[ELSA-2022-0188] kernel security and bug fix update
[4.18.0-348.12.2_5.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-11.0.5
[4.18.0-348.12.2_5]
- vfs: Out-of-bounds write of heap buffer in fs_context.c (Frantisek Hrbata) [2040585 2040586] {CVE-2022-0185}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Bruno Meneguele) [2034864 2034865] {CVE-2021-4155}
[4.18.0-348.12.1_5]
- tcp: don't free a FIN sk_buff in tcp_remove_empty_skb() (Guillaume Nault) [2021574 2016210]
- kernel.spec: Add support to use vmlinux.h (Jiri Olsa) [2031053 1989087]
- spec: Add vmlinux.h to kernel-devel package (Jiri Olsa) [2031053 1989087]
- x86/mce: Avoid infinite loop for copy from user recovery (Prarit Bhargava) [2008789 1999550]
- x86/mce: Rename kill_it to kill_current_task (Prarit Bhargava) [2008789 1999550]
- x86/mce: Recover from poison found while copying from user space (Prarit Bhargava) [2008789 1999550]
- x86/mce: Delay clearing IA32_MCG_STATUS to the end of do_machine_check() (Prarit Bhargava) [2008789 1999550]
- x86/mce: Send #MC singal from task work (Prarit Bhargava) [2008789 1999550]
[4.18.0-348.11.1_5]
- blk-mq: avoid to iterate over stale request (Ming Lei) [2034396 1997338]
- rcu: Tighten rcu_advance_cbs_nowake() checks (Daniel Vacek) [2032579 2013408]
[4.18.0-348.10.1_5]
- selftests: add a test case for mirred egress to ingress (Xin Long) [2024411 1983894]
- net: sched: act_mirred: drop dst for the direction from egress to ingress (Xin Long) [2024411 1983894]
[4.18.0-348.9.1_5]
- ixgbe: Revert 'bpf, devmap: Move drop error path to devmap for XDP_REDIRECT' (Ken Cox) [2029845 2024240]
- i40e: Revert 'bpf, devmap: Move drop error path to devmap for XDP_REDIRECT' (Stefan Assmann) [2029845 2024225]
- rcu/nocb: Perform deferred wake up before last idle's need_resched() check (Waiman Long) [2029449 2008340]
[4.18.0-348.8.1_5]
- ice: Fix VF true promiscuous mode (Jonathan Toppins) [2026698 1970643]
- ice: Remove toggling of antispoof for VF trusted promiscuous mode (Jonathan Toppins) [2026698 1970643]
- ice: Fix replacing VF hardware MAC to existing MAC filter (Jonathan Toppins) [2026698 1970643]
- ice: Fix not stopping Tx queues for VFs (Jonathan Toppins) [2026698 1970643]
- ice: Fix race conditions between virtchnl handling and VF ndo ops (Jonathan Toppins) [2026698 1970643]
- net/netif_receive_skb_core: Use migrate_disable() (Luis Claudio R. Goncalves) [2027689 2024168]
- crypto: jitter - consider 32 LSB for APT (Herbert Xu) [2029365 1994390]
- xfs: fix I_DONTCACHE (Carlos Maiolino) [2028534 2024969]
- ID
- ELSA-2022-0188
- Severity
- important
- URL
- https://linux.oracle.com/errata/ELSA-2022-0188.html
- Published
-
2022-01-21T00:00:00
(2 years ago) - Modified
-
2022-01-21T00:00:00
(2 years ago) - Rights
- Copyright 2022 Oracle, Inc.
- Other Advisories
-
- ALAS-2022-1563
- ALAS-2023-1688
- ALAS2-2022-1749
- ALSA-2022:0188
- CISA-2024:0821
- DSA-5050-1
- DSA-5096-1
- ELSA-2022-0620
- ELSA-2022-9010
- ELSA-2022-9011
- ELSA-2022-9012
- ELSA-2022-9013
- ELSA-2022-9014
- ELSA-2022-9028
- ELSA-2022-9029
- ELSA-2022-9088
- ELSA-2022-9147
- ELSA-2022-9148
- ELSA-2022-9781
- FEDORA-2022-6352c313b7
- FEDORA-2022-6d4082d590
- MS:CVE-2021-4155
- MS:CVE-2022-0185
- openSUSE-SU-2022:0169-1
- openSUSE-SU-2022:0198-1
- RHSA-2022:0176
- RHSA-2022:0188
- RHSA-2022:0232
- RHSA-2022:0592
- RHSA-2022:0620
- RHSA-2022:0622
- RLSA-2022:176
- SSA:2022-031-01
- SUSE-SU-2022:0169-1
- SUSE-SU-2022:0197-1
- SUSE-SU-2022:0198-1
- SUSE-SU-2022:0238-1
- SUSE-SU-2022:0239-1
- SUSE-SU-2022:0241-1
- SUSE-SU-2022:0254-1
- SUSE-SU-2022:0257-1
- SUSE-SU-2022:0262-1
- SUSE-SU-2022:0270-1
- SUSE-SU-2022:0288-1
- SUSE-SU-2022:0289-1
- SUSE-SU-2022:0291-1
- SUSE-SU-2022:0292-1
- SUSE-SU-2022:0293-1
- SUSE-SU-2022:0295-1
- SUSE-SU-2022:0362-1
- SUSE-SU-2022:0477-1
- SUSE-SU-2022:3264-1
- SUSE-SU-2022:3450-1
- SUSE-SU-2022:3609-1
- SUSE-SU-2022:3809-1
- USN-5240-1
- USN-5278-1
- USN-5294-1
- USN-5294-2
- USN-5295-1
- USN-5295-2
- USN-5297-1
- USN-5298-1
- USN-5362-1
- USN-5884-1
- USN-5926-1
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2022-0188 | https://linux.oracle.com/errata/ELSA-2022-0188.html | |
CVE | CVE-2022-0185 | https://linux.oracle.com/cve/CVE-2022-0185.html | |
CVE | CVE-2021-4155 | https://linux.oracle.com/cve/CVE-2021-4155.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/python3-perf?distro=oraclelinux-8.5 | oraclelinux | python3-perf | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/perf?distro=oraclelinux-8.5 | oraclelinux | perf | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel?distro=oraclelinux-8.5 | oraclelinux | kernel | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools?distro=oraclelinux-8.5 | oraclelinux | kernel-tools | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools-libs?distro=oraclelinux-8.5 | oraclelinux | kernel-tools-libs | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools-libs-devel?distro=oraclelinux-8.5 | oraclelinux | kernel-tools-libs-devel | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-modules?distro=oraclelinux-8.5 | oraclelinux | kernel-modules | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-modules-extra?distro=oraclelinux-8.5 | oraclelinux | kernel-modules-extra | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-headers?distro=oraclelinux-8.5 | oraclelinux | kernel-headers | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-doc?distro=oraclelinux-8.5 | oraclelinux | kernel-doc | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-devel?distro=oraclelinux-8.5 | oraclelinux | kernel-devel | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug?distro=oraclelinux-8.5 | oraclelinux | kernel-debug | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-modules?distro=oraclelinux-8.5 | oraclelinux | kernel-debug-modules | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-modules-extra?distro=oraclelinux-8.5 | oraclelinux | kernel-debug-modules-extra | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-devel?distro=oraclelinux-8.5 | oraclelinux | kernel-debug-devel | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-core?distro=oraclelinux-8.5 | oraclelinux | kernel-debug-core | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-cross-headers?distro=oraclelinux-8.5 | oraclelinux | kernel-cross-headers | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-core?distro=oraclelinux-8.5 | oraclelinux | kernel-core | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/kernel-abi-stablelists?distro=oraclelinux-8.5 | oraclelinux | kernel-abi-stablelists | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 | ||
Affected | pkg:rpm/oraclelinux/bpftool?distro=oraclelinux-8.5 | oraclelinux | bpftool | < 4.18.0-348.12.2.el8_5 | oraclelinux-8.5 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |