ELSA-2024-0461

ELSA-2024-0461 - kernel security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2024-03-07

Description


[5.14.0-362.18.1.el9_3.OL9]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove nmap references from kernel (Mridula Shastry) [Orabug: 34313944]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Disable unified kernel image package build
- Add Oracle Linux IMA certificates

[5.14.0]
- Debranding patches copied from Rocky Linux (Louis Abel and Sherif Nagy from RESF)

[5.14.0-362.18.1.el9_3]
- nfp: fix use-after-free in area_cache_get() (Ricardo Robaina) [RHEL-19456 RHEL-19536 RHEL-6566 RHEL-7241] {CVE-2022-3545}
- rtla: Fix uninitialized variable found (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat: Do not stop user-space if a cpu is offline (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_aa: Fix previous IRQ delay for IRQs that happens after thread sample (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_aa: Fix negative IRQ delay (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_aa: Zero thread sum after every sample analysis (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_hist: Add timerlat user-space support (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_top: Add timerlat user-space support (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/hwnoise: Reduce runtime to 75% (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Start the tracers after creating all instances (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat_hist: Add auto-analysis support (John Kacur) [RHEL-18360 RHEL-10079]
- rtla/timerlat: Give timerlat auto analysis its own instance (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Automatically move rtla to a house-keeping cpu (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Change monitored_cpus from char * to cpu_set_t (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Add --house-keeping option (John Kacur) [RHEL-18360 RHEL-10079]
- rtla: Add -C cgroup support (John Kacur) [RHEL-18360 RHEL-10079]
- ata: ahci: Add Intel Alder Lake-P AHCI controller to low power chipsets list (Tomas Henzl) [RHEL-19394 RHEL-10941]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1106 RHEL-1109 RHEL-12930 RHEL-13899] {CVE-2023-38409}
- fbcon: Fix error paths in set_con2fb_map (Jocelyn Falempe) [RHEL-1106 RHEL-1109 RHEL-12930 RHEL-13899] {CVE-2023-38409}
- net: tun: fix bugs for oversize packet when napi frags enabled (Ricardo Robaina) [RHEL-12495 RHEL-12496 RHEL-7186 RHEL-7264] {CVE-2023-3812}
- netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR (Florian Westphal) [RHEL-10536 RHEL-10538 RHEL-10537 RHEL-10539] {CVE-2023-4015}
- md: Put the right device in md_seq_next (Nigel Croxon) [RHEL-16363 RHEL-12455]
- dpll: sanitize possible null pointer dereference in dpll_pin_parent_pin_set() (Michal Schmidt) [RHEL-19677 RHEL-19095] {CVE-2023-6679}
- dpll: Fix potential msg memleak when genlmsg_put_reply failed (Michal Schmidt) [RHEL-19677 RHEL-19095] {CVE-2023-6679}
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb (Bastien Nocera) [RHEL-19003 RHEL-2717] {CVE-2023-40283}
- tcp: enforce receive buffer memory limits by allowing the tcp window to shrink (Felix Maurer) [RHEL-16129 RHEL-11592]
- tcp: adjust rcv_ssthresh according to sk_reserved_mem (Felix Maurer) [RHEL-16129 RHEL-11592]
- md: raid0: account for split bio in iostat accounting (Nigel Croxon) [RHEL-4082 RHEL-2718]
- can: af_can: fix NULL pointer dereference in can_rcv_filter (Ricardo Robaina) [RHEL-19465 RHEL-19526 RHEL-6428 RHEL-7052] {CVE-2023-2166}


Related CVEs


CVE-2023-2166
CVE-2023-5633
CVE-2023-3777
CVE-2023-6679
CVE-2023-46813
CVE-2023-4622
CVE-2023-4623
CVE-2023-40283
CVE-2023-42753
CVE-2022-3545
CVE-2023-2176
CVE-2023-3812
CVE-2023-5178
CVE-2023-4015
CVE-2022-41858
CVE-2023-38409
CVE-2022-36402

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) kernel-5.14.0-362.18.1.el9_3.src.rpmca98c5eda142765a00460b2aaef6e670-ol9_aarch64_appstream
kernel-5.14.0-362.18.1.el9_3.src.rpmca98c5eda142765a00460b2aaef6e670-ol9_aarch64_baseos_latest
kernel-5.14.0-362.18.1.el9_3.src.rpmca98c5eda142765a00460b2aaef6e670-ol9_aarch64_codeready_builder
bpftool-7.2.0-362.18.1.el9_3.aarch64.rpm41c620aaa5adfb9773d512eca1d77ca9-ol9_aarch64_baseos_latest
kernel-cross-headers-5.14.0-362.18.1.el9_3.aarch64.rpmc34c371f86a4a0c41e5c0b9f7cd3a7a7-ol9_aarch64_codeready_builder
kernel-headers-5.14.0-362.18.1.el9_3.aarch64.rpm6e05f205cf8eed63ce4c3ff17666cbd7-ol9_aarch64_appstream
kernel-tools-5.14.0-362.18.1.el9_3.aarch64.rpme93534c06a813b1435d6fda8c0476e7f-ol9_aarch64_baseos_latest
kernel-tools-libs-5.14.0-362.18.1.el9_3.aarch64.rpmbd95f75b79f11c5bf32399c5c084ee01-ol9_aarch64_baseos_latest
kernel-tools-libs-devel-5.14.0-362.18.1.el9_3.aarch64.rpm36ae347cb2b7c35b1d7d3316893f56db-ol9_aarch64_codeready_builder
perf-5.14.0-362.18.1.el9_3.aarch64.rpm143a7b0ac53a7f61ea2038968ee75454-ol9_aarch64_appstream
python3-perf-5.14.0-362.18.1.el9_3.aarch64.rpme46d21b4c0dce51caed00bc1e2a1c326-ol9_aarch64_baseos_latest
Oracle Linux 9 (x86_64) kernel-5.14.0-362.18.1.el9_3.src.rpmca98c5eda142765a00460b2aaef6e670-ol9_x86_64_appstream
kernel-5.14.0-362.18.1.el9_3.src.rpmca98c5eda142765a00460b2aaef6e670-ol9_x86_64_baseos_latest
kernel-5.14.0-362.18.1.el9_3.src.rpmca98c5eda142765a00460b2aaef6e670-ol9_x86_64_codeready_builder
bpftool-7.2.0-362.18.1.el9_3.x86_64.rpm6bc27b01c6a560e9c254c3834da390d8-ol9_x86_64_baseos_latest
kernel-5.14.0-362.18.1.el9_3.x86_64.rpm1b5f5d324b468a65fece079304ce6ac7-ol9_x86_64_baseos_latest
kernel-abi-stablelists-5.14.0-362.18.1.el9_3.noarch.rpmef8d00c4aa97ffa2faa93f5ac8d7f9b9-ol9_x86_64_baseos_latest
kernel-core-5.14.0-362.18.1.el9_3.x86_64.rpm7ff6532cfb1dfba1017d8f600d22e449-ol9_x86_64_baseos_latest
kernel-cross-headers-5.14.0-362.18.1.el9_3.x86_64.rpm07db035114e176896186dac58ffe2d49-ol9_x86_64_codeready_builder
kernel-debug-5.14.0-362.18.1.el9_3.x86_64.rpm82def1db0818f9e824b110a3d390eed2-ol9_x86_64_baseos_latest
kernel-debug-core-5.14.0-362.18.1.el9_3.x86_64.rpmaaee015015c014ec97f312918b456bac-ol9_x86_64_baseos_latest
kernel-debug-devel-5.14.0-362.18.1.el9_3.x86_64.rpm4dc07b31d9cf2c3c6d6a3ed7c0cd8672-ol9_x86_64_appstream
kernel-debug-devel-matched-5.14.0-362.18.1.el9_3.x86_64.rpm2da8682225d50802b0ce9548584d05b5-ol9_x86_64_appstream
kernel-debug-modules-5.14.0-362.18.1.el9_3.x86_64.rpm87afc49f4c8fd4a7be46ee57eb9e7c49-ol9_x86_64_baseos_latest
kernel-debug-modules-core-5.14.0-362.18.1.el9_3.x86_64.rpm4077b457131a8fa22d20c6aa11e4ad29-ol9_x86_64_baseos_latest
kernel-debug-modules-extra-5.14.0-362.18.1.el9_3.x86_64.rpm43e50c34ce4f0370d91529b55cd93c23-ol9_x86_64_baseos_latest
kernel-devel-5.14.0-362.18.1.el9_3.x86_64.rpm73a4d0bbef5baa5858970e89437c48c6-ol9_x86_64_appstream
kernel-devel-matched-5.14.0-362.18.1.el9_3.x86_64.rpmfb955b57df989a28ecf4d4aa0f2f333e-ol9_x86_64_appstream
kernel-doc-5.14.0-362.18.1.el9_3.noarch.rpm74045d0fe7c886d64547984d64c7f141-ol9_x86_64_appstream
kernel-headers-5.14.0-362.18.1.el9_3.x86_64.rpm9a568af458aca41e31283417813cfaf7-ol9_x86_64_appstream
kernel-modules-5.14.0-362.18.1.el9_3.x86_64.rpmdf900de9d216e52acb42cb5bf8bf2e78-ol9_x86_64_baseos_latest
kernel-modules-core-5.14.0-362.18.1.el9_3.x86_64.rpmcf9cf282b9d27e123a0a0ccab71aaef0-ol9_x86_64_baseos_latest
kernel-modules-extra-5.14.0-362.18.1.el9_3.x86_64.rpm36c740891fe49424cf2c67bd8fd398e7-ol9_x86_64_baseos_latest
kernel-tools-5.14.0-362.18.1.el9_3.x86_64.rpmb574c0304f5538b7650804341b61f3c1-ol9_x86_64_baseos_latest
kernel-tools-libs-5.14.0-362.18.1.el9_3.x86_64.rpmb2b6a065228555693358d6fd898f751d-ol9_x86_64_baseos_latest
kernel-tools-libs-devel-5.14.0-362.18.1.el9_3.x86_64.rpm358d5a04f634976b0ea0c8ffa19bcde0-ol9_x86_64_codeready_builder
libperf-5.14.0-362.18.1.el9_3.x86_64.rpm3aea9b48622ecec95479635bfeb506b2-ol9_x86_64_codeready_builder
perf-5.14.0-362.18.1.el9_3.x86_64.rpmefb488d319589ce5b3dde31810ec3341-ol9_x86_64_appstream
python3-perf-5.14.0-362.18.1.el9_3.x86_64.rpmccd09328d3d71aa63f4ab113ef77f1a0-ol9_x86_64_baseos_latest
rtla-5.14.0-362.18.1.el9_3.x86_64.rpmb03d613eb98ba50846f3c77c32a4b51e-ol9_x86_64_appstream
rv-5.14.0-362.18.1.el9_3.x86_64.rpmf15f07afebadf09ca4b612532fa1ab5d-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete