ed3877026f74957181bda8242f994b-
kernel-tools-libs-3.10.0-1160.36.2.el7.x86_64.rpm273f5131edadf347d64da41490017a68-
kernel-tools-libs-devel-3.10.0-1160.36.2.el7.x86_64.rpma1b625bdbbf6806dd0cb7e9727d2a1f1-
perf-3.10.0-1160.36.2.el7.x86_64.rpm107d635c239547a75a6855b0d5851ce3-
python-perf-3.10.0-1160.36.2.el7.x86_64.rpm4836c047058d402065ecf97d2d892bd1-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete