ELSA-2023-0101

ELSA-2023-0101 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2023-01-13

Description


[4.18.0-425.10.1.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]

[4.18.0-425.10.1_7]
- scsi: target: loop: Fix handling of aborted TMRs (Maurizio Lombardi) [2144583 2141713]
- ice: virtchnl rss hena support (Petr Oros) [2148130]
- ice: Fix configuring VIRTCHNL_OP_CONFIG_VSI_QUEUES with unbalanced queues (Michal Schmidt) [2142017 2137378]
- ice: Add support Flex RXD (Michal Schmidt) [2138157 2131310]
- netfilter: flowtable: fix stuck flows on cleanup due to pending work (Phil Sutter) [2134084 2131370]
- netfilter: flowtable: add function to invoke garbage collection immediately (Phil Sutter) [2134084 2131370]
- netfilter: flowtable: pass flowtable to nf_flow_table_iterate() (Phil Sutter) [2134084 2131370]
- netfilter: flowtable: separate replace, destroy and stats to different workqueues (Phil Sutter) [2134084 2131370]
- x86/paravirt: Add a dummy __x86_paravirt_patch_template() function (Waiman Long) [2152206 2144161]
- x86/paravirt: Fix kABI breakage in struct pv_mmu_ops (Waiman Long) [2152206 2144161]
- drm/i915: fix TLB invalidation for Gen12 video and compute engines (Wander Lairson Costa) [2148149 2148150] {CVE-2022-4139}
- PCI: hv: Do not set PCI_COMMAND_MEMORY to reduce VM boot time (Emanuele Giuseppe Esposito) [2150912 2082836]
- iavf: Fix cached head and tail value for iavf_get_tx_pending (Stefan Assmann) [2149742 2103944]
- iavf: Fix change VF's mac address (Stefan Assmann) [2149742 2103944]
- iavf: Fix race between iavf_close and iavf_reset_task (Stefan Assmann) [2149742 2103944]
- net: ethernet: move from strlcpy with unused retval to strscpy (Stefan Assmann) [2149742 2103944]
- iavf: Fix 'tc qdisc show' listing too many queues (Stefan Assmann) [2149742 2103944]
- iavf: Fix max_rate limiting (Stefan Assmann) [2149742 2103944]
- iavf: Check for duplicate TC flower filter before parsing (Stefan Assmann) [2149742 2103944]
- iavf: Fix handling of dummy receive descriptors (Stefan Assmann) [2149742 2103944]
- iavf: Disallow changing rx/tx-frames and rx/tx-frames-irq (Stefan Assmann) [2149742 2103944]
- intel/iavf:fix repeated words in comments (Stefan Assmann) [2149742 2103944]
- intel: remove unused macros (Stefan Assmann) [2149742 2103944]
- iavf: Add waiting for response from PF in set mac (Stefan Assmann) [2149742 2103944]

[4.18.0-425.9.1_7]
- Documentation/admin-guide: Document nomodeset kernel parameter (Jocelyn Falempe) [2145218 2143952]
- drm: Move nomodeset kernel parameter to the DRM subsystem (Jocelyn Falempe) [2145218 2143952]
- wait: Fix __wait_event_hrtimeout for RT/DL tasks (Derek Barbosa) [2138953 2125233]
- scsi: zfcp: Fix missing auto port scan and thus missing target ports (Tobias Huschle) [2127849 2121089]
- net: Fix return value of qdisc ingress handling on success (Ivan Vecera) [2141878 2131361]

[4.18.0-425.8.1_7]
- scsi: mpi3mr: Schedule IRQ kthreads only on non-RT kernels (Tomas Henzl) [2139216 2134535]
- RDMA/mlx5: Set local port to one when accessing counters (Mohammad Kabat) [2141957 2077119]
- drm/mgag200: Fix PLL setup for G200_SE_A rev >=4 (Jocelyn Falempe) [2140152 2130159]
- iavf: Do not restart Tx queues after reset task failure (Petr Oros) [2149081 2134005]
- iavf: Fix a crash during reset task (Petr Oros) [2149081 2134005]
- scsi: core: Allow the ALUA transitioning state enough time (Tomas Henzl) [2147374 2084250]
- scsi: core: Return BLK_STS_TRANSPORT for ALUA transitioning (Tomas Henzl) [2147374 2084250]
- i40e: Fix DMA mappings leak (Ivan Vecera) [2138205 2077847]
- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2142724 2142725] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2142724 2142725] {CVE-2022-2964}

[4.18.0-425.7.1_7]
- ice: Add additional CSR registers to ETHTOOL_GREGS (Petr Oros) [2136513 2131024]
- i40e: Fix set max_tx_rate when it is lower than 1 Mbps (Petr Oros) [2137270 2106964]
- i40e: Fix VF set max MTU size (Petr Oros) [2137270 2106964]
- iavf: Fix set max MTU size with port VLAN and jumbo frames (Petr Oros) [2137270 2106964]
- iavf: Fix bad page state (Petr Oros) [2137270 2106964]
- Revert 'scsi: mpi3mr: Schedule IRQ kthreads only on non-RT kernels' (Jarod Wilson)
- scsi: mpi3mr: Schedule IRQ kthreads only on non-RT kernels (Tomas Henzl) [2139216]
- Revert 'ACPI: processor idle: Practically limit 'Dummy wait' workaround to old Intel systems' (Jarod Wilson)
- ACPI: processor idle: Practically limit 'Dummy wait' workaround to old Intel systems (Wei Huang) [2142170 2130653]

[4.18.0-425.6.1_7]
- ice: Add low latency Tx timestamp read (Petr Oros) [2136036 2092425]
- ice: introduce ice_ptp_reset_cached_phctime function (Petr Oros) [2136036 2092425]
- ice: re-arrange some static functions in ice_ptp.c (Petr Oros) [2136036 2092425]
- ice: track and warn when PHC update is late (Petr Oros) [2136036 2092425]
- ice: track Tx timestamp stats similar to other Intel drivers (Petr Oros) [2136036 2092425]
- ice: implement adjfine with mul_u64_u64_div_u64 (Petr Oros) [2136036 2092425]
- ice: Add EXTTS feature to the feature bitmap (Petr Oros) [2136036 2092425]
- math: Export mul_u64_u64_div_u64 (Petr Oros) [2136036 2092425]
- vfio/type1: Unpin zero pages (Alex Williamson) [2128515 2123015]
- net: atlantic: remove aq_nic_deinit() when resume (Inigo Huguet) [2131935 2130839]
- net: atlantic: remove deep parameter on suspend/resume functions (Inigo Huguet) [2131935 2130839]
- CI: Use zstream builder container (Veronika Kabatova)
- CI: Add disttag override for 8.7 (Veronika Kabatova)

[4.18.0-425.5.1_7]
- ice: Fix interface being down after reset with link-down-on-close flag on (Petr Oros) [2136216 2024110]
- ice: Fix crash by keep old cfg when update TCs more than queues (Petr Oros) [2130992 2129902]
- ice: Fix tunnel checksum offload with fragmented traffic (Petr Oros) [2130992 2129902]
- ice: handle E822 generic device ID in PLDM header (Petr Oros) [2130992 2129902]
- ice: ethtool: Prohibit improper channel config for DCB (Petr Oros) [2130992 2129902]
- ice: ethtool: advertise 1000M speeds properly (Petr Oros) [2130992 2129902]
- ice: Fix switchdev rules book keeping (Petr Oros) [2130992 2129902]
- ice: fix access-beyond-end in the switch code (Petr Oros) [2130992 2129902]
- eth: ice: silence the GCC 12 array-bounds warning (Petr Oros) [2130992 2129902]
- ice: Expose RSS indirection tables for queue groups via ethtool (Petr Oros) [2130992 2129902]
- Revert 'ice: Hide bus-info in ethtool for PRs in switchdev mode' (Petr Oros) [2130992 2129902]
- ice: remove period on argument description in ice_for_each_vf (Petr Oros) [2130992 2129902]
- ice: add a function comment for ice_cfg_mac_antispoof (Petr Oros) [2130992 2129902]
- ice: fix wording in comment for ice_reset_vf (Petr Oros) [2130992 2129902]
- ice: remove return value comment for ice_reset_all_vfs (Petr Oros) [2130992 2129902]
- ice: always check VF VSI pointer values (Petr Oros) [2130992 2129902]
- ice: add newline to dev_dbg in ice_vf_fdir_dump_info (Petr Oros) [2130992 2129902]
- ice: get switch id on switchdev devices (Petr Oros) [2130992 2129902]
- ice: return ENOSPC when exceeding ICE_MAX_CHAIN_WORDS (Petr Oros) [2130992 2129902]
- ice: introduce common helper for retrieving VSI by vsi_num (Petr Oros) [2130992 2129902]
- ice: use min_t() to make code cleaner in ice_gnss (Petr Oros) [2130992 2129902]
- ice: Add mpls+tso support (Petr Oros) [2130992 2129902]
- ice: switch: convert packet template match code to rodata (Petr Oros) [2130992 2129902]
- ice: switch: use convenience macros to declare dummy pkt templates (Petr Oros) [2130992 2129902]
- ice: switch: use a struct to pass packet template params (Petr Oros) [2130992 2129902]
- ice: switch: unobscurify bitops loop in ice_fill_adv_dummy_packet() (Petr Oros) [2130992 2129902]
- ice: switch: add and use u16[] aliases to ice_adv_lkup_elem::{h, m}_u (Petr Oros) [2130992 2129902]
- ice: Support GTP-U and GTP-C offload in switchdev (Petr Oros) [2130992 2129902]
- ice: Remove useless DMA-32 fallback configuration (Petr Oros) [2130992 2129902]
- ice: switch to napi_build_skb() (Petr Oros) [2130992 2129902]
- redhat: switch to z-stream dist tag and build targets (Jarod Wilson)
- block: avoid sign extend problem with default queue flags mask (Nico Pache) [2135813]

[4.18.0-425.4.1]
- random: allow reseeding DRBG with getrandom (Daiki Ueno) [2121766]


Related CVEs


CVE-2022-2964
CVE-2022-4139

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) kernel-4.18.0-425.10.1.el8_7.src.rpm1c92a132f8a086c881a556c565d0f8f7-
bpftool-4.18.0-425.10.1.el8_7.aarch64.rpm2da7103e13b1346e493234965c624644-
kernel-cross-headers-4.18.0-425.10.1.el8_7.aarch64.rpmdd486a3a782e2b9cf0ddf57e4322dd0e-
kernel-headers-4.18.0-425.10.1.el8_7.aarch64.rpmeeae0d9846ada52ff70c2266f062b2b8-
kernel-tools-4.18.0-425.10.1.el8_7.aarch64.rpm51822a044b53e991d069da4a291acfcc-
kernel-tools-libs-4.18.0-425.10.1.el8_7.aarch64.rpmada647adebbf3ad49bd02b2fba44764a-
kernel-tools-libs-devel-4.18.0-425.10.1.el8_7.aarch64.rpmd79e2778d70e528d4157caa8d2f91343-
perf-4.18.0-425.10.1.el8_7.aarch64.rpme85891b3f07ff869e7c5b3b11172021d-
python3-perf-4.18.0-425.10.1.el8_7.aarch64.rpm7e8acc6a6b144146551e6d49d2f19358-
Oracle Linux 8 (x86_64) kernel-4.18.0-425.10.1.el8_7.src.rpm1c92a132f8a086c881a556c565d0f8f7-
bpftool-4.18.0-425.10.1.el8_7.x86_64.rpm60d3aeda50a35f0caae97025f4b0310b-
kernel-4.18.0-425.10.1.el8_7.x86_64.rpmbb515f0826c6b64ab523dbc38715d914-
kernel-abi-stablelists-4.18.0-425.10.1.el8_7.noarch.rpm5da3011be85ea29c602fa98dc9ea1ced-
kernel-core-4.18.0-425.10.1.el8_7.x86_64.rpm27c258cb6a7ec9ac0712c77ead86028c-
kernel-cross-headers-4.18.0-425.10.1.el8_7.x86_64.rpmceb069c9067d59af476fe6cc6df345bf-
kernel-debug-4.18.0-425.10.1.el8_7.x86_64.rpm3e9c06b7b442d0f6f8c0a1ab7c07c028-
kernel-debug-core-4.18.0-425.10.1.el8_7.x86_64.rpm468ece11c0e0b9900c86527a96f10531-
kernel-debug-devel-4.18.0-425.10.1.el8_7.x86_64.rpmf70d7f4cc51d75d91009fcd36f40962b-
kernel-debug-modules-4.18.0-425.10.1.el8_7.x86_64.rpmae2f68769dc7c4e7078f07b3ad9f8ec7-
kernel-debug-modules-extra-4.18.0-425.10.1.el8_7.x86_64.rpm517f0cdef4ac27cea434b1aa3eceafd2-
kernel-devel-4.18.0-425.10.1.el8_7.x86_64.rpm347ea9144d2584659a1ebfb9306f616a-
kernel-doc-4.18.0-425.10.1.el8_7.noarch.rpm240c516bbdff3086dc9a47635ab0c2db-
kernel-headers-4.18.0-425.10.1.el8_7.x86_64.rpm168cdd2053fcafa046a304ba199dda58-
kernel-modules-4.18.0-425.10.1.el8_7.x86_64.rpmc8de8debbec8b5d3eb5c546c10007d11-
kernel-modules-extra-4.18.0-425.10.1.el8_7.x86_64.rpmf6687c0e51f265ef3fcaaf434290c2d7-
kernel-tools-4.18.0-425.10.1.el8_7.x86_64.rpm2ae7a664ab610bbf487fa11aa2b0d915-
kernel-tools-libs-4.18.0-425.10.1.el8_7.x86_64.rpm26919f6ed6a28c46dd8d598effabfd95-
kernel-tools-libs-devel-4.18.0-425.10.1.el8_7.x86_64.rpm74bdbefaa71f169fed3774262e995e9e-
perf-4.18.0-425.10.1.el8_7.x86_64.rpmeed5c24a3102280b448c850739cebf81-
python3-perf-4.18.0-425.10.1.el8_7.x86_64.rpmd5cd4a53becea7eeef22553d92ba757c-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete