ELSA-2023-12836

ELSA-2023-12836 - kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2023-09-25

Description


[5.14.0-284.30.1.el9_2]
- x86/microcode/intel: Expose collect_cpu_info_early() for IFS
- x86/cpu: Load microcode during restore_processor_state()
- x86/microcode: Rip out the OLD_INTERFACE
- x86/microcode: Default-disable late loading
- x86/microcode: Taint and warn on late loading
- x86/microcode: Remove unnecessary perf callback
- x86/microcode: Print previous version of microcode after reload
- x86/microcode: Rip out the subsys interface gunk
- x86/microcode: Simplify init path even more
- x86/microcode/AMD: Rename a couple of functions {CVE-2023-20593}
- x86/microcode: Add a parameter to microcode_check() to store CPU capabilities {CVE-2023-20593}
- x86/microcode: Check CPU capabilities after late microcode update correctly {CVE-2023-20593}
- x86/microcode: Adjust late loading result reporting message {CVE-2023-20593}
- x86/amd: Cache debug register values in percpu variables {CVE-2023-20593}
- x86/microcode: Remove ->request_microcode_user()
- x86/microcode: Kill refresh_fw
- x86/microcode/amd: Remove load_microcode_amd()'s bsp parameter {CVE-2023-20593}
- x86/microcode: Drop struct ucode_cpu_info.valid
- x86/microcode/AMD: Add a @cpu parameter to the reloading functions {CVE-2023-20593}
- x86/microcode/AMD: Track patch allocation size explicitly
- x86/microcode/AMD: Fix mixed steppings support {CVE-2023-20593}
- x86/microcode/core: Return an error only when necessary {CVE-2023-20593}
- x86/apic: Don't disable x2APIC if locked
- x86/cpu/amd: Move the errata checking functionality up {CVE-2023-20593}
- x86/cpu: Remove redundant extern x86_read_arch_cap_msr()
- x86/cpu, kvm: Add support for CPUID_80000021_EAX
- KVM: x86: Advertise that the SMM_CTL MSR is not supported
- KVM: x86: Move open-coded CPUID leaf 0x80000021 EAX bit propagation code
- x86/cpu, kvm: Add the NO_NESTED_DATA_BP feature
- x86/bugs: Make sure MSR_SPEC_CTRL is updated properly upon resume from S3
- x86/cpu: Support AMD Automatic IBRS
- x86/CPU/AMD: Make sure EFER[AIBRSE] is set
- x86/cpu/amd: Add a Zenbleed fix {CVE-2023-20593}


Related CVEs


CVE-2023-20593
CVE-2023-3610

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_aarch64_appstream
kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_aarch64_baseos_latest
kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_aarch64_codeready_builder
kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_aarch64_u2_baseos_patch
bpftool-7.0.0-284.30.1.el9_2.aarch64.rpmfa30fa2e155c73b4069fdba21b6c492a0c9e484ed2cd1ef823594e13547ed915-ol9_aarch64_baseos_latest
bpftool-7.0.0-284.30.1.el9_2.aarch64.rpmfa30fa2e155c73b4069fdba21b6c492a0c9e484ed2cd1ef823594e13547ed915-ol9_aarch64_u2_baseos_patch
kernel-cross-headers-5.14.0-284.30.1.el9_2.aarch64.rpm2ad1e029108171494401e9d26ce0c9739fa606305b0a1d4225c62c7b051807ee-ol9_aarch64_codeready_builder
kernel-headers-5.14.0-284.30.1.el9_2.aarch64.rpm380d4d74567b51c5654cf486cfef7374cf1b5eae72e0f36d379ed282d49728a9-ol9_aarch64_appstream
kernel-tools-5.14.0-284.30.1.el9_2.aarch64.rpme94b150c9c5c1583b34bf636868804875483552c7ceb5bf418448fecb40bfb1a-ol9_aarch64_baseos_latest
kernel-tools-5.14.0-284.30.1.el9_2.aarch64.rpme94b150c9c5c1583b34bf636868804875483552c7ceb5bf418448fecb40bfb1a-ol9_aarch64_u2_baseos_patch
kernel-tools-libs-5.14.0-284.30.1.el9_2.aarch64.rpm4970d093f0ef9f24f5cf92d0f935a95c8f125e2c38532280059df9b286d2882a-ol9_aarch64_baseos_latest
kernel-tools-libs-5.14.0-284.30.1.el9_2.aarch64.rpm4970d093f0ef9f24f5cf92d0f935a95c8f125e2c38532280059df9b286d2882a-ol9_aarch64_u2_baseos_patch
kernel-tools-libs-devel-5.14.0-284.30.1.el9_2.aarch64.rpm39e1d902aad7b14456dc33cb63d027b44fb5728a0abe79f35fa0e040a62c9e54-ol9_aarch64_codeready_builder
perf-5.14.0-284.30.1.el9_2.aarch64.rpm6961fd8176032e7b8adab266ff5dce8ba833fafd8c3a28bbc3917213fa25acfc-ol9_aarch64_appstream
python3-perf-5.14.0-284.30.1.el9_2.aarch64.rpm81bf05d1f21f1fdf912e52f4402838b50a7956a9441d6eb900b0de90796d4d03-ol9_aarch64_baseos_latest
python3-perf-5.14.0-284.30.1.el9_2.aarch64.rpm81bf05d1f21f1fdf912e52f4402838b50a7956a9441d6eb900b0de90796d4d03-ol9_aarch64_u2_baseos_patch
Oracle Linux 9 (x86_64) kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_x86_64_appstream
kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_x86_64_baseos_latest
kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_x86_64_codeready_builder
kernel-5.14.0-284.30.1.el9_2.src.rpm60acc39ac1eee6cc2a962f69f46db5a068c3f915adf1a33c8401a8c145ccc860-ol9_x86_64_u2_baseos_patch
bpftool-7.0.0-284.30.1.el9_2.x86_64.rpmd5cdb9a655d88efeb4591788ccc21aad6a6d10b1f6af21d017a20acc2a4dc6eb-ol9_x86_64_baseos_latest
bpftool-7.0.0-284.30.1.el9_2.x86_64.rpmd5cdb9a655d88efeb4591788ccc21aad6a6d10b1f6af21d017a20acc2a4dc6eb-ol9_x86_64_u2_baseos_patch
kernel-5.14.0-284.30.1.el9_2.x86_64.rpm3d7d938317abea9dd592139ddf9f5ac1c04f4b89607b6f3166733da9b77f5256-ol9_x86_64_baseos_latest
kernel-5.14.0-284.30.1.el9_2.x86_64.rpm3d7d938317abea9dd592139ddf9f5ac1c04f4b89607b6f3166733da9b77f5256-ol9_x86_64_u2_baseos_patch
kernel-abi-stablelists-5.14.0-284.30.1.el9_2.noarch.rpm5e82aa07f5b5218f8aa954be98151663769424ab718269e379383baf3a024e24-ol9_x86_64_baseos_latest
kernel-abi-stablelists-5.14.0-284.30.1.el9_2.noarch.rpm5e82aa07f5b5218f8aa954be98151663769424ab718269e379383baf3a024e24-ol9_x86_64_u2_baseos_patch
kernel-core-5.14.0-284.30.1.el9_2.x86_64.rpm27e0a195dd298fcfd4b98608cb6862d7652890a7c6133818e91803b0c8c3a867-ol9_x86_64_baseos_latest
kernel-core-5.14.0-284.30.1.el9_2.x86_64.rpm27e0a195dd298fcfd4b98608cb6862d7652890a7c6133818e91803b0c8c3a867-ol9_x86_64_u2_baseos_patch
kernel-cross-headers-5.14.0-284.30.1.el9_2.x86_64.rpmecc3f5996f1b307e37e053fec033bf7f9fb1b88f0e6373a37003946eb6a44045-ol9_x86_64_codeready_builder
kernel-debug-5.14.0-284.30.1.el9_2.x86_64.rpmd3e4ced59a32aff71712c37649cefc52173bdf9189c503fa924c4c51dd7f700b-ol9_x86_64_baseos_latest
kernel-debug-5.14.0-284.30.1.el9_2.x86_64.rpmd3e4ced59a32aff71712c37649cefc52173bdf9189c503fa924c4c51dd7f700b-ol9_x86_64_u2_baseos_patch
kernel-debug-core-5.14.0-284.30.1.el9_2.x86_64.rpm4e32ddcb2c3d31121dbe79222503d32deb4fe132df970cc52b3d9fb06b326262-ol9_x86_64_baseos_latest
kernel-debug-core-5.14.0-284.30.1.el9_2.x86_64.rpm4e32ddcb2c3d31121dbe79222503d32deb4fe132df970cc52b3d9fb06b326262-ol9_x86_64_u2_baseos_patch
kernel-debug-devel-5.14.0-284.30.1.el9_2.x86_64.rpme5bbea724d2b66242ad1ca6ec2d6ab2529c68da288af59da72248e99efca59b3-ol9_x86_64_appstream
kernel-debug-devel-matched-5.14.0-284.30.1.el9_2.x86_64.rpm63d8a05eef6f4fa1f12b0a033961057125f5e2c0f270ddcfbf54403dcfbd6e2d-ol9_x86_64_appstream
kernel-debug-modules-5.14.0-284.30.1.el9_2.x86_64.rpm12bde154be10dae2cdcaf6fedca0d31b7d51a8c9a165a2903457c1eb78f5bc03-ol9_x86_64_baseos_latest
kernel-debug-modules-5.14.0-284.30.1.el9_2.x86_64.rpm12bde154be10dae2cdcaf6fedca0d31b7d51a8c9a165a2903457c1eb78f5bc03-ol9_x86_64_u2_baseos_patch
kernel-debug-modules-core-5.14.0-284.30.1.el9_2.x86_64.rpmbe3620c2fdb3a4fa5f6c6f201e7b5b80ba1989087809f13797dfab1a73dbfdbd-ol9_x86_64_baseos_latest
kernel-debug-modules-core-5.14.0-284.30.1.el9_2.x86_64.rpmbe3620c2fdb3a4fa5f6c6f201e7b5b80ba1989087809f13797dfab1a73dbfdbd-ol9_x86_64_u2_baseos_patch
kernel-debug-modules-extra-5.14.0-284.30.1.el9_2.x86_64.rpm28adc38bb8548100280a4d98b57287e6f40c299f430281796c17c36dc3ade0b2-ol9_x86_64_baseos_latest
kernel-debug-modules-extra-5.14.0-284.30.1.el9_2.x86_64.rpm28adc38bb8548100280a4d98b57287e6f40c299f430281796c17c36dc3ade0b2-ol9_x86_64_u2_baseos_patch
kernel-debug-uki-virt-5.14.0-284.30.1.el9_2.x86_64.rpm077b7c42ef220bad06c0b777343778848bf78b724cfa8b4f084a7ee8711ec806-ol9_x86_64_baseos_latest
kernel-debug-uki-virt-5.14.0-284.30.1.el9_2.x86_64.rpm077b7c42ef220bad06c0b777343778848bf78b724cfa8b4f084a7ee8711ec806-ol9_x86_64_u2_baseos_patch
kernel-devel-5.14.0-284.30.1.el9_2.x86_64.rpmf04dd7a585a1e9172f52186be01539645b95d5fee9f8fa3040ecb8cda266f4e1-ol9_x86_64_appstream
kernel-devel-matched-5.14.0-284.30.1.el9_2.x86_64.rpm3afe137d10040d8df19e09333382a80122ac708db6e105f6b0b29b0a099f6290-ol9_x86_64_appstream
kernel-doc-5.14.0-284.30.1.el9_2.noarch.rpm14424bc88d8ac5f2d642e2f684f41ad475f4b2c940a209ae5c0385d085fa4dc8-ol9_x86_64_appstream
kernel-headers-5.14.0-284.30.1.el9_2.x86_64.rpm4aef586c547200473b88e074263dd3629f2cef8e6fb857a2916a975bae746053-ol9_x86_64_appstream
kernel-modules-5.14.0-284.30.1.el9_2.x86_64.rpm8f01b6a6d2072ef998ec54a2edaebf8899245e4cd3c19f07308c1c51b404ecc1-ol9_x86_64_baseos_latest
kernel-modules-5.14.0-284.30.1.el9_2.x86_64.rpm8f01b6a6d2072ef998ec54a2edaebf8899245e4cd3c19f07308c1c51b404ecc1-ol9_x86_64_u2_baseos_patch
kernel-modules-core-5.14.0-284.30.1.el9_2.x86_64.rpm0edcf488d564054abbd1d108a36788bb90a6a175fb6e234168f019fe5d732d00-ol9_x86_64_baseos_latest
kernel-modules-core-5.14.0-284.30.1.el9_2.x86_64.rpm0edcf488d564054abbd1d108a36788bb90a6a175fb6e234168f019fe5d732d00-ol9_x86_64_u2_baseos_patch
kernel-modules-extra-5.14.0-284.30.1.el9_2.x86_64.rpm88202f271aaadc2dbd37643f192fb2d44dc0f221a7d12457258a88dad8bb7093-ol9_x86_64_baseos_latest
kernel-modules-extra-5.14.0-284.30.1.el9_2.x86_64.rpm88202f271aaadc2dbd37643f192fb2d44dc0f221a7d12457258a88dad8bb7093-ol9_x86_64_u2_baseos_patch
kernel-tools-5.14.0-284.30.1.el9_2.x86_64.rpm8c74fa99027f0bd842d9665f8754ce5f5c43fc68c6b42a25e1c6488c8c056116-ol9_x86_64_baseos_latest
kernel-tools-5.14.0-284.30.1.el9_2.x86_64.rpm8c74fa99027f0bd842d9665f8754ce5f5c43fc68c6b42a25e1c6488c8c056116-ol9_x86_64_u2_baseos_patch
kernel-tools-libs-5.14.0-284.30.1.el9_2.x86_64.rpmc462484384ea666ae0ff419dfcd60fe7eadd82d640ea85d473b5b46c9245d427-ol9_x86_64_baseos_latest
kernel-tools-libs-5.14.0-284.30.1.el9_2.x86_64.rpmc462484384ea666ae0ff419dfcd60fe7eadd82d640ea85d473b5b46c9245d427-ol9_x86_64_u2_baseos_patch
kernel-tools-libs-devel-5.14.0-284.30.1.el9_2.x86_64.rpm654a5c5abf7f7e6ce162ce48e50d76cec90214bdd0731ce6e30f5c70617bd060-ol9_x86_64_codeready_builder
kernel-uki-virt-5.14.0-284.30.1.el9_2.x86_64.rpmccd9a6e0280704e695321f5b49a8777fc21489490dd703ea07999a3ae8e153a2-ol9_x86_64_baseos_latest
kernel-uki-virt-5.14.0-284.30.1.el9_2.x86_64.rpmccd9a6e0280704e695321f5b49a8777fc21489490dd703ea07999a3ae8e153a2-ol9_x86_64_u2_baseos_patch
perf-5.14.0-284.30.1.el9_2.x86_64.rpma15bebc8d40096a793a3b1126b1a3d76201ccda05e3117fd3bd90ff1b5384c83-ol9_x86_64_appstream
python3-perf-5.14.0-284.30.1.el9_2.x86_64.rpm07a64e80c7a2b4b3c1db482c133b2ca49e7d5be44d1e18b95392d3abe0730dd7-ol9_x86_64_baseos_latest
python3-perf-5.14.0-284.30.1.el9_2.x86_64.rpm07a64e80c7a2b4b3c1db482c133b2ca49e7d5be44d1e18b95392d3abe0730dd7-ol9_x86_64_u2_baseos_patch
rtla-5.14.0-284.30.1.el9_2.x86_64.rpme7073bfa118976111e6b6b18c45835133a82e59b1f293f2cb73f600c8dba6dce-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete