ELSA-2025-2501

ELSA-2025-2501 - kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-03-28

Description


[3.10.0-1160.119.1.0.7]
- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (Beno_t Sevens) {CVE-2024-53197} [Orabug: 37686305]
- can: bcm: Fix UAF in bcm_proc_show() (YueHaibing) {CVE-2023-52922} [Orabug: 37686305]
- HID: core: zero-initialize the report buffer (Beno_t Sevens) {CVE-2024-50302} [Orabug: 37686305]

[3.10.0-1160.119.1.0.6]
- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (Benoit Sevens) {CVE-2024-53104} [Orabug: 37584712]

[3.10.0-1160.119.1.0.5]
- wifi: mac80211: Avoid address calculations via out of bounds array indexing (Kees Cook) [Orabug: 37092983]

[3.10.0-1160.119.1.0.4]
- fuse: fix pipe buffer lifetime for direct_io (Miklos Szeredi) [Orabug: 36947298]

[3.10.0-1160.119.1.0.3]
- net: fix __dst_negative_advice() race (Eric Dumazet) [Orabug: 36947298]

[3.10.0-1160.119.1.0.2]
- md/raid5: fix oops during stripe resizing (Ritika Srivastava) [Orabug: 34048726]
- blk-mq: Remove generation seqeunce (Ritika Srivastava) [Orabug: 33964689]
- block: init flush rq ref count to 1 (Ritika Srivastava) [Orabug: 33964689]
- block: fix null pointer dereference in blk_mq_rq_timed_out() (Ritika Srivastava) [Orabug: 33964689]
- [xen/netfront] stop tx queues during live migration (Orabug: 33446314)
- [xen/balloon] Support xend-based toolstack (Orabug: 28663970)
- [x86/apic/x2apic] avoid allocate multiple irq vectors for a single interrupt on multiple cpu, otherwise irq vectors would be used up when there are only 2 cpu online per node. [Orabug: 28691156]
- [bonding] avoid repeated display of same link status change. [Orabug: 28109857]
- [ipc] ipc/sem.c: bugfix for semctl(,,GETZCNT) (Manfred Spraul) [Orabug: 22552377]
- kexec: Increase KEXEC_AUTO_RESERVED_SIZE to 256M [Orabug: 31517048]


Related CVEs


CVE-2024-50302
CVE-2023-52922
CVE-2024-53197

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) kernel-3.10.0-1160.119.1.0.7.el7.src.rpm3db48eaa26e5c0a1b93599784115ba45744d84cf05371062086f698e63936699-ol7_x86_64_latest_ELS
bpftool-3.10.0-1160.119.1.0.7.el7.x86_64.rpm7e91b0e0a23d605f66bf75090c66d7013e9c349ad9c8c502750a385591dc65b4-ol7_x86_64_latest_ELS
kernel-3.10.0-1160.119.1.0.7.el7.x86_64.rpm6f217f8e29932bfa3c29e5e93ef4f4203658a03420beee704b80df8686bc8696-ol7_x86_64_latest_ELS
kernel-abi-whitelists-3.10.0-1160.119.1.0.7.el7.noarch.rpmc161862af870f9553d743e591c0f500b7b089093e064c89e8cd16825ec30f323-ol7_x86_64_latest_ELS
kernel-debug-3.10.0-1160.119.1.0.7.el7.x86_64.rpm11029dde8001e6cefb77cfb47848ac4cdd22f84d60acb737456a158738cbb9ac-ol7_x86_64_latest_ELS
kernel-debug-devel-3.10.0-1160.119.1.0.7.el7.x86_64.rpmc536a183d09663402fd0bbfa4cf6bbc506d950b6e4cd8919b2854a2fe28c037b-ol7_x86_64_latest_ELS
kernel-devel-3.10.0-1160.119.1.0.7.el7.x86_64.rpm131711284a74f6e3ecc4e39d5da5b7e1ac6e53aa6c5dc492457c482795e515a5-ol7_x86_64_latest_ELS
kernel-doc-3.10.0-1160.119.1.0.7.el7.noarch.rpm685c75ca5eda7d5d379e133a683dc7081576739d2c8f714bb2357a9e68b980df-ol7_x86_64_latest_ELS
kernel-headers-3.10.0-1160.119.1.0.7.el7.x86_64.rpm88dd73ad15e2fe2ac8a26fadb97f17b4a8b7c4db4cbb9b8a8b43f92cb8143694-ol7_x86_64_latest_ELS
kernel-tools-3.10.0-1160.119.1.0.7.el7.x86_64.rpm87e903f99660f88a6a9265cdb7e6088e6b4950ac0db3c464384844ca1eaa0f30-ol7_x86_64_latest_ELS
kernel-tools-libs-3.10.0-1160.119.1.0.7.el7.x86_64.rpm00f166f90ea5a91a137992416882535b27011d6c4fe59c2c1f0b70d7a691e354-ol7_x86_64_latest_ELS
kernel-tools-libs-devel-3.10.0-1160.119.1.0.7.el7.x86_64.rpm73c4082b6d1383f716f66e666d93bb7693dd4ba23ce4742ce33ac488004efe38-ol7_x86_64_latest_ELS
perf-3.10.0-1160.119.1.0.7.el7.x86_64.rpmeae132a31af75f78c14d8f7790724013407bfa7f2f79a1844aedd47124e6bac2-ol7_x86_64_latest_ELS
python-perf-3.10.0-1160.119.1.0.7.el7.x86_64.rpm247bb8152fe71328a6e85d39709374cd29346cf56c638d83d2bbf32afbf85a53-ol7_x86_64_latest_ELS



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete