Type: | SECURITY |
Impact: | MODERATE |
Release Date: | 2024-09-11 |
[5.14.0-427.35.1_4.OL9]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
[5.14.0-427.35.1_4]
- usb-storage: alauda: Check whether the media is initialized (CKI Backport Bot) [RHEL-43716] {CVE-2024-38619}
- ceph: force sending a cap update msg back to MDS for revoke op (Xiubo Li) [RHEL-55437]
- ceph: periodically flush the cap releases (Xiubo Li) [RHEL-55437]
- mm: avoid overflows in dirty throttling logic (Jay Shin) [RHEL-51848 RHEL-50004] {CVE-2024-42131}
- Revert 'mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again' (Jay Shin) [RHEL-51701 RHEL-50004] {CVE-2024-42102}
- mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (Jay Shin) [RHEL-42628 RHEL-5619] {CVE-2024-26720}
- net: fix out-of-bounds access in ops_init (Paolo Abeni) [RHEL-43188 RHEL-46610] {CVE-2024-36883}
- nvme: avoid double free special payload (CKI Backport Bot) [RHEL-51311] {CVE-2024-41073}
- kernfs: change kernfs_rename_lock into a read-write lock (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: Separate kernfs_pr_cont_buf and rename_lock (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: fix missing kernfs_iattr_rwsem locking (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: Use a per-fs rwsem to protect per-fs list of kernfs_super_info (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: Introduce separate rwsem to protect inode attributes (Jay Shin) [RHEL-55253 RHEL-52956]
- xhci: Handle TD clearing for multiple streams case (CKI Backport Bot) [RHEL-47894 RHEL-47892] {CVE-2024-40927}
- Bluetooth: af_bluetooth: Fix deadlock (Bastien Nocera) [RHEL-34161] {CVE-2024-26886}
- xdp: Remove WARN() from __xdp_reg_mem_model() (CKI Backport Bot) [RHEL-51586] {CVE-2024-42082}
- nfsd: don't take fi_lock in nfsd_break_deleg_cb() (Benjamin Coddington) [RHEL-42578 RHEL-34875]
- nfsd: fix RELEASE_LOCKOWNER (Benjamin Coddington) [RHEL-42578 RHEL-34875] {CVE-2024-26629}
- net: bridge: mst: fix suspicious rcu usage in br_mst_set_state (CKI Backport Bot) [RHEL-43729 RHEL-43727]
- net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state (CKI Backport Bot) [RHEL-43729 RHEL-43727]
- net: bridge: mst: fix vlan use-after-free (cki-backport-bot) [RHEL-43729] {CVE-2024-36979}
- efivarfs: force RO when remounting if SetVariable is not supported (Pavel Reichl) [RHEL-42343 RHEL-26588] {CVE-2023-52463}
- ACPI: arm64: export acpi_arch_thermal_cpufreq_pctg() (Charles Mirabile) [RHEL-34234 RHEL-1697]
- ACPI: processor: reduce CPUFREQ thermal reduction pctg for Tegra241 (Charles Mirabile) [RHEL-34234 RHEL-1697]
- ACPI: thermal: Add Thermal fast Sampling Period (_TFP) support (Scott Weaver) [RHEL-34234 RHEL-1697]
[5.14.0-427.34.1_4]
- mm: prevent derefencing NULL ptr in pfn_section_valid() (Jarod Wilson) [RHEL-51140 RHEL-51138] {CVE-2024-41055}
- mm, kmsan: fix infinite recursion due to RCU critical section (Jarod Wilson) [RHEL-51140 RHEL-51138] {CVE-2024-41055}
- ppp: reject claimed-as-LCP but actually malformed packets (CKI Backport Bot) [RHEL-51061 RHEL-51059] {CVE-2024-41044}
- x86: stop playing stack games in profile_pc() (CKI Backport Bot) [RHEL-51651] {CVE-2024-42096}
- PCI/MSI: Fix UAF in msi_capability_init (CKI Backport Bot) [RHEL-51438] {CVE-2024-41096}
- iommufd: Fix missing update of domains_itree after splitting iopt_area (Jerry Snitselaar) [RHEL-42518 RHEL-28780] {CVE-2023-52801}
- mm: cachestat: fix folio read-after-free in cache walk (Nico Pache) [RHEL-41739 RHEL-5619] {CVE-2024-26630}
- regmap: maple: Fix cache corruption in regcache_maple_drop() (Jaroslav Kysela) [RHEL-43179 RHEL-39706] {CVE-2024-36019}
- mm: cachestat: fix two shmem bugs (Nico Pache) [RHEL-36912] {CVE-2024-35797}
- kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address (Steve Best) [RHEL-42778 RHEL-34985] {CVE-2024-26946}
- mm/hugetlb: fix missing hugetlb_lock for resv uncharge (Rafael Aquini) [RHEL-43132 RHEL-37467] {CVE-2024-36000}
- rbd: don't assume rbd_is_lock_owner() for exclusive mappings (Ilya Dryomov) [RHEL-52675 RHEL-50366]
- rbd: don't assume RBD_LOCK_STATE_LOCKED for exclusive mappings (Ilya Dryomov) [RHEL-52675 RHEL-50366]
- rbd: rename RBD_LOCK_STATE_RELEASING and releasing_wait (Ilya Dryomov) [RHEL-52675 RHEL-50366]
- gpio: tegra186: Fix tegra186_gpio_is_accessible() check (Charles Mirabile) [RHEL-49347 RHEL-32452]
- net/sched: Fix UAF when resolving a clash (CKI Backport Bot) [RHEL-51022 RHEL-51020] {CVE-2024-41040}
- KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() (Maxim Levitsky) [RHEL-41462 RHEL-32430] {CVE-2024-35791}
- cxl/region: Fix memregion leaks in devm_cxl_add_region() (John W. Linville) [RHEL-47965 RHEL-23582] {CVE-2024-40936}
- x86/coco: Require seeding RNG with RDRAND on CoCo systems (Lenny Szubowicz) [RHEL-42986 RHEL-37269] {CVE-2024-35875}
- scsi: qedf: Ensure the copied buf is NUL terminated (cki-backport-bot) [RHEL-44203] {CVE-2024-38559}
Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
Oracle Linux 9 (aarch64) | kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_aarch64_appstream |
kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_aarch64_baseos_latest | |
kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_aarch64_codeready_builder | |
kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_aarch64_u4_baseos_patch | |
bpftool-7.3.0-427.35.1.el9_4.aarch64.rpm | 9729082709b9dc38a3e1827eca32fc492dd01d81237f9663b737395f264dcf5a | - | ol9_aarch64_baseos_latest | |
bpftool-7.3.0-427.35.1.el9_4.aarch64.rpm | 9729082709b9dc38a3e1827eca32fc492dd01d81237f9663b737395f264dcf5a | - | ol9_aarch64_u4_baseos_patch | |
kernel-cross-headers-5.14.0-427.35.1.el9_4.aarch64.rpm | db439997936397b2d1bd57a99a79e84f2c596b98a26cbf6aebba00c924b6b911 | - | ol9_aarch64_codeready_builder | |
kernel-headers-5.14.0-427.35.1.el9_4.aarch64.rpm | c28ddf23701c58018901548966310387c94b5fef587b7f83006b890b7bd047b8 | - | ol9_aarch64_appstream | |
kernel-tools-5.14.0-427.35.1.el9_4.aarch64.rpm | f4ee23c277f9f70feb399f3e4fe6c2217f78bfb430ea83292782e2a7d6b74a96 | - | ol9_aarch64_baseos_latest | |
kernel-tools-5.14.0-427.35.1.el9_4.aarch64.rpm | f4ee23c277f9f70feb399f3e4fe6c2217f78bfb430ea83292782e2a7d6b74a96 | - | ol9_aarch64_u4_baseos_patch | |
kernel-tools-libs-5.14.0-427.35.1.el9_4.aarch64.rpm | 77c696aee3da11007c24f73ff81f1af4b6a2529f815cc18fa97123cce0cbb83e | - | ol9_aarch64_baseos_latest | |
kernel-tools-libs-5.14.0-427.35.1.el9_4.aarch64.rpm | 77c696aee3da11007c24f73ff81f1af4b6a2529f815cc18fa97123cce0cbb83e | - | ol9_aarch64_u4_baseos_patch | |
kernel-tools-libs-devel-5.14.0-427.35.1.el9_4.aarch64.rpm | ffbef5a9e5b659db69e1e50df82a0c7b57fa13105338dbed420c766c267cf46c | - | ol9_aarch64_codeready_builder | |
perf-5.14.0-427.35.1.el9_4.aarch64.rpm | 05151a74d158b2c22012ed71d53bf2cf0faaec92c47d127f1b602cbafe341cb4 | - | ol9_aarch64_appstream | |
python3-perf-5.14.0-427.35.1.el9_4.aarch64.rpm | 48e44b17abfbde3655da1a6bd87d1f0dd51798f507cddc1358e0b386cc2afdc6 | - | ol9_aarch64_baseos_latest | |
python3-perf-5.14.0-427.35.1.el9_4.aarch64.rpm | 48e44b17abfbde3655da1a6bd87d1f0dd51798f507cddc1358e0b386cc2afdc6 | - | ol9_aarch64_u4_baseos_patch | |
Oracle Linux 9 (x86_64) | kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_x86_64_appstream |
kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_x86_64_baseos_latest | |
kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_x86_64_codeready_builder | |
kernel-5.14.0-427.35.1.el9_4.src.rpm | 1dc4140c5532976b237d8ce051782326941ea14266fb2225c125de52d335d85e | - | ol9_x86_64_u4_baseos_patch | |
bpftool-7.3.0-427.35.1.el9_4.x86_64.rpm | a77e7ee2bffbf8c1f98b2765e936262c85e78abe253472c202e9a9de644b93b2 | - | ol9_x86_64_baseos_latest | |
bpftool-7.3.0-427.35.1.el9_4.x86_64.rpm | a77e7ee2bffbf8c1f98b2765e936262c85e78abe253472c202e9a9de644b93b2 | - | ol9_x86_64_u4_baseos_patch | |
kernel-5.14.0-427.35.1.el9_4.x86_64.rpm | 1e309ac3ce8d5557de85f63a9394866cd5002696fbca938ade78541fb8bd1980 | - | ol9_x86_64_baseos_latest | |
kernel-5.14.0-427.35.1.el9_4.x86_64.rpm | 1e309ac3ce8d5557de85f63a9394866cd5002696fbca938ade78541fb8bd1980 | - | ol9_x86_64_u4_baseos_patch | |
kernel-abi-stablelists-5.14.0-427.35.1.el9_4.noarch.rpm | fe37b2a3d0cccef7c4d10d4444f57f6866de2f661e750116b2e1d82f09f5fd11 | - | ol9_x86_64_baseos_latest | |
kernel-abi-stablelists-5.14.0-427.35.1.el9_4.noarch.rpm | fe37b2a3d0cccef7c4d10d4444f57f6866de2f661e750116b2e1d82f09f5fd11 | - | ol9_x86_64_u4_baseos_patch | |
kernel-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 939bc6062357e9a68f120ffb0a22a04b3373bd605b9c168099895f10b8bc2652 | - | ol9_x86_64_baseos_latest | |
kernel-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 939bc6062357e9a68f120ffb0a22a04b3373bd605b9c168099895f10b8bc2652 | - | ol9_x86_64_u4_baseos_patch | |
kernel-cross-headers-5.14.0-427.35.1.el9_4.x86_64.rpm | 75da96cd833ce7447ed60f97d2c44deab0b28efa190dd746029bde8c8d9cfa66 | - | ol9_x86_64_codeready_builder | |
kernel-debug-5.14.0-427.35.1.el9_4.x86_64.rpm | 579549d82a9f5da98ff53edcf21a994e009125fe553cc703fb22604a4fb38f59 | - | ol9_x86_64_baseos_latest | |
kernel-debug-5.14.0-427.35.1.el9_4.x86_64.rpm | 579549d82a9f5da98ff53edcf21a994e009125fe553cc703fb22604a4fb38f59 | - | ol9_x86_64_u4_baseos_patch | |
kernel-debug-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 8d7e31e64e18e92792603518fa717dd5966950e9972198ce4eb17abf31a327b2 | - | ol9_x86_64_baseos_latest | |
kernel-debug-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 8d7e31e64e18e92792603518fa717dd5966950e9972198ce4eb17abf31a327b2 | - | ol9_x86_64_u4_baseos_patch | |
kernel-debug-devel-5.14.0-427.35.1.el9_4.x86_64.rpm | ff2000217b5ec7fedd9c30674f8acebbab113863f263440e9281b6e1fcb0e33c | - | ol9_x86_64_appstream | |
kernel-debug-devel-matched-5.14.0-427.35.1.el9_4.x86_64.rpm | 20176bf759caf6f7a1cc17adbcafc5467f55202f90c4838763433d917f59fb3c | - | ol9_x86_64_appstream | |
kernel-debug-modules-5.14.0-427.35.1.el9_4.x86_64.rpm | 900154561caa31903ddb143a3dca482b6a4f5891a4ad3d75a054def9c0642f00 | - | ol9_x86_64_baseos_latest | |
kernel-debug-modules-5.14.0-427.35.1.el9_4.x86_64.rpm | 900154561caa31903ddb143a3dca482b6a4f5891a4ad3d75a054def9c0642f00 | - | ol9_x86_64_u4_baseos_patch | |
kernel-debug-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 0a1499054039d71a3e7907629fa96f688e851737528676242c7d9e1f16fa70a7 | - | ol9_x86_64_baseos_latest | |
kernel-debug-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 0a1499054039d71a3e7907629fa96f688e851737528676242c7d9e1f16fa70a7 | - | ol9_x86_64_u4_baseos_patch | |
kernel-debug-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm | 0773450df31cbbfa85b0e35d335e88e25a79368785c38306d5523a29a9d42e10 | - | ol9_x86_64_baseos_latest | |
kernel-debug-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm | 0773450df31cbbfa85b0e35d335e88e25a79368785c38306d5523a29a9d42e10 | - | ol9_x86_64_u4_baseos_patch | |
kernel-debug-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm | bfc41ee49a03fea2a5f7763d7afc667e9e3bfd550e2a0f8adb940672a3292039 | - | ol9_x86_64_baseos_latest | |
kernel-debug-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm | bfc41ee49a03fea2a5f7763d7afc667e9e3bfd550e2a0f8adb940672a3292039 | - | ol9_x86_64_u4_baseos_patch | |
kernel-devel-5.14.0-427.35.1.el9_4.x86_64.rpm | 9abc774c92e4aadf50733d113d3d8bce2ca15b4e5cfa5c28ca0ac623f4234922 | - | ol9_x86_64_appstream | |
kernel-devel-matched-5.14.0-427.35.1.el9_4.x86_64.rpm | 0556fb719bbad0d8749f9febdc7a2a3977b169c8d3b4d87cf975e617b6ba423a | - | ol9_x86_64_appstream | |
kernel-doc-5.14.0-427.35.1.el9_4.noarch.rpm | c8ba3d1eb36ce5e6bac39f1e1efdab429b5d21d29bd392d8dc7527d34b4cb11e | - | ol9_x86_64_appstream | |
kernel-headers-5.14.0-427.35.1.el9_4.x86_64.rpm | b37b84b09a21bc30fb38c3e10a281e402d99028ed039d7c915087c2fac365837 | - | ol9_x86_64_appstream | |
kernel-modules-5.14.0-427.35.1.el9_4.x86_64.rpm | 0af75376184b5073aec113a1bf66d2dea0fff8c5f1a669a5ed1d7748d356952c | - | ol9_x86_64_baseos_latest | |
kernel-modules-5.14.0-427.35.1.el9_4.x86_64.rpm | 0af75376184b5073aec113a1bf66d2dea0fff8c5f1a669a5ed1d7748d356952c | - | ol9_x86_64_u4_baseos_patch | |
kernel-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 8f45cd5663263bb357fed7f65f93ef92714ba94888b15a46e680a6665b5375fd | - | ol9_x86_64_baseos_latest | |
kernel-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm | 8f45cd5663263bb357fed7f65f93ef92714ba94888b15a46e680a6665b5375fd | - | ol9_x86_64_u4_baseos_patch | |
kernel-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm | 9e823d8728467e360934742a1243de3837cc85530c6cc1a5356c201c47c8c380 | - | ol9_x86_64_baseos_latest | |
kernel-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm | 9e823d8728467e360934742a1243de3837cc85530c6cc1a5356c201c47c8c380 | - | ol9_x86_64_u4_baseos_patch | |
kernel-tools-5.14.0-427.35.1.el9_4.x86_64.rpm | bafb2786a340c179d367018ecadcc0be9499dcd4b41df9a499a83dd659bb8182 | - | ol9_x86_64_baseos_latest | |
kernel-tools-5.14.0-427.35.1.el9_4.x86_64.rpm | bafb2786a340c179d367018ecadcc0be9499dcd4b41df9a499a83dd659bb8182 | - | ol9_x86_64_u4_baseos_patch | |
kernel-tools-libs-5.14.0-427.35.1.el9_4.x86_64.rpm | e98c271d72c21bbdbc2ff75273b18d9dd817ce4e7f505bce10fe10f080014f19 | - | ol9_x86_64_baseos_latest | |
kernel-tools-libs-5.14.0-427.35.1.el9_4.x86_64.rpm | e98c271d72c21bbdbc2ff75273b18d9dd817ce4e7f505bce10fe10f080014f19 | - | ol9_x86_64_u4_baseos_patch | |
kernel-tools-libs-devel-5.14.0-427.35.1.el9_4.x86_64.rpm | 5733c5de7f21b5bff53d2a282cc2f7e9765397468dfd2a321f8e6dc4956691f9 | - | ol9_x86_64_codeready_builder | |
kernel-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm | 650704555ede178e8197ef3cb6325bfadb2eb03e9ba3606777a1b3f87218c675 | - | ol9_x86_64_baseos_latest | |
kernel-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm | 650704555ede178e8197ef3cb6325bfadb2eb03e9ba3606777a1b3f87218c675 | - | ol9_x86_64_u4_baseos_patch | |
libperf-5.14.0-427.35.1.el9_4.x86_64.rpm | 009d2408290035ec23fcb886635da4dc97061fa4a5baccf248e4ec7f3b1b7b70 | - | ol9_x86_64_codeready_builder | |
perf-5.14.0-427.35.1.el9_4.x86_64.rpm | 23fa46b8b81cc34f7e8df3a29cdd3980b9241e7ed26f0ab10dc351d91b620e87 | - | ol9_x86_64_appstream | |
python3-perf-5.14.0-427.35.1.el9_4.x86_64.rpm | 869d2b1aee8223243a2a59e94f5de7a4aa8350268237d63146168c3452c6717a | - | ol9_x86_64_baseos_latest | |
python3-perf-5.14.0-427.35.1.el9_4.x86_64.rpm | 869d2b1aee8223243a2a59e94f5de7a4aa8350268237d63146168c3452c6717a | - | ol9_x86_64_u4_baseos_patch | |
rtla-5.14.0-427.35.1.el9_4.x86_64.rpm | a214e74bea110c0de3977e1c12f4a5d5f07ff096c15d5a381f58b7380b85b3fb | - | ol9_x86_64_appstream | |
rv-5.14.0-427.35.1.el9_4.x86_64.rpm | ce286f2d556a68c5ebb0f8f5c48d082f3a5c6d2cfab3f38e3a48bc0932843b47 | - | ol9_x86_64_appstream |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team