[ELSA-2021-3057] kernel security, bug fix, and enhancement update
[4.18.0-305.12.1_4.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-11.0.5
[4.18.0-305.12.1_4]
- Revert 'nvme-pci: remove last_sq_tail' (Gopal Tiwari) [1965415 1921591]
- tc-testing: add test for ct DNAT tuple collision (Marcelo Ricardo Leitner) [1982494 1964578]
- tc-testing: add support for sending various scapy packets (Marcelo Ricardo Leitner) [1982494 1964578]
- tc-testing: fix list handling (Marcelo Ricardo Leitner) [1982494 1964578]
- net/sched: act_ct: handle DNAT tuple collision (Marcelo Ricardo Leitner) [1982494 1964578]
- mm/memcg: Relocate tcpmem to below memory in struct mem_cgroup (Waiman Long) [1980314 1959772]
- mm/memcg: optimize user context object stock access (Waiman Long) [1980314 1959772]
- mm/memcg: improve refill_obj_stock() performance (Waiman Long) [1980314 1959772]
- mm/memcg: cache vmstat data in percpu memcg_stock_pcp (Waiman Long) [1980314 1959772]
- mm/memcg: move mod_objcg_state() to memcontrol.c (Waiman Long) [1980314 1959772]
- mm: memcontrol: use obj_cgroup APIs to charge kmem pages (Waiman Long) [1980314 1959772]
- mm: memcontrol: change ug->dummy_page only if memcg changed (Waiman Long) [1980314 1959772]
- mm: memcontrol: directly access page->memcg_data in mm/page_alloc.c (Waiman Long) [1980314 1959772]
- mm: memcontrol: introduce obj_cgroup_{un}charge_pages (Waiman Long) [1980314 1959772]
- mm: memcontrol: slab: fix obtain a reference to a freeing memcg (Waiman Long) [1980314 1959772]
- mm: move lruvec stats update functions to vmstat.h (Waiman Long) [1980314 1959772]
- mm: memcg/slab: rename *_lruvec_slab_state to *_lruvec_kmem_state (Waiman Long) [1980314 1959772]
- mm: Convert page kmemcg type to a page memcg flag (Waiman Long) [1980314 1959772]
- mm: Introduce page memcg flags (Waiman Long) [1980314 1959772]
- mm: memcontrol/slab: Use helpers to access slab page's memcg_data (Waiman Long) [1980314 1959772]
- mm: memcontrol: Use helpers to read page's memcg data (Waiman Long) [1980314 1959772]
- mm/page_alloc.c: extract check_[new|free]_page_bad() common part to page_bad_reason() (Waiman Long) [1980314 1959772]
- mm/page_alloc.c: rename free_pages_check() to check_free_page() (Waiman Long) [1980314 1959772]
- mm/page_alloc.c: rename free_pages_check_bad() to check_free_page_bad() (Waiman Long) [1980314 1959772]
- mm/page_alloc.c: bad_flags is not necessary for bad_page() (Waiman Long) [1980314 1959772]
- mm/page_alloc.c: bad_[reason|flags] is not necessary when PageHWPoison (Waiman Long) [1980314 1959772]
[4.18.0-305.11.1_4]
- SUNRPC: Handle major timeout in xprt_adjust_timeout() (Scott Mayhew) [1980613 1979070]
- net/mlx5e: Disable TLS device offload in kdump mode (Alaa Hleihel) [1969909 1946647]
- net/mlx5e: Disable TX MPWQE in kdump mode (Alaa Hleihel) [1969909 1946647]
- drm/i915: Add an encoder hook to sanitize its state during init/resume (Imre Deak) [1981250 1961122]
- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980500 1980501] {CVE-2021-22555}
- Bluetooth: btusb: Fix the autosuspend enable and disable (Gopal Tiwari) [1972564 1927375]
- cifs: handle empty list of targets in cifs_reconnect() (Ronnie Sahlberg) [1973637 1952263]
- tick/nohz: Update idle_exittime on actual idle exit (Phil Auld) [1978710 1962632]
- tick/nohz: Remove superflous check for CONFIG_VIRT_CPU_ACCOUNTING_NATIVE (Phil Auld) [1978710 1962632]
- tick/nohz: Conditionally restart tick on idle exit (Phil Auld) [1978710 1962632]
- can: bcm: delay release of struct bcm_op after synchronize_rcu() (Hangbin Liu) [1975058 1975059]
- redhat/configs: Re-enable dptf_power module (Prarit Bhargava) [1968381 1962349]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975514 1975515] {CVE-2021-22543}
- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975181 1975182] {CVE-2021-33909}
- ID
- ELSA-2021-3057
- Severity
- important
- URL
- https://linux.oracle.com/errata/ELSA-2021-3057.html
- Published
-
2021-08-11T00:00:00
(3 years ago) - Modified
-
2021-08-11T00:00:00
(3 years ago) - Rights
- Copyright 2021 Oracle, Inc.
- Other Advisories
-
- ALAS-2021-1539
- ALAS2-2021-1627
- ALAS2-2021-1699
- ALSA-2021:3057
- ASA-202107-48
- ASA-202107-49
- ASA-202107-50
- ASA-202107-51
- DSA-4941-1
- ELSA-2021-3327
- ELSA-2021-3801
- ELSA-2021-9395
- ELSA-2021-9442
- ELSA-2021-9450
- ELSA-2021-9451
- ELSA-2021-9452
- ELSA-2021-9453
- FEDORA-2021-95f2f1cfc7
- FEDORA-2021-fe826f202e
- MS:CVE-2021-3609
- openSUSE-SU-2021:1076-1
- openSUSE-SU-2021:1142-1
- openSUSE-SU-2021:2409-1
- openSUSE-SU-2021:2415-1
- openSUSE-SU-2021:2427-1
- openSUSE-SU-2021:2645-1
- openSUSE-SU-2021:2687-1
- openSUSE-SU-2021:3876-1
- RHSA-2021:3044
- RHSA-2021:3057
- RHSA-2021:3088
- RHSA-2021:3327
- RHSA-2021:3328
- RHSA-2021:3381
- RHSA-2021:3768
- RHSA-2021:3801
- RHSA-2021:3802
- RLSA-2021:3057
- SSA:2021-202-01
- SUSE-SU-2021:2406-1
- SUSE-SU-2021:2407-1
- SUSE-SU-2021:2408-1
- SUSE-SU-2021:2409-1
- SUSE-SU-2021:2415-1
- SUSE-SU-2021:2416-1
- SUSE-SU-2021:2421-1
- SUSE-SU-2021:2422-1
- SUSE-SU-2021:2427-1
- SUSE-SU-2021:2438-1
- SUSE-SU-2021:2451-1
- SUSE-SU-2021:2487-1
- SUSE-SU-2021:2538-1
- SUSE-SU-2021:2542-1
- SUSE-SU-2021:2559-1
- SUSE-SU-2021:2560-1
- SUSE-SU-2021:2577-1
- SUSE-SU-2021:2584-1
- SUSE-SU-2021:2599-1
- SUSE-SU-2021:2599-2
- SUSE-SU-2021:2643-1
- SUSE-SU-2021:2644-1
- SUSE-SU-2021:2645-1
- SUSE-SU-2021:2646-1
- SUSE-SU-2021:2647-1
- SUSE-SU-2021:2678-1
- SUSE-SU-2021:2687-1
- SUSE-SU-2021:2695-1
- SUSE-SU-2021:2746-1
- SUSE-SU-2021:2756-1
- SUSE-SU-2021:2842-1
- SUSE-SU-2021:3876-1
- SUSE-SU-2021:3969-1
- SUSE-SU-2021:3972-1
- USN-4997-1
- USN-4997-2
- USN-4999-1
- USN-5000-1
- USN-5000-2
- USN-5001-1
- USN-5002-1
- USN-5003-1
- USN-5039-1
- USN-5070-1
- USN-5071-1
- USN-5071-2
- USN-5071-3
- USN-5082-1
- USN-5094-1
- USN-5094-2
- USN-5106-1
- USN-5120-1
- USN-5505-1
- USN-5513-1
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2021-3057 | https://linux.oracle.com/errata/ELSA-2021-3057.html | |
CVE | CVE-2021-22555 | https://linux.oracle.com/cve/CVE-2021-22555.html | |
CVE | CVE-2021-3609 | https://linux.oracle.com/cve/CVE-2021-3609.html | |
CVE | CVE-2021-22543 | https://linux.oracle.com/cve/CVE-2021-22543.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/python3-perf?distro=oraclelinux-8.4 | oraclelinux | python3-perf | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/perf?distro=oraclelinux-8.4 | oraclelinux | perf | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel?distro=oraclelinux-8.4 | oraclelinux | kernel | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools?distro=oraclelinux-8.4 | oraclelinux | kernel-tools | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools-libs?distro=oraclelinux-8.4 | oraclelinux | kernel-tools-libs | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools-libs-devel?distro=oraclelinux-8.4 | oraclelinux | kernel-tools-libs-devel | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-modules?distro=oraclelinux-8.4 | oraclelinux | kernel-modules | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-modules-extra?distro=oraclelinux-8.4 | oraclelinux | kernel-modules-extra | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-headers?distro=oraclelinux-8.4 | oraclelinux | kernel-headers | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-doc?distro=oraclelinux-8.4 | oraclelinux | kernel-doc | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-devel?distro=oraclelinux-8.4 | oraclelinux | kernel-devel | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug?distro=oraclelinux-8.4 | oraclelinux | kernel-debug | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-modules?distro=oraclelinux-8.4 | oraclelinux | kernel-debug-modules | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-modules-extra?distro=oraclelinux-8.4 | oraclelinux | kernel-debug-modules-extra | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-devel?distro=oraclelinux-8.4 | oraclelinux | kernel-debug-devel | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-core?distro=oraclelinux-8.4 | oraclelinux | kernel-debug-core | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-cross-headers?distro=oraclelinux-8.4 | oraclelinux | kernel-cross-headers | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-core?distro=oraclelinux-8.4 | oraclelinux | kernel-core | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/kernel-abi-stablelists?distro=oraclelinux-8.4 | oraclelinux | kernel-abi-stablelists | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 | ||
Affected | pkg:rpm/oraclelinux/bpftool?distro=oraclelinux-8.4 | oraclelinux | bpftool | < 4.18.0-305.12.1.el8_4 | oraclelinux-8.4 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |