ELSA-2023-1566

ELSA-2023-1566 - kernel security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2023-04-05

Description


[4.18.0-425.19.2_7.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]

[4.18.0-425.19.2_7.gf5e8]
- ovl: fail on invalid uid/gid mapping at copy up (Miklos Szeredi) [2165341 2165342] {CVE-2023-0386}

[4.18.0-425.19.1_7]
- s390/dasd: fix no record found for raw_track_access (Tobias Huschle) [2167776 2161270]
- locking/rwsem: Disable preemption in all down_read*() and up_read() code paths (Waiman Long) [2170939 2162139]
- locking/rwsem: Prevent non-first waiter from spinning in down_write() slowpath (Waiman Long) [2170939 2162139]
- locking/rwsem: Allow slowpath writer to ignore handoff bit if not set by first waiter (Waiman Long) [2170939 2162139]
- locking/rwsem: Always try to wake waiters in out_nolock path (Waiman Long) [2170939 2162139]
- locking/rwsem: No need to check for handoff bit if wait queue empty (Waiman Long) [2170939 2162139]
- locking/rwsem: Make handoff bit handling more consistent (Waiman Long) [2170939 2162139]
- locking/rwsem: Disable preemption while trying for rwsem lock (Waiman Long) [2170939 2162139]
- locking/rwsem: Conditionally wake waiters in reader/writer slowpaths (Waiman Long) [2170939 2162139]
(Waiman Long) [2170939 2162139]
- locking/rwsem: Optimize down_read_trylock() under highly contended case (Waiman Long) [2170939 2162139]
- locking/rwsem: Fix comments about reader optimistic lock stealing conditions (Waiman Long) [2170939 2162139]
- locking/rwsem: Disable preemption for spinning region (Waiman Long) [2170939 2162139]
- locking: Remove rcu_read_{,un}lock() for preempt_{dis,en}able() (Waiman Long) [2170939 2162139]
- watchdog: fix UAF in reboot notifier handling in watchdog core code (Wander Lairson Costa) [2139770 2131308]
- netfilter: nf_conntrack_irc: Tighten matching on DCC message (Wander Lairson Costa) [2139770 2131308]
- ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (Jaroslav Kysela) [2163400 2163401] {CVE-2023-0266}
- net/mlx5e: Fix enabling sriov while tc nic rules are offloaded (Amir Tzin) [2167647 2112925]
- net/mlx5: E-Switch, pair only capable devices (Amir Tzin) [2167647 2112925]
- net/mlx5: Fix mlx5_get_next_dev() peer device matching (Amir Tzin) [2167647 2112925]
- net/mlx5: Lag, filter non compatible devices (Amir Tzin) [2167647 2112925]

[4.18.0-425.18.1_7]
- futex: Resend potentially swallowed owner death notification (Rafael Aquini) [2170054 2161526]

[4.18.0-425.17.1_7]
- net: mana: Add rmb after checking owner bits (Mohammed Gamal) [2173103 2139462]
- net: mana: Add support of XDP_REDIRECT action (Mohammed Gamal) [2173103 2139462]
- net: mana: Add the Linux MANA PF driver (Mohammed Gamal) [2173103 2139462]
- ice: fix lost multicast packets in promisc mode (Ken Cox) [2172550 2138215]

[4.18.0-425.16.1_7]
- ipv6: fix panic when fib_lookup_arg->result is fib6_info (Jiri Benc) [2167602 2140599]
- ceph: blocklist the kclient when receiving corrupted snap trace (Xiubo Li) [2168896 2162414]
- ceph: move mount state enum to super.h (Xiubo Li) [2168896 2162414]
- s390/kexec: fix ipl report address for kdump (Tobias Huschle) [2166296 2161328]
- mm, compaction: fix fast_isolate_around() to stay within boundaries (Daniel Vacek) [2170576 2149309]
- scsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM (Emanuele Giuseppe Esposito) [2170228 2150659]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2165587 2158726]

