ELSA-2023-7549

ELSA-2023-7549 - kernel security and bug fix update

Type:SECURITY
Impact:IMPORTANT
Release Date:2023-12-01

Description


[4.18.0-513.9.1_9.OL8]
- media: dvb-core: Fix use-after-free due to race at dvb_register_device() (Mauro Carvalho Chehab) {CVE-2022-45884}
- cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu) {CVE-2023-1192}
- nvmet-tcp: Fix a possible UAF in queue intialization setup (Sagi Grimberg) {CVE-2023-5178}
- net: tun: fix bugs for oversize packet when napi frags enabled (Ziyang Xuan) {CVE-2023-3812}
- bpf: Fix incorrect verifier pruning due to missing register precision taints (Daniel Borkmann) (Andrii Nakryiko) {CVE-2023-2163}
- media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 (Hyunwoo Kim) {CVE-2022-45919}
- media: dvbdev: fix error logic at dvb_register_device() (Mauro Carvalho Chehab)
- media: dvbdev: Fix memleak in dvb_register_device (Dinghao Liu)
- media: dvb-core: Fix use-after-free due on race condition at dvb_net (Hyunwoo Kim} {CVE-2022-45886}

[4.18.0-513.5.1_9.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Drop not needed patch


Related CVEs


CVE-2023-2163
CVE-2023-3812
CVE-2022-45884
CVE-2023-1192
CVE-2022-45919
CVE-2022-45886
CVE-2023-5178

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-4.18.0-513.9.1.el8_9.src.rpm875ccc4fd09a17d29f4c667c408b759518ca9d55f5650f7447330e7ef79bbee7-ol8_aarch64_baseos_latest
kernel-4.18.0-513.9.1.el8_9.src.rpm875ccc4fd09a17d29f4c667c408b759518ca9d55f5650f7447330e7ef79bbee7-ol8_aarch64_codeready_builder
kernel-4.18.0-513.9.1.el8_9.src.rpm875ccc4fd09a17d29f4c667c408b759518ca9d55f5650f7447330e7ef79bbee7-ol8_aarch64_u9_baseos_patch
bpftool-4.18.0-513.9.1.el8_9.aarch64.rpma9bab5b7530d0cea45ce5aca38390863fc9ba6459168f8ceeb693f8ed90b39bb-ol8_aarch64_baseos_latest
bpftool-4.18.0-513.9.1.el8_9.aarch64.rpma9bab5b7530d0cea45ce5aca38390863fc9ba6459168f8ceeb693f8ed90b39bb-ol8_aarch64_u9_baseos_patch
kernel-cross-headers-4.18.0-513.9.1.el8_9.aarch64.rpm136e865a700a8d97331b4bb8678bfb90968747a97b8834b61d436459f4201df2-ol8_aarch64_baseos_latest
kernel-cross-headers-4.18.0-513.9.1.el8_9.aarch64.rpm136e865a700a8d97331b4bb8678bfb90968747a97b8834b61d436459f4201df2-ol8_aarch64_u9_baseos_patch
kernel-headers-4.18.0-513.9.1.el8_9.aarch64.rpme3d2ca266ab510cc6c50b062375a39e56b8eaa8c18a6322ccf9cc0ee31adc6d2-ol8_aarch64_baseos_latest
kernel-headers-4.18.0-513.9.1.el8_9.aarch64.rpme3d2ca266ab510cc6c50b062375a39e56b8eaa8c18a6322ccf9cc0ee31adc6d2-ol8_aarch64_u9_baseos_patch
kernel-tools-4.18.0-513.9.1.el8_9.aarch64.rpmec1c864596dd96ebc7a303b9e70b01eaaa36bce6142bda56dca58997b5c4c2bb-ol8_aarch64_baseos_latest
kernel-tools-4.18.0-513.9.1.el8_9.aarch64.rpmec1c864596dd96ebc7a303b9e70b01eaaa36bce6142bda56dca58997b5c4c2bb-ol8_aarch64_u9_baseos_patch
kernel-tools-libs-4.18.0-513.9.1.el8_9.aarch64.rpmaddf703514b9c88e7e63487a7541a818f8f82f493fc84a16a7fb89f8e91a5dff-ol8_aarch64_baseos_latest
kernel-tools-libs-4.18.0-513.9.1.el8_9.aarch64.rpmaddf703514b9c88e7e63487a7541a818f8f82f493fc84a16a7fb89f8e91a5dff-ol8_aarch64_u9_baseos_patch
kernel-tools-libs-devel-4.18.0-513.9.1.el8_9.aarch64.rpm7ba0ebe8e21dedd40328b323969924de817b6de4ab72282ae0edc6fd167da696-ol8_aarch64_codeready_builder
perf-4.18.0-513.9.1.el8_9.aarch64.rpmb0d610d4d741e70e9d67410272e0edd77b8b41e0e83cf490347873c28d618318-ol8_aarch64_baseos_latest
perf-4.18.0-513.9.1.el8_9.aarch64.rpmb0d610d4d741e70e9d67410272e0edd77b8b41e0e83cf490347873c28d618318-ol8_aarch64_u9_baseos_patch
python3-perf-4.18.0-513.9.1.el8_9.aarch64.rpm7130fa6cf69db5d1d1a056d80b65891428928f41e0beb10ec5c85c4e061b6b0a-ol8_aarch64_baseos_latest
python3-perf-4.18.0-513.9.1.el8_9.aarch64.rpm7130fa6cf69db5d1d1a056d80b65891428928f41e0beb10ec5c85c4e061b6b0a-ol8_aarch64_u9_baseos_patch
Oracle Linux 8 (x86_64) kernel-4.18.0-513.9.1.el8_9.src.rpm875ccc4fd09a17d29f4c667c408b759518ca9d55f5650f7447330e7ef79bbee7-ol8_x86_64_baseos_latest
kernel-4.18.0-513.9.1.el8_9.src.rpm875ccc4fd09a17d29f4c667c408b759518ca9d55f5650f7447330e7ef79bbee7-ol8_x86_64_codeready_builder
kernel-4.18.0-513.9.1.el8_9.src.rpm875ccc4fd09a17d29f4c667c408b759518ca9d55f5650f7447330e7ef79bbee7-ol8_x86_64_u9_baseos_patch
bpftool-4.18.0-513.9.1.el8_9.x86_64.rpm4b09786ecc0d6976e7e9f5415e26a69943c0eeefca338bd997cd7aad64db87e3-ol8_x86_64_baseos_latest
bpftool-4.18.0-513.9.1.el8_9.x86_64.rpm4b09786ecc0d6976e7e9f5415e26a69943c0eeefca338bd997cd7aad64db87e3-ol8_x86_64_u9_baseos_patch
kernel-4.18.0-513.9.1.el8_9.x86_64.rpmad84d23050f3c9c5ba79b5d71da8ff630e52e93d790188ede96ec33e9e0a4c2d-ol8_x86_64_baseos_latest
kernel-4.18.0-513.9.1.el8_9.x86_64.rpmad84d23050f3c9c5ba79b5d71da8ff630e52e93d790188ede96ec33e9e0a4c2d-ol8_x86_64_u9_baseos_patch
kernel-abi-stablelists-4.18.0-513.9.1.el8_9.noarch.rpmb7ac84c6170319e6d8dbf321a8b99299377bf5c8b9b3bd44c7ad778f2373a469-ol8_x86_64_baseos_latest
kernel-abi-stablelists-4.18.0-513.9.1.el8_9.noarch.rpmb7ac84c6170319e6d8dbf321a8b99299377bf5c8b9b3bd44c7ad778f2373a469-ol8_x86_64_u9_baseos_patch
kernel-core-4.18.0-513.9.1.el8_9.x86_64.rpmb6693a36e4d2a1e05663aab3ff56e962d04204a76da9aff6001b685be9245fbe-ol8_x86_64_baseos_latest
kernel-core-4.18.0-513.9.1.el8_9.x86_64.rpmb6693a36e4d2a1e05663aab3ff56e962d04204a76da9aff6001b685be9245fbe-ol8_x86_64_u9_baseos_patch
kernel-cross-headers-4.18.0-513.9.1.el8_9.x86_64.rpm4349ca6d8da7392841e48d353ebf0ecf056d0c58dbe2f849056dab23430d6cac-ol8_x86_64_baseos_latest
kernel-cross-headers-4.18.0-513.9.1.el8_9.x86_64.rpm4349ca6d8da7392841e48d353ebf0ecf056d0c58dbe2f849056dab23430d6cac-ol8_x86_64_u9_baseos_patch
kernel-debug-4.18.0-513.9.1.el8_9.x86_64.rpm474a5d7b3e1eb80ed595712e0a9f873eb34947c611733d1c327476a1578d5edb-ol8_x86_64_baseos_latest
kernel-debug-4.18.0-513.9.1.el8_9.x86_64.rpm474a5d7b3e1eb80ed595712e0a9f873eb34947c611733d1c327476a1578d5edb-ol8_x86_64_u9_baseos_patch
kernel-debug-core-4.18.0-513.9.1.el8_9.x86_64.rpm9f5b950028ab230699bef7ae53e4bb4fedbfb22113694324a69e66b1d8d482b7-ol8_x86_64_baseos_latest
kernel-debug-core-4.18.0-513.9.1.el8_9.x86_64.rpm9f5b950028ab230699bef7ae53e4bb4fedbfb22113694324a69e66b1d8d482b7-ol8_x86_64_u9_baseos_patch
kernel-debug-devel-4.18.0-513.9.1.el8_9.x86_64.rpme2e89eb2d98a47d29d6f282810f3e1c54fedefdcc517d5132f2468fdd988ff49-ol8_x86_64_baseos_latest
kernel-debug-devel-4.18.0-513.9.1.el8_9.x86_64.rpme2e89eb2d98a47d29d6f282810f3e1c54fedefdcc517d5132f2468fdd988ff49-ol8_x86_64_u9_baseos_patch
kernel-debug-modules-4.18.0-513.9.1.el8_9.x86_64.rpme96fac1229f9699bb9c8ec3cd808f2fa28ead528155b21765da6156eec061233-ol8_x86_64_baseos_latest
kernel-debug-modules-4.18.0-513.9.1.el8_9.x86_64.rpme96fac1229f9699bb9c8ec3cd808f2fa28ead528155b21765da6156eec061233-ol8_x86_64_u9_baseos_patch
kernel-debug-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpmc3951b6a4038c7a89b71369ec8bd838033fabb981cc9c88fed1b3b5959c3b963-ol8_x86_64_baseos_latest
kernel-debug-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpmc3951b6a4038c7a89b71369ec8bd838033fabb981cc9c88fed1b3b5959c3b963-ol8_x86_64_u9_baseos_patch
kernel-devel-4.18.0-513.9.1.el8_9.x86_64.rpmb9718300cb3677b11229c31b4ed6e64eff5a99a651f1ebe479e4cfa05d0f2ded-ol8_x86_64_baseos_latest
kernel-devel-4.18.0-513.9.1.el8_9.x86_64.rpmb9718300cb3677b11229c31b4ed6e64eff5a99a651f1ebe479e4cfa05d0f2ded-ol8_x86_64_u9_baseos_patch
kernel-doc-4.18.0-513.9.1.el8_9.noarch.rpm958374b58e33df3ada653868d1fc0d45d33f6f58a552f2b4118435d3548ab07d-ol8_x86_64_baseos_latest
kernel-doc-4.18.0-513.9.1.el8_9.noarch.rpm958374b58e33df3ada653868d1fc0d45d33f6f58a552f2b4118435d3548ab07d-ol8_x86_64_u9_baseos_patch
kernel-headers-4.18.0-513.9.1.el8_9.x86_64.rpmc76c4f5483a3344ec8efb571bd1da31ce3a7aebc712d4e171f2dcc832d6e2b09-exadata_dbserver_23.1.10.0.0_x86_64_base
kernel-headers-4.18.0-513.9.1.el8_9.x86_64.rpmc76c4f5483a3344ec8efb571bd1da31ce3a7aebc712d4e171f2dcc832d6e2b09-ol8_x86_64_baseos_latest
kernel-headers-4.18.0-513.9.1.el8_9.x86_64.rpmc76c4f5483a3344ec8efb571bd1da31ce3a7aebc712d4e171f2dcc832d6e2b09-ol8_x86_64_u9_baseos_patch
kernel-modules-4.18.0-513.9.1.el8_9.x86_64.rpm3ef37080c9857b21d39122317eaddc9db9deacc0f84299a56963a02e80c6af00-ol8_x86_64_baseos_latest
kernel-modules-4.18.0-513.9.1.el8_9.x86_64.rpm3ef37080c9857b21d39122317eaddc9db9deacc0f84299a56963a02e80c6af00-ol8_x86_64_u9_baseos_patch
kernel-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpm8886799db42d415199f71ff28e631f2fe762456aa3dbef9b5b5cb018716c6db7-ol8_x86_64_baseos_latest
kernel-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpm8886799db42d415199f71ff28e631f2fe762456aa3dbef9b5b5cb018716c6db7-ol8_x86_64_u9_baseos_patch
kernel-tools-4.18.0-513.9.1.el8_9.x86_64.rpm4b10c020e50b2aa7801130c5c601cf26264c1a2ef4fdd17124d21ddc9d3dd74a-ol8_x86_64_baseos_latest
kernel-tools-4.18.0-513.9.1.el8_9.x86_64.rpm4b10c020e50b2aa7801130c5c601cf26264c1a2ef4fdd17124d21ddc9d3dd74a-ol8_x86_64_u9_baseos_patch
kernel-tools-libs-4.18.0-513.9.1.el8_9.x86_64.rpmc580ff510cdc6dec83931b6ccc6847ffba1393b51f74f79678160e9b19ae2cd5-ol8_x86_64_baseos_latest
kernel-tools-libs-4.18.0-513.9.1.el8_9.x86_64.rpmc580ff510cdc6dec83931b6ccc6847ffba1393b51f74f79678160e9b19ae2cd5-ol8_x86_64_u9_baseos_patch
kernel-tools-libs-devel-4.18.0-513.9.1.el8_9.x86_64.rpm40e521fddd7c33c106aa25792ff5da21737a7243f5533644f0cc70a39421d7b5-ol8_x86_64_codeready_builder
perf-4.18.0-513.9.1.el8_9.x86_64.rpm98ecf7da1b1252358f365e6d765347addc7435254f3ec7a488b1ac2f24694b71-ol8_x86_64_baseos_latest
perf-4.18.0-513.9.1.el8_9.x86_64.rpm98ecf7da1b1252358f365e6d765347addc7435254f3ec7a488b1ac2f24694b71-ol8_x86_64_u9_baseos_patch
python3-perf-4.18.0-513.9.1.el8_9.x86_64.rpmc4eb220658ac89816a3568b1251da2f7fa8378cb3764e32c33fdf85f7e12a362-ol8_x86_64_baseos_latest
python3-perf-4.18.0-513.9.1.el8_9.x86_64.rpmc4eb220658ac89816a3568b1251da2f7fa8378cb3764e32c33fdf85f7e12a362-ol8_x86_64_u9_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete