ELSA-2023-1703

ELSA-2023-1703 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2023-04-12

Description


- [5.14.0-162.23.1_1.OL9]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5
- Remove nmap references from kernel (Mridula Shastry) [Orabug: 34313944]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]

[5.14.0-162.23.1_1]
- ovl: fail on invalid uid/gid mapping at copy up (Miklos Szeredi) [2165344 2165345] {CVE-2023-0386}
- intel_idle: make SPR C1 and C1E be independent (David Arcari) [2168361 2125352]
- intel_idle: Add a new flag to initialize the AMX state (David Arcari) [2168361 2117766]
- x86/fpu: Add a helper to prepare AMX state for low-power CPU idle (David Arcari) [2168361 2117766]
- x86/insn: Add AMX instructions to the x86 instruction decoder (Michael Petlan) [2168361 2140492]
- futex: Resend potentially swallowed owner death notification (Rafael Aquini) [2168836 2161817]
- tun: avoid double free in tun_free_netdev (Jon Maloy) [2156373 2156374] {CVE-2022-4744}


Related CVEs


CVE-2023-0386

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 9 (aarch64) kernel-5.14.0-162.23.1.el9_1.src.rpmdb2eaac352db23e68a2efc702e619e13-
bpftool-5.14.0-162.23.1.el9_1.aarch64.rpme56bd95b7e8ea79cc1c8303a1aeb09fd-
kernel-cross-headers-5.14.0-162.23.1.el9_1.aarch64.rpmb468c3b2d88ecdbcbaf2af21a5e47e73-
kernel-headers-5.14.0-162.23.1.el9_1.aarch64.rpmc3794d9ea21c6b913b13f4b7cb7b5a7e-
kernel-tools-5.14.0-162.23.1.el9_1.aarch64.rpm4b2fee1b6f9796e1e3aba7882eca427e-
kernel-tools-libs-5.14.0-162.23.1.el9_1.aarch64.rpm7c3b1137a28c4ded9402581802b42280-
kernel-tools-libs-devel-5.14.0-162.23.1.el9_1.aarch64.rpm32b73845b66f27d4009164dbd6aa17a9-
perf-5.14.0-162.23.1.el9_1.aarch64.rpm6ed8a07671b20b14a5aa18ed55ad78fd-
python3-perf-5.14.0-162.23.1.el9_1.aarch64.rpm06dcbe94e5919aafc709ef2af68651e3-
Oracle Linux 9 (x86_64) kernel-5.14.0-162.23.1.el9_1.src.rpmdb2eaac352db23e68a2efc702e619e13-
bpftool-5.14.0-162.23.1.el9_1.x86_64.rpm23fdef1fe16e4fe4c04b341056fc00fb-
kernel-5.14.0-162.23.1.el9_1.x86_64.rpm99ebc0e247057a1b58d7b28688107f99-
kernel-abi-stablelists-5.14.0-162.23.1.el9_1.noarch.rpm0531dd6e7d2781600b4c800df0be9d39-
kernel-core-5.14.0-162.23.1.el9_1.x86_64.rpm20e1153c31903680a5924bdac45fa38b-
kernel-cross-headers-5.14.0-162.23.1.el9_1.x86_64.rpm422109ad7739918c2246f74a9589601d-
kernel-debug-5.14.0-162.23.1.el9_1.x86_64.rpm53d90ee99bab24ed40e6eeeace9c84e7-
kernel-debug-core-5.14.0-162.23.1.el9_1.x86_64.rpm362b5b5689afc12d7d47c7af0b8aef5a-
kernel-debug-devel-5.14.0-162.23.1.el9_1.x86_64.rpmc256a4ac5ab97d82b83294ad8558de4e-
kernel-debug-devel-matched-5.14.0-162.23.1.el9_1.x86_64.rpm9ca8034b326066198cfa27b5e867879d-
kernel-debug-modules-5.14.0-162.23.1.el9_1.x86_64.rpm0e9b584c40022717c53e611305f24f9d-
kernel-debug-modules-extra-5.14.0-162.23.1.el9_1.x86_64.rpmdfae9b74afd5292a936c647442c8403d-
kernel-devel-5.14.0-162.23.1.el9_1.x86_64.rpm6141a1df85e2ff5f62fae7e2df46b5c6-
kernel-devel-matched-5.14.0-162.23.1.el9_1.x86_64.rpm9ec759481b3a914bf84f30378d6762de-
kernel-doc-5.14.0-162.23.1.el9_1.noarch.rpm2c3464b7dc5d725b6fb1753af514ff6f-
kernel-headers-5.14.0-162.23.1.el9_1.x86_64.rpm7fa253a7b988a68b80e16f501f33d5ac-
kernel-modules-5.14.0-162.23.1.el9_1.x86_64.rpm285c64f624cebacdfa0a30eb1bc99d50-
kernel-modules-extra-5.14.0-162.23.1.el9_1.x86_64.rpm21d6c6a33f439bc5763d60dcb6b5f4e1-
kernel-tools-5.14.0-162.23.1.el9_1.x86_64.rpm0dc300f6d91ee33fe247f20b8719b8d7-
kernel-tools-libs-5.14.0-162.23.1.el9_1.x86_64.rpm42be401e4e603a4c23e2300d803e7c96-
kernel-tools-libs-devel-5.14.0-162.23.1.el9_1.x86_64.rpm9d87a0d513e31ca1a466b9146358c9b7-
perf-5.14.0-162.23.1.el9_1.x86_64.rpm69733aa3b84ce7f8149da69fff8901c4-
python3-perf-5.14.0-162.23.1.el9_1.x86_64.rpmfef6ac7ebc2c085fe1681aaac351f95b-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete