Type: | SECURITY |
Severity: | IMPORTANT |
Release Date: | 2022-06-30 |
[5.14.0-70.17.1.0.1_0.OL9]
- lockdown: also lock down previous kgdb use (Daniel Thompson) [Orabug: 34290418] {CVE-2022-21499}
[5.14.0-70.17.1_0.OL9]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 < 15.3-1.0.4
- Remove nmap references from kernel (Mridula Shastry) [Orabug: 34313944]
[5.14.0-70.17.1_0]
- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2092994 2092995] {CVE-2022-1966}
- thunderx nic: mark device as unmaintained (Inigo Huguet) [2092638 2060285]
- pseries/eeh: Fix the kdump kernel crash during eeh_pseries_init (Steve Best) [2092255 2067770]
- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087963 2087964] {CVE-2022-1729}
- spec: Fix separate tools build (Jiri Olsa) [2090852 2054579]
- mm: lru_cache_disable: replace work queue synchronization with synchronize_rcu (Marcelo Tosatti) [2086963 2033500]
[5.14.0-70.16.1_0]
- dm integrity: fix memory corruption when tag_size is less than digest size (Benjamin Marzinski) [2082187 2081778]
[5.14.0-70.15.1_0]
- CI: Use zstream builder image (Veronika Kabatova)
- tcp: drop the hash_32() part from the index calculation (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: increase source port perturb table to 2^16 (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: dynamically allocate the perturb table used by source ports (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: add small random increments to the source port (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: resalt the secret every 10 seconds (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: use different parts of the port_offset for index and offset (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- secure_seq: use the 64 bits of the siphash for port offset calculation (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- Revert 'netfilter: conntrack: tag conntracks picked up in local out hook' (Florian Westphal) [2085480 2061850]
- Revert 'netfilter: nat: force port remap to prevent shadowing well-known ports' (Florian Westphal) [2085480 2061850]
- redhat/koji/Makefile: Decouple koji Makefile from Makefile.common (Andrea Claudi)
- redhat: fix make {distg-brew,distg-koji} (Andrea Claudi)
- esp: limit skb_page_frag_refill use to a single page (Sabrina Dubroca) [2082950 2082951] {CVE-2022-27666}
- esp: Fix possible buffer overflow in ESP transformation (Sabrina Dubroca) [2082950 2082951] {CVE-2022-27666}
- sctp: use the correct skb for security_sctp_assoc_request (Ondrej Mosnacek) [2084044 2078856]
- security: implement sctp_assoc_established hook in selinux (Ondrej Mosnacek) [2084044 2078856]
- security: add sctp_assoc_established hook (Ondrej Mosnacek) [2084044 2078856]
- security: call security_sctp_assoc_request in sctp_sf_do_5_1D_ce (Ondrej Mosnacek) [2084044 2078856]
- security: pass asoc to sctp_assoc_request and sctp_sk_clone (Ondrej Mosnacek) [2084044 2078856]
[5.14.0-70.14.1_0]
- PCI: hv: Propagate coherence from VMbus device to PCI device (Vitaly Kuznetsov) [2074830 2068432]
- Drivers: hv: vmbus: Propagate VMbus coherence to each VMbus device (Vitaly Kuznetsov) [2074830 2068432]
- redhat: rpminspect: disable 'patches' check for known empty patch files (Herton R. Krzesinski)
- redhat/configs: make SHA512_arch algos and CRYPTO_USER built-ins (Vladis Dronov) [2072643 2070624]
- CI: Drop baseline runs (Veronika Kabatova)
CVE-2022-27666 |
CVE-2022-1729 |
CVE-2022-1966 |
CVE-2022-1012 |
Release/Architecture | Filename | MD5sum | Superseded By Advisory |
Oracle Linux 9 (aarch64) | kernel-5.14.0-70.17.1.0.1.el9_0.src.rpm | 566ffd8bc13caeaee59b35bcad20f657 | - |
bpftool-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | ede22da78af2996bfe9bffe5659745e7 | - | |
kernel-cross-headers-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | 2424219722258837c34fc57cfb4f5964 | - | |
kernel-headers-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | f75b590eb048431129d1ca9c307adeca | - | |
kernel-tools-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | e40f34777e7483dc3e4af8fb733c1f43 | - | |
kernel-tools-libs-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | f89dff4839859db9639c5cdb025b5c72 | - | |
kernel-tools-libs-devel-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | 1a24297cfb3c266a25f076d622159cc0 | - | |
perf-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | d33b9ff84cd89f738008fa5799c15b5e | - | |
python3-perf-5.14.0-70.17.1.0.1.el9_0.aarch64.rpm | f20b85b050588b00319bac5c72a58f52 | - | |
Oracle Linux 9 (x86_64) | kernel-5.14.0-70.17.1.0.1.el9_0.src.rpm | 566ffd8bc13caeaee59b35bcad20f657 | - |
bpftool-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | f9972ee57f3e4cefa9706498ef9f3e26 | - | |
kernel-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 742b60286050e2f0004edef7de501f95 | - | |
kernel-abi-stablelists-5.14.0-70.17.1.0.1.el9_0.noarch.rpm | e8b09b1f324f763e95d7f6dd4f94d0b9 | - | |
kernel-core-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 924aa9e407b11f095c467154e69e06aa | - | |
kernel-cross-headers-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 10f5965dababfa271d539076d2ceea59 | - | |
kernel-debug-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 0d5ebf2d75602ade16a36675e502b524 | - | |
kernel-debug-core-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 3703e02a1abbfc48b650e9b80c3d5659 | - | |
kernel-debug-devel-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | bdc1ac7b86c76d617c983435251426e9 | - | |
kernel-debug-devel-matched-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | b900d686ba01861a9547d356f851f1f1 | - | |
kernel-debug-modules-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 6e171ea7d4cf619ec431310b2f886519 | - | |
kernel-debug-modules-extra-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 9439e83d7048d01ea8229671c9ce7630 | - | |
kernel-devel-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 4161c0de5f3784bff625624d72282bea | - | |
kernel-devel-matched-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 2d67f91495ca90353ea956045cbd5b85 | - | |
kernel-doc-5.14.0-70.17.1.0.1.el9_0.noarch.rpm | 37ce9ceb400aece073b43a0d8d5bb50e | - | |
kernel-headers-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 68b1f9ef3b046b2f75fc0993cbeb8ea1 | - | |
kernel-modules-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | ef67303a2ef7b996a7c675e58f25d698 | - | |
kernel-modules-extra-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 0a2fecad6d47d0ce4acc363a079127fc | - | |
kernel-tools-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | a4351f05e0a31346ef1cfe196b345fe2 | - | |
kernel-tools-libs-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 65d0415c0dce8e3863e2bc7f9c20e554 | - | |
kernel-tools-libs-devel-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 8c08e5930e15ac2b6ea3e2f5be6966aa | - | |
perf-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | 44db33fdb4b2cc2383a552c1541f6a10 | - | |
python3-perf-5.14.0-70.17.1.0.1.el9_0.x86_64.rpm | cfb0251adddc1f9f6f1788a414fb9698 | - |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team