ELSA-2022-5937

ELSA-2022-5937 - kernel security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2022-08-11

Description


[3.10.0-1160.76.1.0.1.OL7]
[debug: lock down kgdb [Orabug: 34270798] {CVE-2022-21499}

[3.10.0-1160.76.1.OL7]
[Update Oracle Linux certificates (Ilya Okomin)
[Oracle Linux RHCK Module Signing Key was compiled into kernel (olkmod_signing_key.x509)(alexey.petrenko@oracle.com)
[Update x509.genkey [Orabug: 24817676]
[Conflict with shim-ia32 and shim-x64 <= 15-2.0.9
[Update oracle(kernel-sig-key) value to match new certificate (Ilya Okomin)

[3.10.0-1160.76.1]
[sfc: complete the next packet when we receive a timestamp (Inigo Huguet) [1793280]

[3.10.0-1160.75.1]
[xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
[x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[cpu/speculation: Add prototype for cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
[[s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]

[3.10.0-1160.74.1]
[tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]

[3.10.0-1160.73.1]
[qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
[RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]

[3.10.0-1160.72.1]
[sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
[sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
[sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]


Related CVEs


CVE-2022-21123
CVE-2022-21125
CVE-2022-21166

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) kernel-3.10.0-1160.76.1.0.1.el7.src.rpm782cf05e4414257fc408e0c2ce8e7b6f-
bpftool-3.10.0-1160.76.1.0.1.el7.x86_64.rpmc9d6b74d1b5f6a80afbbc395588b7ec4-
kernel-3.10.0-1160.76.1.0.1.el7.x86_64.rpmb923a5b69c5dd2f3bad9819da227aded-
kernel-abi-whitelists-3.10.0-1160.76.1.0.1.el7.noarch.rpmdc5d87963957ad8c7211edb6cd3f2004-
kernel-debug-3.10.0-1160.76.1.0.1.el7.x86_64.rpm010e1df11f609b2243f72ad59a3d453f-
kernel-debug-devel-3.10.0-1160.76.1.0.1.el7.x86_64.rpm1856bd64372c192988d09fa8e395209a-
kernel-devel-3.10.0-1160.76.1.0.1.el7.x86_64.rpm752a002d96d5f9b3446498bb5a7e1256-
kernel-doc-3.10.0-1160.76.1.0.1.el7.noarch.rpm25ba965cc8666e065dc355895add4f9e-
kernel-headers-3.10.0-1160.76.1.0.1.el7.x86_64.rpm53be9e3a530a4ccd292373a2eee4f0a5-
kernel-tools-3.10.0-1160.76.1.0.1.el7.x86_64.rpmeb8b3196de84cb0b58aee8d40e20c022-
kernel-tools-libs-3.10.0-1160.76.1.0.1.el7.x86_64.rpm86fedf4fd96000dcc37430a8a7bc8500-
kernel-tools-libs-devel-3.10.0-1160.76.1.0.1.el7.x86_64.rpm526ffeffe320129af73d62dc759d04a4-
perf-3.10.0-1160.76.1.0.1.el7.x86_64.rpm542fe25db4e0d3f0fd06dbcb980846a9-
python-perf-3.10.0-1160.76.1.0.1.el7.x86_64.rpmad70e8e045ee51c5ebd4d52afe10caba-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete