Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-0897

Опубликовано: 06 мар. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-0897: kernel security update (IMPORTANT)

[4.18.0-513.18.1.el8_9.OL8]

  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
  • Drop not needed patch

[4.18.0-513.18.1.el8_9]

  • net: tls, update curr on splice as well (Sabrina Dubroca) [RHEL-22091 RHEL-19065] {CVE-2024-0646}
  • smb: client: fix potential OOB in smb2_dump_detail() (Scott Mayhew) [RHEL-21672 RHEL-19144] {CVE-2023-6610}
  • smb: client: fix potential OOB in cifs_dump_detail() (Scott Mayhew) [RHEL-21672 RHEL-19144] {CVE-2023-6610}
  • nvmet-tcp: Fix the H2C expected PDU len calculation (Maurizio Lombardi) [RHEL-22299 RHEL-22637 RHEL-22641 RHEL-19155 RHEL-19161 RHEL-19167] {CVE-2023-6535 CVE-2023-6356 CVE-2023-6536}
  • nvmet-tcp: remove boilerplate code (Maurizio Lombardi) [RHEL-22299 RHEL-22637 RHEL-22641 RHEL-19155 RHEL-19161 RHEL-19167] {CVE-2023-6535 CVE-2023-6356 CVE-2023-6536}
  • nvmet-tcp: fix a crash in nvmet_req_complete() (Maurizio Lombardi) [RHEL-22299 RHEL-22637 RHEL-22641 RHEL-19155 RHEL-19161 RHEL-19167] {CVE-2023-6535 CVE-2023-6356 CVE-2023-6536}
  • nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length (Maurizio Lombardi) [RHEL-22299 RHEL-22637 RHEL-22641 RHEL-19155 RHEL-19161 RHEL-19167] {CVE-2023-6535 CVE-2023-6356 CVE-2023-6536}
  • net-sysfs: add check for netdevice being present to speed_show (Michal Schmidt) [RHEL-20924 RHEL-16007]
  • netfilter: nft_set_pipapo: skip inactive elements during set walk (Florian Westphal) [RHEL-20698 RHEL-19721] {CVE-2023-6817}

[4.18.0-513.17.1.el8_9]

  • redhat: rewrite genlog and support Y- tags (Jan Stancek)
  • smb: client: fix OOB in smbCalcSize() (Scott Mayhew) [RHEL-21662 RHEL-18990] {CVE-2023-6606}
  • s390/qeth: Don't call dev_close/dev_open (DOWN/UP) (Tobias Huschle) [RHEL-17884 RHEL-2410]
  • blk-mq: use quiesced elevator switch when reinitializing queues (Ming Lei) [RHEL-21785 RHEL-19944]
  • lib/group_cpus.c: avoid acquiring cpu hotplug lock in group_cpus_evenly (Ming Lei) [RHEL-20232 RHEL-8128]

[4.18.0-513.16.1.el8_9]

  • tracing/timerlat: Add user-space interface (Chris White) [RHEL-20362 RHEL-15142]
  • tracing/osnoise: Skip running osnoise if all instances are off (Chris White) [RHEL-20362 RHEL-15142]
  • tracing/osnoise: Switch from PF_NO_SETAFFINITY to migrate_disable (Chris White) [RHEL-20362 RHEL-15142]
  • tracing/timerlat: Always wakeup the timerlat thread (Chris White) [RHEL-20362 RHEL-15142]
  • tracing/osnoise: Fix notify new tracing_max_latency (Chris White) [RHEL-20362 RHEL-15142]
  • tracing/timerlat: Notify new max thread latency (Chris White) [RHEL-20362 RHEL-15142]
  • trace/osnoise: make use of the helper function kthread_run_on_cpu() (Chris White) [RHEL-20362 RHEL-15142]
  • kthread: add the helper function kthread_run_on_cpu() (Chris White) [RHEL-20362 RHEL-15142]
  • x86/apic: Mark all legacy interrupts when IO/APIC is missing (Prarit Bhargava) [RHEL-7238 RHEL-4244]
  • HID: check empty report_list in hid_validate_values() (Desnes Nunes) [RHEL-19274 RHEL-19237] {CVE-2023-1073}
  • s390/dasd: print copy pair message only for the correct error (Tobias Huschle) [RHEL-9444 RHEL-2831]
  • blk-mq: don't count completed flush data request as inflight in case of quiesce (Ming Lei) [RHEL-19111 RHEL-18055]

[4.18.0-513.15.1.el8_9]

  • IB/ipoib: Fix mcast list locking (Daniel Vacek) [RHEL-19699 RHEL-19244]
  • RDMA/IPoIB: Fix error code return in ipoib_mcast_join (Daniel Vacek) [RHEL-19699 RHEL-19244]
  • x86/sev: Check for user-space IOIO pointing to kernel space (Wander Lairson Costa) [RHEL-18014 RHEL-14978] {CVE-2023-46813}
  • x86/sev: Check IOBM for IOIO exceptions from user-space (Wander Lairson Costa) [RHEL-18014 RHEL-14978] {CVE-2023-46813}
  • x86/sev: Disable MMIO emulation from user mode (Wander Lairson Costa) [RHEL-18014 RHEL-14978] {CVE-2023-46813}
  • x86/sev-es: Fix SEV-ES OUT/IN immediate opcode vc handling (Wander Lairson Costa) [RHEL-18014 RHEL-14978] {CVE-2023-46813}

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

bpftool

4.18.0-513.18.1.el8_9

kernel-cross-headers

4.18.0-513.18.1.el8_9

kernel-headers

4.18.0-513.18.1.el8_9

kernel-tools

4.18.0-513.18.1.el8_9

kernel-tools-libs

4.18.0-513.18.1.el8_9

kernel-tools-libs-devel

4.18.0-513.18.1.el8_9

perf

4.18.0-513.18.1.el8_9

python3-perf

4.18.0-513.18.1.el8_9

Oracle Linux x86_64

bpftool

4.18.0-513.18.1.el8_9

kernel

4.18.0-513.18.1.el8_9

kernel-abi-stablelists

4.18.0-513.18.1.el8_9

kernel-core

4.18.0-513.18.1.el8_9

kernel-cross-headers

4.18.0-513.18.1.el8_9

kernel-debug

4.18.0-513.18.1.el8_9

kernel-debug-core

4.18.0-513.18.1.el8_9

kernel-debug-devel

4.18.0-513.18.1.el8_9

kernel-debug-modules

4.18.0-513.18.1.el8_9

kernel-debug-modules-extra

4.18.0-513.18.1.el8_9

kernel-devel

4.18.0-513.18.1.el8_9

kernel-doc

4.18.0-513.18.1.el8_9

kernel-headers

4.18.0-513.18.1.el8_9

kernel-modules

4.18.0-513.18.1.el8_9

kernel-modules-extra

4.18.0-513.18.1.el8_9

kernel-tools

4.18.0-513.18.1.el8_9

kernel-tools-libs

4.18.0-513.18.1.el8_9

kernel-tools-libs-devel

4.18.0-513.18.1.el8_9

perf

4.18.0-513.18.1.el8_9

python3-perf

4.18.0-513.18.1.el8_9

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2024-12169: kernel security update (IMPORTANT)

CVSS3: 7.1
ubuntu
больше 2 лет назад

A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.

CVSS3: 7.1
redhat
около 3 лет назад

A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.

CVSS3: 7.1
nvd
больше 2 лет назад

A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.

CVSS3: 7.1
msrc
больше 2 лет назад

Описание отсутствует

Уязвимость ELSA-2024-0897