Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-0188

Опубликовано: 21 янв. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-0188: kernel security and bug fix update (IMPORTANT)

[4.18.0-348.12.2_5.OL8]

  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15-11.0.5

[4.18.0-348.12.2_5]

  • vfs: Out-of-bounds write of heap buffer in fs_context.c (Frantisek Hrbata) [2040585 2040586] {CVE-2022-0185}
  • xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Bruno Meneguele) [2034864 2034865] {CVE-2021-4155}

[4.18.0-348.12.1_5]

  • tcp: don't free a FIN sk_buff in tcp_remove_empty_skb() (Guillaume Nault) [2021574 2016210]
  • kernel.spec: Add support to use vmlinux.h (Jiri Olsa) [2031053 1989087]
  • spec: Add vmlinux.h to kernel-devel package (Jiri Olsa) [2031053 1989087]
  • x86/mce: Avoid infinite loop for copy from user recovery (Prarit Bhargava) [2008789 1999550]
  • x86/mce: Rename kill_it to kill_current_task (Prarit Bhargava) [2008789 1999550]
  • x86/mce: Recover from poison found while copying from user space (Prarit Bhargava) [2008789 1999550]
  • x86/mce: Delay clearing IA32_MCG_STATUS to the end of do_machine_check() (Prarit Bhargava) [2008789 1999550]
  • x86/mce: Send #MC singal from task work (Prarit Bhargava) [2008789 1999550]

[4.18.0-348.11.1_5]

  • blk-mq: avoid to iterate over stale request (Ming Lei) [2034396 1997338]
  • rcu: Tighten rcu_advance_cbs_nowake() checks (Daniel Vacek) [2032579 2013408]

[4.18.0-348.10.1_5]

  • selftests: add a test case for mirred egress to ingress (Xin Long) [2024411 1983894]
  • net: sched: act_mirred: drop dst for the direction from egress to ingress (Xin Long) [2024411 1983894]

[4.18.0-348.9.1_5]

  • ixgbe: Revert 'bpf, devmap: Move drop error path to devmap for XDP_REDIRECT' (Ken Cox) [2029845 2024240]
  • i40e: Revert 'bpf, devmap: Move drop error path to devmap for XDP_REDIRECT' (Stefan Assmann) [2029845 2024225]
  • rcu/nocb: Perform deferred wake up before last idle's need_resched() check (Waiman Long) [2029449 2008340]

[4.18.0-348.8.1_5]

  • ice: Fix VF true promiscuous mode (Jonathan Toppins) [2026698 1970643]
  • ice: Remove toggling of antispoof for VF trusted promiscuous mode (Jonathan Toppins) [2026698 1970643]
  • ice: Fix replacing VF hardware MAC to existing MAC filter (Jonathan Toppins) [2026698 1970643]
  • ice: Fix not stopping Tx queues for VFs (Jonathan Toppins) [2026698 1970643]
  • ice: Fix race conditions between virtchnl handling and VF ndo ops (Jonathan Toppins) [2026698 1970643]
  • net/netif_receive_skb_core: Use migrate_disable() (Luis Claudio R. Goncalves) [2027689 2024168]
  • crypto: jitter - consider 32 LSB for APT (Herbert Xu) [2029365 1994390]
  • xfs: fix I_DONTCACHE (Carlos Maiolino) [2028534 2024969]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

bpftool

4.18.0-348.12.2.el8_5

kernel-cross-headers

4.18.0-348.12.2.el8_5

kernel-headers

4.18.0-348.12.2.el8_5

kernel-tools

4.18.0-348.12.2.el8_5

kernel-tools-libs

4.18.0-348.12.2.el8_5

kernel-tools-libs-devel

4.18.0-348.12.2.el8_5

perf

4.18.0-348.12.2.el8_5

python3-perf

4.18.0-348.12.2.el8_5

Oracle Linux x86_64

bpftool

4.18.0-348.12.2.el8_5

kernel

4.18.0-348.12.2.el8_5

kernel-abi-stablelists

4.18.0-348.12.2.el8_5

kernel-core

4.18.0-348.12.2.el8_5

kernel-cross-headers

4.18.0-348.12.2.el8_5

kernel-debug

4.18.0-348.12.2.el8_5

kernel-debug-core

4.18.0-348.12.2.el8_5

kernel-debug-devel

4.18.0-348.12.2.el8_5

kernel-debug-modules

4.18.0-348.12.2.el8_5

kernel-debug-modules-extra

4.18.0-348.12.2.el8_5

kernel-devel

4.18.0-348.12.2.el8_5

kernel-doc

4.18.0-348.12.2.el8_5

kernel-headers

4.18.0-348.12.2.el8_5

kernel-modules

4.18.0-348.12.2.el8_5

kernel-modules-extra

4.18.0-348.12.2.el8_5

kernel-tools

4.18.0-348.12.2.el8_5

kernel-tools-libs

4.18.0-348.12.2.el8_5

kernel-tools-libs-devel

4.18.0-348.12.2.el8_5

perf

4.18.0-348.12.2.el8_5

python3-perf

4.18.0-348.12.2.el8_5

Связанные CVE

Связанные уязвимости

rocky
больше 3 лет назад

Important: kernel-rt security and bug fix update

oracle-oval
больше 3 лет назад

ELSA-2022-9148: Unbreakable Enterprise kernel-container security update (IMPORTANT)

oracle-oval
больше 3 лет назад

ELSA-2022-9147: Unbreakable Enterprise kernel security update (IMPORTANT)

CVSS3: 5.5
ubuntu
почти 3 года назад

A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.

CVSS3: 5.5
redhat
больше 3 лет назад

A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.

Уязвимость ELSA-2022-0188