Описание
ELSA-2022-9609: Unbreakable Enterprise kernel security update (IMPORTANT)
[5.4.17-2136.309.5]
- lockdown: Fix kexec lockdown bypass with ima policy (Eric Snowberg) [Orabug: 34386637] {CVE-2022-21505}
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
kernel-uek
5.4.17-2136.309.5.el7uek
kernel-uek-debug
5.4.17-2136.309.5.el7uek
kernel-uek-debug-devel
5.4.17-2136.309.5.el7uek
kernel-uek-devel
5.4.17-2136.309.5.el7uek
kernel-uek-doc
5.4.17-2136.309.5.el7uek
kernel-uek-tools
5.4.17-2136.309.5.el7uek
kernel-uek-tools-libs
5.4.17-2136.309.5.el7uek
perf
5.4.17-2136.309.5.el7uek
python-perf
5.4.17-2136.309.5.el7uek
Oracle Linux x86_64
kernel-uek
5.4.17-2136.309.5.el7uek
kernel-uek-debug
5.4.17-2136.309.5.el7uek
kernel-uek-debug-devel
5.4.17-2136.309.5.el7uek
kernel-uek-devel
5.4.17-2136.309.5.el7uek
kernel-uek-doc
5.4.17-2136.309.5.el7uek
kernel-uek-tools
5.4.17-2136.309.5.el7uek
Oracle Linux 8
Oracle Linux aarch64
kernel-uek
5.4.17-2136.309.5.el8uek
kernel-uek-debug
5.4.17-2136.309.5.el8uek
kernel-uek-debug-devel
5.4.17-2136.309.5.el8uek
kernel-uek-devel
5.4.17-2136.309.5.el8uek
kernel-uek-doc
5.4.17-2136.309.5.el8uek
Oracle Linux x86_64
kernel-uek
5.4.17-2136.309.5.el8uek
kernel-uek-debug
5.4.17-2136.309.5.el8uek
kernel-uek-debug-devel
5.4.17-2136.309.5.el8uek
kernel-uek-devel
5.4.17-2136.309.5.el8uek
kernel-uek-doc
5.4.17-2136.309.5.el8uek
Связанные CVE
Связанные уязвимости
In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
In the linux kernel, if IMA appraisal is used with the "ima_appraise=l ...
ELSA-2022-9612: Unbreakable Enterprise kernel-container security update (IMPORTANT)