[4.18.0-425.15.1_7]
- net/mlx5e: Fix use-after-free when reverting termination table (Amir Tzin) [2167640 2112927]
- net/mlx5: Do not query pci info while pci disabled (Amir Tzin) [2167645 2129249]
- x86/fpu: Fix copy_xstate_to_uabi() to copy init states correctly (Dean Nelson) [2168384 2122850]
- x86/fpu: Exclude dynamic states from init_fpstate (Dean Nelson) [2168384 2122850]
- x86/fpu: Fix the init_fpstate size check with the actual size (Dean Nelson) [2168384 2122850]
- x86/fpu: Configure init_fpstate attributes orderly (Dean Nelson) [2168384 2122850]
- x86/fpu/xstate: Fix the ARCH_REQ_XCOMP_PERM implementation (Dean Nelson) [2168384 2122850]
- net/mlx5: E-Switch, properly handle ingress tagged packets on VST (Amir Tzin) [2166665 2096109]
- cpuhotplug: Fix KABI breakage (Prarit Bhargava) [2162763 2156529]

[4.18.0-425.14.1_7]
- ACPI: processor idle: Practically limit 'Dummy wait' workaround to old Intel systems (Wei Huang) [2142170 2130653]
- KVM: x86: nSVM: implement nested LBR virtualization (Emanuele Giuseppe Esposito) [2166362 2155149]
- KVM: x86: nSVM: correctly virtualize LBR msrs when L2 is running (Emanuele Giuseppe Esposito) [2166362 2155149]
- kvm: x86: SVM: use vmcb* instead of svm->vmcb where it makes sense (Emanuele Giuseppe Esposito) [2166362 2155149]
- KVM: x86: nSVM: implement nested VMLOAD/VMSAVE (Emanuele Giuseppe Esposito) [2166362 2155149]
- IB/iser: Fix login with authentication (Kamal Heib) [2161750 2120676]
- act_mirred: use the backlog for nested calls to mirred ingress (Davide Caratti) [2164648 2131339] {CVE-2022-4269}
- net/sched: act_mirred: better wording on protection against excessive stack growth (Davide Caratti) [2164648 2131339] {CVE-2022-4269}
- redhat/configs: Set CONFIG_X86_AMD_PSTATE to 'm' (Prarit Bhargava) [2151275 2145246]
- KVM: x86: smm: preserve interrupt shadow in SMRAM (Maxim Levitsky) [2166368 2097144]
- KVM: x86: SVM: don't save SVM state to SMRAM when VM is not long mode capable (Maxim Levitsky) [2166368 2097144]
- KVM: x86: SVM: use smram structs (Maxim Levitsky) [2166368 2097144]
- KVM: svm: drop explicit return value of kvm_vcpu_map (Maxim Levitsky) [2166368 2097144]
- KVM: x86: smm: use smram struct for 64 bit smram load/restore (Maxim Levitsky) [2166368 2097144]
- KVM: x86: smm: use smram struct for 32 bit smram load/restore (Maxim Levitsky) [2166368 2097144]
- KVM: x86: smm: use smram structs in the common code (Maxim Levitsky) [2166368 2097144]
- KVM: x86: smm: add structs for KVM's smram layout (Maxim Levitsky) [2166368 2097144]
- KVM: x86: smm: check for failures on smm entry (Maxim Levitsky) [2166368 2097144]
- KVM: x86: do not go through ctxt->ops when emulating rsm (Maxim Levitsky) [2166368 2097144]
- KVM: x86: move SMM exit to a new file (Maxim Levitsky) [2166368 2097144]
- KVM: x86: move SMM entry to a new file (Maxim Levitsky) [2166368 2097144]
- KVM: x86: start moving SMM-related functions to new files (Maxim Levitsky) [2166368 2097144]
- bug: introduce ASSERT_STRUCT_OFFSET (Maxim Levitsky) [2166368 2097144]
- KVM: x86: Rename and expose helper to detect if INIT/SIPI are allowed (Maxim Levitsky) [2166368 2097144]
- KVM: x86: smm: number of GPRs in the SMRAM image depends on the image format (Maxim Levitsky) [2166368 2097144]
- KVM: x86: emulator: update the emulation mode after CR0 write (Maxim Levitsky) [2166368 2097144]
- KVM: x86: emulator: update the emulation mode after rsm (Maxim Levitsky) [2166368 2097144]
- KVM: x86: emulator: introduce emulator_recalc_and_set_mode (Maxim Levitsky) [2166368 2097144]
- KVM: x86: emulator: em_sysexit should update ctxt->mode (Maxim Levitsky) [2166368 2097144]
- KVM: x86: Bug the VM if the emulator accesses a non-existent GPR (Maxim Levitsky) [2166368 2097144]
- \KVM: x86: Reduce the number of emulator GPRs to '8' for 32-bit KVM (Maxim Levitsky) [2166368 2097144]
- KVM: x86: Use 16-bit fields to track dirty/valid emulator GPRs (Maxim Levitsky) [2166368 2097144]
- KVM: x86: Omit VCPU_REGS_RIP from emulator's _regs array (Maxim Levitsky) [2166368 2097144]
- \KVM: x86: Harden _regs accesses to guard against buggy input (Maxim Levitsky) [2166368 2097144]
- KVM: x86: Grab regs_dirty in local 'unsigned long' (Maxim Levitsky) [2166368 2097144]
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152571 2152572] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152571 2152572] {CVE-2022-4378}


Related CVEs


CVE-2023-0386
CVE-2023-0266
CVE-2022-4269
CVE-2022-4378

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-4.18.0-425.19.2.el8_7.src.rpm418dabec5583524f184e9f53906c10fa4a5fda025d1f34dcae270aca5f0ce11a-ol8_aarch64_baseos_latest
kernel-4.18.0-425.19.2.el8_7.src.rpm418dabec5583524f184e9f53906c10fa4a5fda025d1f34dcae270aca5f0ce11a-ol8_aarch64_codeready_builder
kernel-4.18.0-425.19.2.el8_7.src.rpm418dabec5583524f184e9f53906c10fa4a5fda025d1f34dcae270aca5f0ce11a-ol8_aarch64_u7_baseos_patch
bpftool-4.18.0-425.19.2.el8_7.aarch64.rpm424834cf4a69e56b32f951bcea5285a4099545e1ed35c654c70ce22d84e4baf4-ol8_aarch64_baseos_latest
bpftool-4.18.0-425.19.2.el8_7.aarch64.rpm424834cf4a69e56b32f951bcea5285a4099545e1ed35c654c70ce22d84e4baf4-ol8_aarch64_u7_baseos_patch
kernel-cross-headers-4.18.0-425.19.2.el8_7.aarch64.rpmc50cc64eba256f0208cd631c605aaf5ae713604200e6b1c4da285d890bc490ef-ol8_aarch64_baseos_latest
kernel-cross-headers-4.18.0-425.19.2.el8_7.aarch64.rpmc50cc64eba256f0208cd631c605aaf5ae713604200e6b1c4da285d890bc490ef-ol8_aarch64_u7_baseos_patch
kernel-headers-4.18.0-425.19.2.el8_7.aarch64.rpm1fd4e1735f6eb27b510b0760df831ff5b72fc40e403af28c2884374aad645604-ol8_aarch64_baseos_latest
kernel-headers-4.18.0-425.19.2.el8_7.aarch64.rpm1fd4e1735f6eb27b510b0760df831ff5b72fc40e403af28c2884374aad645604-ol8_aarch64_u7_baseos_patch
kernel-tools-4.18.0-425.19.2.el8_7.aarch64.rpma2dc278b2150d9d334d7f641716ec1ce28bd8fe8371b691274d0e71c32cf4688-ol8_aarch64_baseos_latest
kernel-tools-4.18.0-425.19.2.el8_7.aarch64.rpma2dc278b2150d9d334d7f641716ec1ce28bd8fe8371b691274d0e71c32cf4688-ol8_aarch64_u7_baseos_patch
kernel-tools-libs-4.18.0-425.19.2.el8_7.aarch64.rpma703f0e2d468e40c2cf7615a016f26324299c18b83a8843a44dcf4c7b258b815-ol8_aarch64_baseos_latest
kernel-tools-libs-4.18.0-425.19.2.el8_7.aarch64.rpma703f0e2d468e40c2cf7615a016f26324299c18b83a8843a44dcf4c7b258b815-ol8_aarch64_u7_baseos_patch
kernel-tools-libs-devel-4.18.0-425.19.2.el8_7.aarch64.rpm9458ca4d583e56dcb5a4e090f46418df0183e8edf6f926c32209754bd9e0e1dd-ol8_aarch64_codeready_builder
perf-4.18.0-425.19.2.el8_7.aarch64.rpmcf9d9a06a6890ccff85265485e6edb6eeeb6f2eaa276223d9f9ceb0b4ea551de-ol8_aarch64_baseos_latest
perf-4.18.0-425.19.2.el8_7.aarch64.rpmcf9d9a06a6890ccff85265485e6edb6eeeb6f2eaa276223d9f9ceb0b4ea551de-ol8_aarch64_u7_baseos_patch
python3-perf-4.18.0-425.19.2.el8_7.aarch64.rpm0202649b1038256a9361043d757e8345e92121ff3b39c0df7046a82fb8ef6f13-ol8_aarch64_baseos_latest
python3-perf-4.18.0-425.19.2.el8_7.aarch64.rpm0202649b1038256a9361043d757e8345e92121ff3b39c0df7046a82fb8ef6f13-ol8_aarch64_u7_baseos_patch
Oracle Linux 8 (x86_64) kernel-4.18.0-425.19.2.el8_7.src.rpm418dabec5583524f184e9f53906c10fa4a5fda025d1f34dcae270aca5f0ce11a-ol8_x86_64_baseos_latest
kernel-4.18.0-425.19.2.el8_7.src.rpm418dabec5583524f184e9f53906c10fa4a5fda025d1f34dcae270aca5f0ce11a-ol8_x86_64_codeready_builder
kernel-4.18.0-425.19.2.el8_7.src.rpm418dabec5583524f184e9f53906c10fa4a5fda025d1f34dcae270aca5f0ce11a-ol8_x86_64_u7_baseos_patch
bpftool-4.18.0-425.19.2.el8_7.x86_64.rpm588a6d8d064f8949b4eabbb6cd808becda02683bc907a671866fccb76216020f-ol8_x86_64_baseos_latest
bpftool-4.18.0-425.19.2.el8_7.x86_64.rpm588a6d8d064f8949b4eabbb6cd808becda02683bc907a671866fccb76216020f-ol8_x86_64_u7_baseos_patch
kernel-4.18.0-425.19.2.el8_7.x86_64.rpma1755d0d1efe19d6306481012fe66be6dc4701ae483b39c651c742c727ae5f0f-ol8_x86_64_baseos_latest
kernel-4.18.0-425.19.2.el8_7.x86_64.rpma1755d0d1efe19d6306481012fe66be6dc4701ae483b39c651c742c727ae5f0f-ol8_x86_64_u7_baseos_patch
kernel-abi-stablelists-4.18.0-425.19.2.el8_7.noarch.rpm2aa1b37d18dab138bd64334269a760f6d4623d954e372a110cb4c432e71e9609-ol8_x86_64_baseos_latest
kernel-abi-stablelists-4.18.0-425.19.2.el8_7.noarch.rpm2aa1b37d18dab138bd64334269a760f6d4623d954e372a110cb4c432e71e9609-ol8_x86_64_u7_baseos_patch
kernel-core-4.18.0-425.19.2.el8_7.x86_64.rpm46746d47595f3a1c6325ad91ff300390e7a26f98243753fff175276fffcbe4e9-ol8_x86_64_baseos_latest
kernel-core-4.18.0-425.19.2.el8_7.x86_64.rpm46746d47595f3a1c6325ad91ff300390e7a26f98243753fff175276fffcbe4e9-ol8_x86_64_u7_baseos_patch
kernel-cross-headers-4.18.0-425.19.2.el8_7.x86_64.rpmac87e90c833a18cc046b07d2a7e95ac4a4a9699e997d799844c558771bfce25d-ol8_x86_64_baseos_latest
kernel-cross-headers-4.18.0-425.19.2.el8_7.x86_64.rpmac87e90c833a18cc046b07d2a7e95ac4a4a9699e997d799844c558771bfce25d-ol8_x86_64_u7_baseos_patch
kernel-debug-4.18.0-425.19.2.el8_7.x86_64.rpm3407c2b28d4ce17111e229cbed8831ca44963f0624539f0d3bb1073428560a0c-ol8_x86_64_baseos_latest
kernel-debug-4.18.0-425.19.2.el8_7.x86_64.rpm3407c2b28d4ce17111e229cbed8831ca44963f0624539f0d3bb1073428560a0c-ol8_x86_64_u7_baseos_patch
kernel-debug-core-4.18.0-425.19.2.el8_7.x86_64.rpm877bfd842bdd7dab1739b3c7ec9317de0453a5cb67c1081ec4bc5c8c9e3c7864-ol8_x86_64_baseos_latest
kernel-debug-core-4.18.0-425.19.2.el8_7.x86_64.rpm877bfd842bdd7dab1739b3c7ec9317de0453a5cb67c1081ec4bc5c8c9e3c7864-ol8_x86_64_u7_baseos_patch
kernel-debug-devel-4.18.0-425.19.2.el8_7.x86_64.rpm7b11a2f0e22e939cbedd49b594b2876b2e14f46715a2609c531e55167267d0a5-ol8_x86_64_baseos_latest
kernel-debug-devel-4.18.0-425.19.2.el8_7.x86_64.rpm7b11a2f0e22e939cbedd49b594b2876b2e14f46715a2609c531e55167267d0a5-ol8_x86_64_u7_baseos_patch
kernel-debug-modules-4.18.0-425.19.2.el8_7.x86_64.rpm16f4ee4ede3f9bdec33b418f513282d2f902f97fa55158326322dbb79fa7e73b-ol8_x86_64_baseos_latest
kernel-debug-modules-4.18.0-425.19.2.el8_7.x86_64.rpm16f4ee4ede3f9bdec33b418f513282d2f902f97fa55158326322dbb79fa7e73b-ol8_x86_64_u7_baseos_patch
kernel-debug-modules-extra-4.18.0-425.19.2.el8_7.x86_64.rpm6358d495296e273a20b413e124f00f51cb31f55326930df46c811ed3760e790d-ol8_x86_64_baseos_latest
kernel-debug-modules-extra-4.18.0-425.19.2.el8_7.x86_64.rpm6358d495296e273a20b413e124f00f51cb31f55326930df46c811ed3760e790d-ol8_x86_64_u7_baseos_patch
kernel-devel-4.18.0-425.19.2.el8_7.x86_64.rpmc68d25ab982d212303a99d61f6a26a79051c08b17a846c647edf5d6467883785-ol8_x86_64_baseos_latest
kernel-devel-4.18.0-425.19.2.el8_7.x86_64.rpmc68d25ab982d212303a99d61f6a26a79051c08b17a846c647edf5d6467883785-ol8_x86_64_u7_baseos_patch
kernel-doc-4.18.0-425.19.2.el8_7.noarch.rpm1a3bdd9c451d6d031e114a3ad11410169f99d52316d051bd2baff23a83e95534-ol8_x86_64_baseos_latest
kernel-doc-4.18.0-425.19.2.el8_7.noarch.rpm1a3bdd9c451d6d031e114a3ad11410169f99d52316d051bd2baff23a83e95534-ol8_x86_64_u7_baseos_patch
kernel-headers-4.18.0-425.19.2.el8_7.x86_64.rpm86c5d5aa629a7ecd00d52ac4d99ef51d53c0f5825cc12249360914176ab9a5a7-exadata_dbserver_23.1.1.0.0_x86_64_base
kernel-headers-4.18.0-425.19.2.el8_7.x86_64.rpm86c5d5aa629a7ecd00d52ac4d99ef51d53c0f5825cc12249360914176ab9a5a7-exadata_dbserver_23.1.2.0.0_x86_64_base
kernel-headers-4.18.0-425.19.2.el8_7.x86_64.rpm86c5d5aa629a7ecd00d52ac4d99ef51d53c0f5825cc12249360914176ab9a5a7-ol8_x86_64_baseos_latest
kernel-headers-4.18.0-425.19.2.el8_7.x86_64.rpm86c5d5aa629a7ecd00d52ac4d99ef51d53c0f5825cc12249360914176ab9a5a7-ol8_x86_64_u7_baseos_patch
kernel-modules-4.18.0-425.19.2.el8_7.x86_64.rpm1e851d08ef2afbab34870dee9f01fe03365e20a614da866ed2b69a5de4d250d0-ol8_x86_64_baseos_latest
kernel-modules-4.18.0-425.19.2.el8_7.x86_64.rpm1e851d08ef2afbab34870dee9f01fe03365e20a614da866ed2b69a5de4d250d0-ol8_x86_64_u7_baseos_patch
kernel-modules-extra-4.18.0-425.19.2.el8_7.x86_64.rpme951414157e6eb2eb36602571ef73208decb12962caf9c2ce888d5ad07b60c3c-ol8_x86_64_baseos_latest
kernel-modules-extra-4.18.0-425.19.2.el8_7.x86_64.rpme951414157e6eb2eb36602571ef73208decb12962caf9c2ce888d5ad07b60c3c-ol8_x86_64_u7_baseos_patch
kernel-tools-4.18.0-425.19.2.el8_7.x86_64.rpm200be217c22f46886af39007663233c66498e4071f9360830033fc6cdeeeef64-ol8_x86_64_baseos_latest
kernel-tools-4.18.0-425.19.2.el8_7.x86_64.rpm200be217c22f46886af39007663233c66498e4071f9360830033fc6cdeeeef64-ol8_x86_64_u7_baseos_patch
kernel-tools-libs-4.18.0-425.19.2.el8_7.x86_64.rpm2a722875c8ea3af974469862bc5069d61313b3b863029fef8a02c0313bbef405-ol8_x86_64_baseos_latest
kernel-tools-libs-4.18.0-425.19.2.el8_7.x86_64.rpm2a722875c8ea3af974469862bc5069d61313b3b863029fef8a02c0313bbef405-ol8_x86_64_u7_baseos_patch
kernel-tools-libs-devel-4.18.0-425.19.2.el8_7.x86_64.rpm94ee9af6224b83869a99bd5af17a18c30f36063cb956cb2509def58b82f01fce-ol8_x86_64_codeready_builder
perf-4.18.0-425.19.2.el8_7.x86_64.rpmaca1178887b4f14e1e3fb7a7ec7eb4ea14e4a2da6625a6d84f5f57760c2c1d55-ol8_x86_64_baseos_latest
perf-4.18.0-425.19.2.el8_7.x86_64.rpmaca1178887b4f14e1e3fb7a7ec7eb4ea14e4a2da6625a6d84f5f57760c2c1d55-ol8_x86_64_u7_baseos_patch
python3-perf-4.18.0-425.19.2.el8_7.x86_64.rpm78cebd6f4037934138b924fd2c08b0718ed379629a5a8c788bf46f93e617a5e2-ol8_x86_64_baseos_latest
python3-perf-4.18.0-425.19.2.el8_7.x86_64.rpm78cebd6f4037934138b924fd2c08b0718ed379629a5a8c788bf46f93e617a5e2-ol8_x86_64_u7_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete