ELSA-2023-7549

ELSA-2023-7549 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2023-12-01

Description


[4.18.0-513.9.1_9.OL8]
- media: dvb-core: Fix use-after-free due to race at dvb_register_device() (Mauro Carvalho Chehab) {CVE-2022-45884}
- cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu) {CVE-2023-1192}
- nvmet-tcp: Fix a possible UAF in queue intialization setup (Sagi Grimberg) {CVE-2023-5178}
- net: tun: fix bugs for oversize packet when napi frags enabled (Ziyang Xuan) {CVE-2023-3812}
- bpf: Fix incorrect verifier pruning due to missing register precision taints (Daniel Borkmann) (Andrii Nakryiko) {CVE-2023-2163}
- media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 (Hyunwoo Kim) {CVE-2022-45919}
- media: dvbdev: fix error logic at dvb_register_device() (Mauro Carvalho Chehab)
- media: dvbdev: Fix memleak in dvb_register_device (Dinghao Liu)
- media: dvb-core: Fix use-after-free due on race condition at dvb_net (Hyunwoo Kim} {CVE-2022-45886}

[4.18.0-513.5.1_9.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Drop not needed patch


Related CVEs


CVE-2023-2163
CVE-2023-3812
CVE-2022-45884
CVE-2023-1192
CVE-2022-45919
CVE-2022-45886
CVE-2023-5178

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-4.18.0-513.9.1.el8_9.src.rpm07c4a44b3c02a55e07beb2fd1daf3a62-ol8_aarch64_baseos_latest
kernel-4.18.0-513.9.1.el8_9.src.rpm07c4a44b3c02a55e07beb2fd1daf3a62-ol8_aarch64_codeready_builder
kernel-4.18.0-513.9.1.el8_9.src.rpm07c4a44b3c02a55e07beb2fd1daf3a62-ol8_aarch64_u9_baseos_patch
bpftool-4.18.0-513.9.1.el8_9.aarch64.rpm89bc14d700e2794d1a34d5a2d884406d-ol8_aarch64_baseos_latest
bpftool-4.18.0-513.9.1.el8_9.aarch64.rpm89bc14d700e2794d1a34d5a2d884406d-ol8_aarch64_u9_baseos_patch
kernel-cross-headers-4.18.0-513.9.1.el8_9.aarch64.rpm3e6259e58ae421870a8556d7d2dbd5ad-ol8_aarch64_baseos_latest
kernel-cross-headers-4.18.0-513.9.1.el8_9.aarch64.rpm3e6259e58ae421870a8556d7d2dbd5ad-ol8_aarch64_u9_baseos_patch
kernel-headers-4.18.0-513.9.1.el8_9.aarch64.rpm53b99fa0ad8cc113418df882a892d0a9-ol8_aarch64_baseos_latest
kernel-headers-4.18.0-513.9.1.el8_9.aarch64.rpm53b99fa0ad8cc113418df882a892d0a9-ol8_aarch64_u9_baseos_patch
kernel-tools-4.18.0-513.9.1.el8_9.aarch64.rpmb95493d7c6505b287d0e25eb89771522-ol8_aarch64_baseos_latest
kernel-tools-4.18.0-513.9.1.el8_9.aarch64.rpmb95493d7c6505b287d0e25eb89771522-ol8_aarch64_u9_baseos_patch
kernel-tools-libs-4.18.0-513.9.1.el8_9.aarch64.rpmdc74beaaba8fbccc0302697763627e45-ol8_aarch64_baseos_latest
kernel-tools-libs-4.18.0-513.9.1.el8_9.aarch64.rpmdc74beaaba8fbccc0302697763627e45-ol8_aarch64_u9_baseos_patch
kernel-tools-libs-devel-4.18.0-513.9.1.el8_9.aarch64.rpm60e4968a5ef25543a40469a9cc7b8937-ol8_aarch64_codeready_builder
perf-4.18.0-513.9.1.el8_9.aarch64.rpm6b801b822aa1346bc88bd6f9117d269c-ol8_aarch64_baseos_latest
perf-4.18.0-513.9.1.el8_9.aarch64.rpm6b801b822aa1346bc88bd6f9117d269c-ol8_aarch64_u9_baseos_patch
python3-perf-4.18.0-513.9.1.el8_9.aarch64.rpm0faad30b733f8e129339468d914b91b4-ol8_aarch64_baseos_latest
python3-perf-4.18.0-513.9.1.el8_9.aarch64.rpm0faad30b733f8e129339468d914b91b4-ol8_aarch64_u9_baseos_patch
Oracle Linux 8 (x86_64) kernel-4.18.0-513.9.1.el8_9.src.rpm07c4a44b3c02a55e07beb2fd1daf3a62-ol8_x86_64_baseos_latest
kernel-4.18.0-513.9.1.el8_9.src.rpm07c4a44b3c02a55e07beb2fd1daf3a62-ol8_x86_64_codeready_builder
kernel-4.18.0-513.9.1.el8_9.src.rpm07c4a44b3c02a55e07beb2fd1daf3a62-ol8_x86_64_u9_baseos_patch
bpftool-4.18.0-513.9.1.el8_9.x86_64.rpme679a5b5117a574032af41f79a5a127f-ol8_x86_64_baseos_latest
bpftool-4.18.0-513.9.1.el8_9.x86_64.rpme679a5b5117a574032af41f79a5a127f-ol8_x86_64_u9_baseos_patch
kernel-4.18.0-513.9.1.el8_9.x86_64.rpmc296a8febefc5d6e7bd120d8c6a2810d-ol8_x86_64_baseos_latest
kernel-4.18.0-513.9.1.el8_9.x86_64.rpmc296a8febefc5d6e7bd120d8c6a2810d-ol8_x86_64_u9_baseos_patch
kernel-abi-stablelists-4.18.0-513.9.1.el8_9.noarch.rpm8ada4010801a14ee12780f6a19f3c388-ol8_x86_64_baseos_latest
kernel-abi-stablelists-4.18.0-513.9.1.el8_9.noarch.rpm8ada4010801a14ee12780f6a19f3c388-ol8_x86_64_u9_baseos_patch
kernel-core-4.18.0-513.9.1.el8_9.x86_64.rpmea6c173e1d91932bfd910c7cbce3b451-ol8_x86_64_baseos_latest
kernel-core-4.18.0-513.9.1.el8_9.x86_64.rpmea6c173e1d91932bfd910c7cbce3b451-ol8_x86_64_u9_baseos_patch
kernel-cross-headers-4.18.0-513.9.1.el8_9.x86_64.rpm2deb9ee17bb011d5dbfe0ff6908fefbc-ol8_x86_64_baseos_latest
kernel-cross-headers-4.18.0-513.9.1.el8_9.x86_64.rpm2deb9ee17bb011d5dbfe0ff6908fefbc-ol8_x86_64_u9_baseos_patch
kernel-debug-4.18.0-513.9.1.el8_9.x86_64.rpmddf9c0b0a66c3d51ec97ae827d1e4fc6-ol8_x86_64_baseos_latest
kernel-debug-4.18.0-513.9.1.el8_9.x86_64.rpmddf9c0b0a66c3d51ec97ae827d1e4fc6-ol8_x86_64_u9_baseos_patch
kernel-debug-core-4.18.0-513.9.1.el8_9.x86_64.rpm3b91080d4db73ce522539c5851a370c8-ol8_x86_64_baseos_latest
kernel-debug-core-4.18.0-513.9.1.el8_9.x86_64.rpm3b91080d4db73ce522539c5851a370c8-ol8_x86_64_u9_baseos_patch
kernel-debug-devel-4.18.0-513.9.1.el8_9.x86_64.rpmf940d066cf9c50f9d9856d0c2f0b428e-ol8_x86_64_baseos_latest
kernel-debug-devel-4.18.0-513.9.1.el8_9.x86_64.rpmf940d066cf9c50f9d9856d0c2f0b428e-ol8_x86_64_u9_baseos_patch
kernel-debug-modules-4.18.0-513.9.1.el8_9.x86_64.rpm45201c51100c6ce605c2065fac383aba-ol8_x86_64_baseos_latest
kernel-debug-modules-4.18.0-513.9.1.el8_9.x86_64.rpm45201c51100c6ce605c2065fac383aba-ol8_x86_64_u9_baseos_patch
kernel-debug-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpm6a33847185988ed9cd4bd153eb84c507-ol8_x86_64_baseos_latest
kernel-debug-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpm6a33847185988ed9cd4bd153eb84c507-ol8_x86_64_u9_baseos_patch
kernel-devel-4.18.0-513.9.1.el8_9.x86_64.rpm579aa87d3990c2cbbbef34050cec8df1-ol8_x86_64_baseos_latest
kernel-devel-4.18.0-513.9.1.el8_9.x86_64.rpm579aa87d3990c2cbbbef34050cec8df1-ol8_x86_64_u9_baseos_patch
kernel-doc-4.18.0-513.9.1.el8_9.noarch.rpm40db5b12dd082248c2147b89b5118464-ol8_x86_64_baseos_latest
kernel-doc-4.18.0-513.9.1.el8_9.noarch.rpm40db5b12dd082248c2147b89b5118464-ol8_x86_64_u9_baseos_patch
kernel-headers-4.18.0-513.9.1.el8_9.x86_64.rpm9e08e6c6892c5aefbbd16130ed4cce93-ol8_x86_64_baseos_latest
kernel-headers-4.18.0-513.9.1.el8_9.x86_64.rpm9e08e6c6892c5aefbbd16130ed4cce93-ol8_x86_64_u9_baseos_patch
kernel-modules-4.18.0-513.9.1.el8_9.x86_64.rpmd6202dbfbb849545fe1c509c8dda3593-ol8_x86_64_baseos_latest
kernel-modules-4.18.0-513.9.1.el8_9.x86_64.rpmd6202dbfbb849545fe1c509c8dda3593-ol8_x86_64_u9_baseos_patch
kernel-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpm306d88290baa284b87ae99b67222d560-ol8_x86_64_baseos_latest
kernel-modules-extra-4.18.0-513.9.1.el8_9.x86_64.rpm306d88290baa284b87ae99b67222d560-ol8_x86_64_u9_baseos_patch
kernel-tools-4.18.0-513.9.1.el8_9.x86_64.rpmcc126d63388fefbd0216969f0c22ad48-ol8_x86_64_baseos_latest
kernel-tools-4.18.0-513.9.1.el8_9.x86_64.rpmcc126d63388fefbd0216969f0c22ad48-ol8_x86_64_u9_baseos_patch
kernel-tools-libs-4.18.0-513.9.1.el8_9.x86_64.rpm511c2f358103660d26d497798edd0e8d-ol8_x86_64_baseos_latest
kernel-tools-libs-4.18.0-513.9.1.el8_9.x86_64.rpm511c2f358103660d26d497798edd0e8d-ol8_x86_64_u9_baseos_patch
kernel-tools-libs-devel-4.18.0-513.9.1.el8_9.x86_64.rpmf0736f5a3632766d964b042fb25819a0-ol8_x86_64_codeready_builder
perf-4.18.0-513.9.1.el8_9.x86_64.rpm8d2acdd3c210e2c554cdc9fa7823b4b7-ol8_x86_64_baseos_latest
perf-4.18.0-513.9.1.el8_9.x86_64.rpm8d2acdd3c210e2c554cdc9fa7823b4b7-ol8_x86_64_u9_baseos_patch
python3-perf-4.18.0-513.9.1.el8_9.x86_64.rpmfea10e2be19ac72b930a6e889e4c7305-ol8_x86_64_baseos_latest
python3-perf-4.18.0-513.9.1.el8_9.x86_64.rpmfea10e2be19ac72b930a6e889e4c7305-ol8_x86_64_u9_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete