ELSA-2024-0461

ELSA-2024-0461 - kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2024-03-07

Description


[5.14.0-362.18.1.el9_3.OL9]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove nmap references from kernel (Mridula Shastry) [Orabug: 34313944]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Disable unified kernel image package build
- Add Oracle Linux IMA certificates

[5.14.0]
- Debranding patches copied from Rocky Linux (Louis Abel and Sherif Nagy from RESF)

[5.14.0-362.18.1.el9_3]
- nfp: fix use-after-free in area_cache_get() (Ricardo Robaina) [RHEL-19456 RHEL-19536 RHEL-6566 RHEL-7241] {CVE-2022-3545}
- rtla: Fix uninitialized variable found (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat: Do not stop user-space if a cpu is offline (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_aa: Fix previous IRQ delay for IRQs that happens after thread sample (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_aa: Fix negative IRQ delay (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_aa: Zero thread sum after every sample analysis (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_hist: Add timerlat user-space support (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_top: Add timerlat user-space support (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/hwnoise: Reduce runtime to 75% (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Start the tracers after creating all instances (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_hist: Add auto-analysis support (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat: Give timerlat auto analysis its own instance (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Automatically move rtla to a house-keeping cpu (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Change monitored_cpus from char * to cpu_set_t (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Add --house-keeping option (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Add -C cgroup support (John Kacur) [RHEL-18360 RHEL-10079]
- ata: ahci: Add Intel Alder Lake-P AHCI controller to low power chipsets list (Tomas Henzl) [RHEL-19394 RHEL-10941]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1106 RHEL-1109 RHEL-12930 RHEL-13899] {CVE-2023-38409}
- fbcon: Fix error paths in set_con2fb_map (Jocelyn Falempe) [RHEL-1106 RHEL-1109 RHEL-12930 RHEL-13899] {CVE-2023-38409}
- net: tun: fix bugs for oversize packet when napi frags enabled (Ricardo Robaina) [RHEL-12495 RHEL-12496 RHEL-7186 RHEL-7264] {CVE-2023-3812}
- netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR (Florian Westphal) [RHEL-10536 RHEL-10538 RHEL-10537 RHEL-10539] {CVE-2023-4015}
- md: Put the right device in md_seq_next (Nigel Croxon) [RHEL-16363 RHEL-12455]
- dpll: sanitize possible null pointer dereference in dpll_pin_parent_pin_set() (Michal Schmidt) [RHEL-19677 RHEL-19095] {CVE-2023-6679}
- dpll: Fix potential msg memleak when genlmsg_put_reply failed (Michal Schmidt) [RHEL-19677 RHEL-19095] {CVE-2023-6679}
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb (Bastien Nocera) [RHEL-19003 RHEL-2717] {CVE-2023-40283}
- tcp: enforce receive buffer memory limits by allowing the tcp window to shrink (Felix Maurer) [RHEL-16129 RHEL-11592]
- tcp: adjust rcv_ssthresh according to sk_reserved_mem (Felix Maurer) [RHEL-16129 RHEL-11592]
- md: raid0: account for split bio in iostat accounting (Nigel Croxon) [RHEL-4082 RHEL-2718]
- can: af_can: fix NULL pointer dereference in can_rcv_filter (Ricardo Robaina) [RHEL-19465 RHEL-19526 RHEL-6428 RHEL-7052] {CVE-2023-2166}


Related CVEs


CVE-2023-2166
CVE-2023-5633
CVE-2023-3777
CVE-2023-6679
CVE-2023-46813
CVE-2023-4622
CVE-2023-4623
CVE-2023-40283
CVE-2023-42753
CVE-2022-3545
CVE-2023-2176
CVE-2023-3812
CVE-2023-5178
CVE-2023-4015
CVE-2022-41858
CVE-2023-38409
CVE-2022-36402

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) kernel-5.14.0-362.18.1.el9_3.src.rpmc9a2d02ae40ae5e40e2789f7cae12f0dff3b7512e12280ad14c1cc7682cf2cb0-ol9_aarch64_appstream
kernel-5.14.0-362.18.1.el9_3.src.rpmc9a2d02ae40ae5e40e2789f7cae12f0dff3b7512e12280ad14c1cc7682cf2cb0-ol9_aarch64_baseos_latest
kernel-5.14.0-362.18.1.el9_3.src.rpmc9a2d02ae40ae5e40e2789f7cae12f0dff3b7512e12280ad14c1cc7682cf2cb0-ol9_aarch64_codeready_builder
bpftool-7.2.0-362.18.1.el9_3.aarch64.rpmb651d2d5aa1bab80e19df72ee91b4f4856ce57da498454151c9fe4729b1d2342-ol9_aarch64_baseos_latest
kernel-cross-headers-5.14.0-362.18.1.el9_3.aarch64.rpm5236503383c4e3857d4d6e80cdeb401a6edecbaeffda6a585f906a0456cb2952-ol9_aarch64_codeready_builder
kernel-headers-5.14.0-362.18.1.el9_3.aarch64.rpmcf438641d9259cc024aaf8e60429014261e7790dc5b4fd8c332c37245f32f383-ol9_aarch64_appstream
kernel-tools-5.14.0-362.18.1.el9_3.aarch64.rpm81a21ccc3ec44c5c40adf44b1aea97dba9510ebf32df17fb10a13bae23762553-ol9_aarch64_baseos_latest
kernel-tools-libs-5.14.0-362.18.1.el9_3.aarch64.rpm6707980e810b7e61e1d5cff66aaf1049e4a3cd5808d4cb310887f26a5c5c2df7-ol9_aarch64_baseos_latest
kernel-tools-libs-devel-5.14.0-362.18.1.el9_3.aarch64.rpm2cb4564f52cba8e16d8a917f0e2253d62df8b22a2f0b82976d7c91858c8b4add-ol9_aarch64_codeready_builder
perf-5.14.0-362.18.1.el9_3.aarch64.rpmff23d69a705d12aa04f08163197d2cea1650d3b8e26815607094e135b3510603-ol9_aarch64_appstream
python3-perf-5.14.0-362.18.1.el9_3.aarch64.rpm33d52507b221038d465470be7f2902e04165c18a8282dd070f2c35c8bca2dda8-ol9_aarch64_baseos_latest
Oracle Linux 9 (x86_64) kernel-5.14.0-362.18.1.el9_3.src.rpmc9a2d02ae40ae5e40e2789f7cae12f0dff3b7512e12280ad14c1cc7682cf2cb0-ol9_x86_64_appstream
kernel-5.14.0-362.18.1.el9_3.src.rpmc9a2d02ae40ae5e40e2789f7cae12f0dff3b7512e12280ad14c1cc7682cf2cb0-ol9_x86_64_baseos_latest
kernel-5.14.0-362.18.1.el9_3.src.rpmc9a2d02ae40ae5e40e2789f7cae12f0dff3b7512e12280ad14c1cc7682cf2cb0-ol9_x86_64_codeready_builder
bpftool-7.2.0-362.18.1.el9_3.x86_64.rpmb565345cf2048f373a07cde9f17c076cc5a11a14ff22f932ffaf5e513a540d90-ol9_x86_64_baseos_latest
kernel-5.14.0-362.18.1.el9_3.x86_64.rpmcf60baebbe64022f7fea51bb5b6ba8d4f1888d3cf0632f45182bef382d05b2d6-ol9_x86_64_baseos_latest
kernel-abi-stablelists-5.14.0-362.18.1.el9_3.noarch.rpm014cbd9f649c77d182f8474f8bd94f99460d3a55d43b4a4f325b964959366fbd-ol9_x86_64_baseos_latest
kernel-core-5.14.0-362.18.1.el9_3.x86_64.rpm98c9aa7cca171e2ba823c88d4ed19318f5f3b1c033cd7a80020e4fdffb6bda83-ol9_x86_64_baseos_latest
kernel-cross-headers-5.14.0-362.18.1.el9_3.x86_64.rpmeb2459832e1fa9faf90aa033d0a2ed75dc214f3a6ab3ea40a64a5e1bf2db3d88-ol9_x86_64_codeready_builder
kernel-debug-5.14.0-362.18.1.el9_3.x86_64.rpmf10ae0d5f21866d8a221652e40a57cf2793e769762ce0ca8ea7a6daffea181a9-ol9_x86_64_baseos_latest
kernel-debug-core-5.14.0-362.18.1.el9_3.x86_64.rpm6c151b1d0a749351187d0ed975e58ac63e74e1bb87c254e013c6b0e071f3600f-ol9_x86_64_baseos_latest
kernel-debug-devel-5.14.0-362.18.1.el9_3.x86_64.rpm97c668e7e8d5a0b584e902d199c2f3b4b91d8ca8e22c2b61aff3caf3f6d912b9-ol9_x86_64_appstream
kernel-debug-devel-matched-5.14.0-362.18.1.el9_3.x86_64.rpme10f4f1bf5098a53712ff38ae8089b86f1af27731fc0820db05f7434a9c45040-ol9_x86_64_appstream
kernel-debug-modules-5.14.0-362.18.1.el9_3.x86_64.rpmdb82f8dbe6038a43839813490ebc1a0fd8d9a92a5f3cb6c6cabac7ff1f60ace7-ol9_x86_64_baseos_latest
kernel-debug-modules-core-5.14.0-362.18.1.el9_3.x86_64.rpm570cbb3f18c033cd041fca6f47819ddab44c892907fe2aeeb6d33a2383d48319-ol9_x86_64_baseos_latest
kernel-debug-modules-extra-5.14.0-362.18.1.el9_3.x86_64.rpm1630a6c811189ee3cf8e03f3179333db041e377c012a7e2fb56d6011fb732bce-ol9_x86_64_baseos_latest
kernel-devel-5.14.0-362.18.1.el9_3.x86_64.rpm034c658c2d63b314688bb5c9b4bc5c0a9fd38326dd3910b2fb6dee871678eabf-ol9_x86_64_appstream
kernel-devel-matched-5.14.0-362.18.1.el9_3.x86_64.rpme5f9e548edc20cd391a9d78d1f2aaf387b381effb25fb4c79f46c5852cad95ec-ol9_x86_64_appstream
kernel-doc-5.14.0-362.18.1.el9_3.noarch.rpm0364806ea7a0831301ed52b1c1d640a6578e4a7ad0faf8561afd3fbb094a5cf3-ol9_x86_64_appstream
kernel-headers-5.14.0-362.18.1.el9_3.x86_64.rpm0ffca86bb520b6c3acd89d71dd6a4acc6618508ff46db0b81d50ed359dfc5226-ol9_x86_64_appstream
kernel-modules-5.14.0-362.18.1.el9_3.x86_64.rpmbfb19e18751fd2a3510c7c17b64fc4d68d12d8558f2f4be5ab46a2d68cf16af4-ol9_x86_64_baseos_latest
kernel-modules-core-5.14.0-362.18.1.el9_3.x86_64.rpmc211b271c2aaa45b7d86916ce51dd96a2bc342a07a1f12ae4a7033090bb025f2-ol9_x86_64_baseos_latest
kernel-modules-extra-5.14.0-362.18.1.el9_3.x86_64.rpm040e159b05e41a1367f6dd6b3569cf94046c3cd744c4f478976e725b33b26755-ol9_x86_64_baseos_latest
kernel-tools-5.14.0-362.18.1.el9_3.x86_64.rpmf20000a840206d2c214d47536ce101431919e68f75e36168947922e47c8e046c-ol9_x86_64_baseos_latest
kernel-tools-libs-5.14.0-362.18.1.el9_3.x86_64.rpm5105a729fdb712cec614a616e053e6b2fd1d0d994324082ba6b02095c726c333-ol9_x86_64_baseos_latest
kernel-tools-libs-devel-5.14.0-362.18.1.el9_3.x86_64.rpm2e880023dcf31d9bf3a0c2f351aca96c3008f0573fd70673905dc5951aeb2592-ol9_x86_64_codeready_builder
libperf-5.14.0-362.18.1.el9_3.x86_64.rpm384446af2ab56f1e1f5eadc13f87d214fd9684488204fcaaf63c889ac3809538-ol9_x86_64_codeready_builder
perf-5.14.0-362.18.1.el9_3.x86_64.rpmce50fd7b4f993c3b996f819efbfa0c51a570c15fb9a51c7b06c8a6ac6fd4d832-ol9_x86_64_appstream
python3-perf-5.14.0-362.18.1.el9_3.x86_64.rpm23156512c4c5492667195e5d47bf733727af7f314b1c5ddc8e3cb72511d85684-ol9_x86_64_baseos_latest
rtla-5.14.0-362.18.1.el9_3.x86_64.rpm811c4a3e42ead464ccc51108459fa094710b0a9774cfd8ec113f26fee9fe22bd-ol9_x86_64_appstream
rv-5.14.0-362.18.1.el9_3.x86_64.rpmbf3d7bc778ea4ceae43855643cb183e1c08c9e3858790c6f308f7529a456c8fb-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete