Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-3349

Опубликовано: 01 июн. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-3349: kernel security and bug fix update (IMPORTANT)

[4.18.0-477.13.1_8.OL8]

  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]

[4.18.0-477.13.1_8]

  • netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196147 2196146] {CVE-2023-32233}

[4.18.0-477.12.1_8]

  • redhat/configs: Fix incorrect configs location and content (Vladis Dronov)
  • wifi: iwlwifi: mvm: protect TXQ list manipulation (Jose Ignacio Tornos Martinez) [2183471 2152168]
  • wifi: iwlwifi: mvm: fix mvmtxq->stopped handling (Jose Ignacio Tornos Martinez) [2183471 2152168]
  • migrate: grab the compound head in migration_entry_wait_on_locked (Nico Pache) [2189629 2188249]
  • redhat/configs: Fix DEBUG_BLK_CGROUP and BFQ_CGROUP_DEBUG configs (Vladis Dronov)
  • redhat: switch release to zstream (Lucas Zampieri)

[4.18.0-477.11.1_8]

  • crypto: drbg - Only fail when jent is unavailable in FIPS mode (Vladis Dronov) [2181730 2175712]
  • crypto: jitter - permanent and intermittent health errors (Vladis Dronov) [2181730 2175712]
  • crypto: jitter - quit sample collection loop upon RCT failure (Vladis Dronov) [2181730 2175712]
  • crypto: jitter - don't limit ->health_failure check to FIPS mode (Vladis Dronov) [2181730 2175712]
  • crypto: jitter - drop kernel-doc notation (Vladis Dronov) [2181730 2175712]
  • qede: avoid uninitialized entries in coal_entry array (Michal Schmidt) [2176104 2160054]
  • qede: fix interrupt coalescing configuration (Jonathan Toppins) [2176104 2160054]
  • crypto: qat - add support for 402xx devices (Vladis Dronov) [2176850 2144529]
  • crypto: qat - drop log level of msg in get_instance_node() (Vladis Dronov) [2176850 2144529]
  • crypto: qat - fix out-of-bounds read (Vladis Dronov) [2176850 2144529]
  • Documentation: qat: change kernel version (Vladis Dronov) [2176850 2144529]
  • crypto: qat - add qat_zlib_deflate (Vladis Dronov) [2176850 2144529]
  • crypto: qat - extend buffer list logic interface (Vladis Dronov) [2176850 2144529]
  • crypto: qat - fix spelling mistakes from 'bufer' to 'buffer' (Vladis Dronov) [2176850 2144529]
  • crypto: qat - add resubmit logic for decompression (Vladis Dronov) [2176850 2144529]
  • crypto: acomp - define max size for destination (Vladis Dronov) [2176850 2144529]
  • crypto: qat - enable deflate for QAT GEN4 (Vladis Dronov) [2176850 2144529]
  • crypto: qat - expose deflate through acomp api for QAT GEN2 (Vladis Dronov) [2176850 2144529]
  • crypto: qat - rename and relocate GEN2 config function (Vladis Dronov) [2176850 2144529]
  • crypto: qat - relocate qat_algs_alloc_flags() (Vladis Dronov) [2176850 2144529]
  • crypto: qat - relocate backlog related structures (Vladis Dronov) [2176850 2144529]
  • crypto: qat - extend buffer list interface (Vladis Dronov) [2176850 2144529]
  • crypto: qat - generalize crypto request buffers (Vladis Dronov) [2176850 2144529]
  • crypto: qat - change bufferlist logic interface (Vladis Dronov) [2176850 2144529]
  • crypto: qat - rename bufferlist functions (Vladis Dronov) [2176850 2144529]
  • crypto: qat - relocate bufferlist logic (Vladis Dronov) [2176850 2144529]
  • crypto: qat - Use helper to set reqsize (Vladis Dronov) [2176850 2144529]
  • crypto: kpp - Add helper to set reqsize (Vladis Dronov) [2176850 2144529]
  • crypto: qat - fix error return code in adf_probe (Vladis Dronov) [2176850 2144529]
  • crypto: qat - remove ADF_STATUS_PF_RUNNING flag from probe (Vladis Dronov) [2176850 2144529]
  • sched/core: Fix arch_scale_freq_tick() on tickless systems (Phil Auld) [2188067 2184083]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

bpftool

4.18.0-477.13.1.el8_8

kernel-cross-headers

4.18.0-477.13.1.el8_8

kernel-headers

4.18.0-477.13.1.el8_8

kernel-tools

4.18.0-477.13.1.el8_8

kernel-tools-libs

4.18.0-477.13.1.el8_8

kernel-tools-libs-devel

4.18.0-477.13.1.el8_8

perf

4.18.0-477.13.1.el8_8

python3-perf

4.18.0-477.13.1.el8_8

Oracle Linux x86_64

bpftool

4.18.0-477.13.1.el8_8

kernel

4.18.0-477.13.1.el8_8

kernel-abi-stablelists

4.18.0-477.13.1.el8_8

kernel-core

4.18.0-477.13.1.el8_8

kernel-cross-headers

4.18.0-477.13.1.el8_8

kernel-debug

4.18.0-477.13.1.el8_8

kernel-debug-core

4.18.0-477.13.1.el8_8

kernel-debug-devel

4.18.0-477.13.1.el8_8

kernel-debug-modules

4.18.0-477.13.1.el8_8

kernel-debug-modules-extra

4.18.0-477.13.1.el8_8

kernel-devel

4.18.0-477.13.1.el8_8

kernel-doc

4.18.0-477.13.1.el8_8

kernel-headers

4.18.0-477.13.1.el8_8

kernel-modules

4.18.0-477.13.1.el8_8

kernel-modules-extra

4.18.0-477.13.1.el8_8

kernel-tools

4.18.0-477.13.1.el8_8

kernel-tools-libs

4.18.0-477.13.1.el8_8

kernel-tools-libs-devel

4.18.0-477.13.1.el8_8

perf

4.18.0-477.13.1.el8_8

python3-perf

4.18.0-477.13.1.el8_8

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

CVSS3: 7.8
redhat
около 2 лет назад

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

CVSS3: 7.8
nvd
около 2 лет назад

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

CVSS3: 7.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 2 лет назад

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_ta ...