Описание
ELSA-2022-9198: Unbreakable Enterprise kernel security update (IMPORTANT)
[4.14.35-2047.511.5.4]
- x86/speculation: Add knob for eibrs_retpoline_enabled (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Extend our code to properly support eibrs+lfence and eibrs+retpoline (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Update link to AMD speculation whitepaper (Kim Phillips) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Use generic retpoline by default on AMD (Kim Phillips) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting (Josh Poimboeuf) [Orabug: 33922122] {CVE-2021-26341}
- Documentation/hw-vuln: Update spectre doc (Peter Zijlstra) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Add eIBRS + Retpoline options (Peter Zijlstra) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE (Peter Zijlstra (Intel)) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Merge one test in spectre_v2_user_select_mitigation() (Borislav Petkov) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Update ALTERNATIVEs to (more closely) match upstream (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341}
- x86/speculation: Fix bug in retpoline mode on AMD with (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341}
- bpf: Add kconfig knob for disabling unpriv bpf by default (Daniel Borkmann) [Orabug: 33926438]
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
kernel-uek
4.14.35-2047.511.5.4.el7uek
kernel-uek-debug
4.14.35-2047.511.5.4.el7uek
kernel-uek-debug-devel
4.14.35-2047.511.5.4.el7uek
kernel-uek-devel
4.14.35-2047.511.5.4.el7uek
kernel-uek-headers
4.14.35-2047.511.5.4.el7uek
kernel-uek-tools
4.14.35-2047.511.5.4.el7uek
kernel-uek-tools-libs
4.14.35-2047.511.5.4.el7uek
kernel-uek-tools-libs-devel
4.14.35-2047.511.5.4.el7uek
perf
4.14.35-2047.511.5.4.el7uek
python-perf
4.14.35-2047.511.5.4.el7uek
Oracle Linux x86_64
kernel-uek
4.14.35-2047.511.5.4.el7uek
kernel-uek-debug
4.14.35-2047.511.5.4.el7uek
kernel-uek-debug-devel
4.14.35-2047.511.5.4.el7uek
kernel-uek-devel
4.14.35-2047.511.5.4.el7uek
kernel-uek-doc
4.14.35-2047.511.5.4.el7uek
kernel-uek-tools
4.14.35-2047.511.5.4.el7uek
Связанные CVE
Связанные уязвимости
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
ELSA-2022-9201: Unbreakable Enterprise kernel-container security update (IMPORTANT)
ELSA-2022-9200: Unbreakable Enterprise kernel-container security update (IMPORTANT)