Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-2714

Опубликовано: 21 июл. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-2714: kernel security and bug fix update (IMPORTANT)

[4.18.0-305.10.2_4.OL8]

  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15-11.0.5

[4.18.0-305.10.2_4]

  • seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975181 1975182] {CVE-2021-33909}

[4.18.0-305.10.1_4]

  • igbvf: amend removal of MODULE_VERSION (Corinna Vinschen) [1969920 1955752]
  • bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971464 1971488] {CVE-2021-32399}
  • scsi: ibmvfc: Free channel_setup_buf during device tear down (Steve Best) [1964697 1938102]
  • i40e: Fix parameters in aq_get_phy_register() (Stefan Assmann) [1967099 1907852]

[4.18.0-305.9.1_4]

  • ixgbevf: Amend commit acf03026ec5a to include a version in module info. (Ken Cox) [1969911 1955764]
  • CI: Merge configuration (Veronika Kabatova)
  • igc: amend removal of MODULE_VERSION (Corinna Vinschen) [1969921 1955755]
  • igb: amend removal of MODULE_VERSION (Corinna Vinschen) [1969919 1955748]
  • locking/qrwlock: Fix ordering in queued_write_lock_slowpath() (Waiman Long) [1964419 1950110]
  • scsi: qedf: Do not put host in qedf_vport_create() unconditionally (Nilesh Javali) [1974968 1899384]

[4.18.0-305.8.1_4]

  • iavf: amend removal of MODULE_VERSION (Stefan Assmann) [1969925 1955738]
  • ixgbe: Amend commit acf03026ec5a to include a version string in module info. (Ken Cox) [1969922 1955759]
  • i40e: amend removal of MODULE_VERSION (Stefan Assmann) [1969923 1955736]
  • redhat/configs: Add CONFIG_PINCTRL_EMMITSBURG (David Arcari) [1963984 1959506]
  • redhat/configs: Remove CONFIG_EMMITSBURG (David Arcari) [1963984 1959506]
  • netlink: add tracepoint at NL_SET_ERR_MSG (Marcelo Ricardo Leitner) [1972938 1956983]
  • Revert '[netdrv] net/intel: remove driver versions from Intel drivers' (Jonathan Toppins) [1969917 1955745]
  • Amends commit ea6244cc248b to include a version string in module info. (Ken Cox) [1969915 1955726]
  • Revert '[netdrv] net/broadcom: Clean broadcom code from driver versions' (Jonathan Toppins) [1969914 1955721]
  • ena: revert removal of MODULE_VERSION from ena (Petr Oros) [1969913 1955712]
  • fm10k: amend removal of MODULE_VERSION (Vladis Dronov) [1969910 1955730]
  • net/sched: act_ct: Offload connections with commit action (Marcelo Ricardo Leitner) [1968679 1965817]
  • netfilter: flowtable: Remove redundant hw refresh bit (Marcelo Ricardo Leitner) [1968679 1965817]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

bpftool

4.18.0-305.10.2.el8_4

kernel-cross-headers

4.18.0-305.10.2.el8_4

kernel-headers

4.18.0-305.10.2.el8_4

kernel-tools

4.18.0-305.10.2.el8_4

kernel-tools-libs

4.18.0-305.10.2.el8_4

kernel-tools-libs-devel

4.18.0-305.10.2.el8_4

perf

4.18.0-305.10.2.el8_4

python3-perf

4.18.0-305.10.2.el8_4

Oracle Linux x86_64

bpftool

4.18.0-305.10.2.el8_4

kernel

4.18.0-305.10.2.el8_4

kernel-abi-stablelists

4.18.0-305.10.2.el8_4

kernel-core

4.18.0-305.10.2.el8_4

kernel-cross-headers

4.18.0-305.10.2.el8_4

kernel-debug

4.18.0-305.10.2.el8_4

kernel-debug-core

4.18.0-305.10.2.el8_4

kernel-debug-devel

4.18.0-305.10.2.el8_4

kernel-debug-modules

4.18.0-305.10.2.el8_4

kernel-debug-modules-extra

4.18.0-305.10.2.el8_4

kernel-devel

4.18.0-305.10.2.el8_4

kernel-doc

4.18.0-305.10.2.el8_4

kernel-headers

4.18.0-305.10.2.el8_4

kernel-modules

4.18.0-305.10.2.el8_4

kernel-modules-extra

4.18.0-305.10.2.el8_4

kernel-tools

4.18.0-305.10.2.el8_4

kernel-tools-libs

4.18.0-305.10.2.el8_4

kernel-tools-libs-devel

4.18.0-305.10.2.el8_4

perf

4.18.0-305.10.2.el8_4

python3-perf

4.18.0-305.10.2.el8_4

Связанные CVE

Связанные уязвимости

rocky
почти 4 года назад

Important: kernel security and bug fix update

oracle-oval
почти 4 года назад

ELSA-2021-9395: Unbreakable Enterprise kernel security update (IMPORTANT)

suse-cvrf
почти 4 года назад

Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP2)

CVSS3: 7
ubuntu
около 4 лет назад

net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.

CVSS3: 7
redhat
около 4 лет назад

net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.

Уязвимость ELSA-2021-2714