[ELSA-2022-5249] kernel security and bug fix update
[5.14.0-70.17.1.0.1_0.OL9]
- lockdown: also lock down previous kgdb use (Daniel Thompson) [Orabug: 34290418] {CVE-2022-21499}
[5.14.0-70.17.1_0.OL9]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 < 15.3-1.0.4
- Remove nmap references from kernel (Mridula Shastry) [Orabug: 34313944]
[5.14.0-70.17.1_0]
- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2092994 2092995] {CVE-2022-1966}
- thunderx nic: mark device as unmaintained (Inigo Huguet) [2092638 2060285]
- pseries/eeh: Fix the kdump kernel crash during eeh_pseries_init (Steve Best) [2092255 2067770]
- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087963 2087964] {CVE-2022-1729}
- spec: Fix separate tools build (Jiri Olsa) [2090852 2054579]
- mm: lru_cache_disable: replace work queue synchronization with synchronize_rcu (Marcelo Tosatti) [2086963 2033500]
[5.14.0-70.16.1_0]
- dm integrity: fix memory corruption when tag_size is less than digest size (Benjamin Marzinski) [2082187 2081778]
[5.14.0-70.15.1_0]
- CI: Use zstream builder image (Veronika Kabatova)
- tcp: drop the hash_32() part from the index calculation (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: increase source port perturb table to 216 (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: dynamically allocate the perturb table used by source ports (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: add small random increments to the source port (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: resalt the secret every 10 seconds (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- tcp: use different parts of the port_offset for index and offset (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- secure_seq: use the 64 bits of the siphash for port offset calculation (Guillaume Nault) [2087128 2064868] {CVE-2022-1012}
- Revert 'netfilter: conntrack: tag conntracks picked up in local out hook' (Florian Westphal) [2085480 2061850]
- Revert 'netfilter: nat: force port remap to prevent shadowing well-known ports' (Florian Westphal) [2085480 2061850]
- redhat/koji/Makefile: Decouple koji Makefile from Makefile.common (Andrea Claudi)
- redhat: fix make {distg-brew,distg-koji} (Andrea Claudi)
- esp: limit skb_page_frag_refill use to a single page (Sabrina Dubroca) [2082950 2082951] {CVE-2022-27666}
- esp: Fix possible buffer overflow in ESP transformation (Sabrina Dubroca) [2082950 2082951] {CVE-2022-27666}
- sctp: use the correct skb for security_sctp_assoc_request (Ondrej Mosnacek) [2084044 2078856]
- security: implement sctp_assoc_established hook in selinux (Ondrej Mosnacek) [2084044 2078856]
- security: add sctp_assoc_established hook (Ondrej Mosnacek) [2084044 2078856]
- security: call security_sctp_assoc_request in sctp_sf_do_5_1D_ce (Ondrej Mosnacek) [2084044 2078856]
- security: pass asoc to sctp_assoc_request and sctp_sk_clone (Ondrej Mosnacek) [2084044 2078856]
[5.14.0-70.14.1_0]
- PCI: hv: Propagate coherence from VMbus device to PCI device (Vitaly Kuznetsov) [2074830 2068432]
- Drivers: hv: vmbus: Propagate VMbus coherence to each VMbus device (Vitaly Kuznetsov) [2074830 2068432]
- redhat: rpminspect: disable 'patches' check for known empty patch files (Herton R. Krzesinski)
- redhat/configs: make SHA512_arch algos and CRYPTO_USER built-ins (Vladis Dronov) [2072643 2070624]
- CI: Drop baseline runs (Veronika Kabatova)
- ID
- ELSA-2022-5249
- Severity
- important
- URL
- https://linux.oracle.com/errata/ELSA-2022-5249.html
- Published
-
2022-06-30T00:00:00
(2 years ago) - Modified
-
2022-06-30T00:00:00
(2 years ago) - Rights
- Copyright 2022 Oracle, Inc.
- Other Advisories
-
- ALAS-2022-1581
- ALAS-2022-1591
- ALAS-2022-1604
- ALAS2-2022-1774
- ALAS2-2022-1798
- ALAS2-2022-1813
- ALSA-2022:5249
- ALSA-2022:5316
- ALSA-2022:5564
- ALSA-2022:5819
- DSA-5127-1
- DSA-5161-1
- DSA-5173-1
- ELSA-2022-5232
- ELSA-2022-5316
- ELSA-2022-5564
- ELSA-2022-5819
- ELSA-2022-9365
- ELSA-2022-9366
- ELSA-2022-9367
- ELSA-2022-9368
- ELSA-2022-9409
- ELSA-2022-9410
- ELSA-2022-9412
- ELSA-2022-9413
- FEDORA-2022-014c3a24d9
- FEDORA-2022-8095b23575
- FEDORA-2022-80cc9873be
- FEDORA-2022-8269eaf361
- FEDORA-2022-b2cde267d9
- MS:CVE-2022-1012
- MS:CVE-2022-27666
- openSUSE-SU-2022:2173-1
- openSUSE-SU-2022:2177-1
- openSUSE-SU-2022:2549-1
- RHSA-2022:5214
- RHSA-2022:5216
- RHSA-2022:5219
- RHSA-2022:5232
- RHSA-2022:5236
- RHSA-2022:5249
- RHSA-2022:5267
- RHSA-2022:5316
- RHSA-2022:5344
- RHSA-2022:5564
- RHSA-2022:5565
- RHSA-2022:5819
- RHSA-2022:5834
- RLSA-2022:5316
- RLSA-2022:5564
- RLSA-2022:5819
- SSA:2022-129-01
- SSA:2022-237-02
- SUSE-SU-2022:1163-1
- SUSE-SU-2022:1172-1
- SUSE-SU-2022:1182-1
- SUSE-SU-2022:1183-1
- SUSE-SU-2022:1189-1
- SUSE-SU-2022:1192-1
- SUSE-SU-2022:1193-1
- SUSE-SU-2022:1194-1
- SUSE-SU-2022:1196-1
- SUSE-SU-2022:1197-1
- SUSE-SU-2022:1212-1
- SUSE-SU-2022:1215-1
- SUSE-SU-2022:1223-1
- SUSE-SU-2022:1224-1
- SUSE-SU-2022:1230-1
- SUSE-SU-2022:1242-1
- SUSE-SU-2022:1246-1
- SUSE-SU-2022:1248-1
- SUSE-SU-2022:1257-1
- SUSE-SU-2022:1261-1
- SUSE-SU-2022:1266-1
- SUSE-SU-2022:1267-1
- SUSE-SU-2022:1268-1
- SUSE-SU-2022:1269-1
- SUSE-SU-2022:1278-1
- SUSE-SU-2022:1303-1
- SUSE-SU-2022:1402-1
- SUSE-SU-2022:1407-1
- SUSE-SU-2022:2077-1
- SUSE-SU-2022:2078-1
- SUSE-SU-2022:2079-1
- SUSE-SU-2022:2080-1
- SUSE-SU-2022:2082-1
- SUSE-SU-2022:2103-1
- SUSE-SU-2022:2104-1
- SUSE-SU-2022:2111-1
- SUSE-SU-2022:2116-1
- SUSE-SU-2022:2172-1
- SUSE-SU-2022:2173-1
- SUSE-SU-2022:2177-1
- SUSE-SU-2022:2214-1
- SUSE-SU-2022:2216-1
- SUSE-SU-2022:2230-1
- SUSE-SU-2022:2239-1
- SUSE-SU-2022:2245-1
- SUSE-SU-2022:2262-1
- SUSE-SU-2022:2268-1
- SUSE-SU-2022:2377-1
- SUSE-SU-2022:2382-1
- SUSE-SU-2022:2393-1
- SUSE-SU-2022:2424-1
- SUSE-SU-2022:2424-2
- SUSE-SU-2022:2438-1
- SUSE-SU-2022:2444-1
- SUSE-SU-2022:2445-1
- SUSE-SU-2022:2446-1
- SUSE-SU-2022:2461-1
- SUSE-SU-2022:2482-1
- SUSE-SU-2022:2520-1
- SUSE-SU-2022:2549-1
- SUSE-SU-2022:2615-1
- SUSE-SU-2022:2629-1
- SUSE-SU-2022:3408-1
- SUSE-SU-2022:3450-1
- USN-5353-1
- USN-5357-1
- USN-5357-2
- USN-5358-1
- USN-5358-2
- USN-5368-1
- USN-5377-1
- USN-5465-1
- USN-5466-1
- USN-5467-1
- USN-5468-1
- USN-5469-1
- USN-5470-1
- USN-5471-1
- USN-5560-1
- USN-5560-2
- USN-5594-1
- USN-5599-1
- USN-5602-1
- USN-5616-1
- USN-5622-1
- USN-5623-1
- USN-5630-1
- USN-5639-1
- USN-5647-1
- USN-5650-1
- USN-5654-1
- USN-5660-1
- USN-5669-1
- USN-5669-2
- USN-5678-1
- USN-5679-1
- USN-5684-1
- USN-5687-1
- USN-5695-1
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2022-5249 | https://linux.oracle.com/errata/ELSA-2022-5249.html | |
CVE | CVE-2022-27666 | https://linux.oracle.com/cve/CVE-2022-27666.html | |
CVE | CVE-2022-1729 | https://linux.oracle.com/cve/CVE-2022-1729.html | |
CVE | CVE-2022-1966 | https://linux.oracle.com/cve/CVE-2022-1966.html | |
CVE | CVE-2022-1012 | https://linux.oracle.com/cve/CVE-2022-1012.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/python3-perf?distro=oraclelinux-9.0 | oraclelinux | python3-perf | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/perf?distro=oraclelinux-9.0 | oraclelinux | perf | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel?distro=oraclelinux-9.0 | oraclelinux | kernel | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools?distro=oraclelinux-9.0 | oraclelinux | kernel-tools | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools-libs?distro=oraclelinux-9.0 | oraclelinux | kernel-tools-libs | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-tools-libs-devel?distro=oraclelinux-9.0 | oraclelinux | kernel-tools-libs-devel | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-modules?distro=oraclelinux-9.0 | oraclelinux | kernel-modules | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-modules-extra?distro=oraclelinux-9.0 | oraclelinux | kernel-modules-extra | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-headers?distro=oraclelinux-9.0 | oraclelinux | kernel-headers | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-doc?distro=oraclelinux-9.0 | oraclelinux | kernel-doc | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-devel?distro=oraclelinux-9.0 | oraclelinux | kernel-devel | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-devel-matched?distro=oraclelinux-9.0 | oraclelinux | kernel-devel-matched | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug?distro=oraclelinux-9.0 | oraclelinux | kernel-debug | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-modules?distro=oraclelinux-9.0 | oraclelinux | kernel-debug-modules | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-modules-extra?distro=oraclelinux-9.0 | oraclelinux | kernel-debug-modules-extra | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-devel?distro=oraclelinux-9.0 | oraclelinux | kernel-debug-devel | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-devel-matched?distro=oraclelinux-9.0 | oraclelinux | kernel-debug-devel-matched | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-debug-core?distro=oraclelinux-9.0 | oraclelinux | kernel-debug-core | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-cross-headers?distro=oraclelinux-9.0 | oraclelinux | kernel-cross-headers | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-core?distro=oraclelinux-9.0 | oraclelinux | kernel-core | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/kernel-abi-stablelists?distro=oraclelinux-9.0 | oraclelinux | kernel-abi-stablelists | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 | ||
Affected | pkg:rpm/oraclelinux/bpftool?distro=oraclelinux-9.0 | oraclelinux | bpftool | < 5.14.0-70.17.1.0.1.el9_0 | oraclelinux-9.0 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |