[ELSA-2024-3619] kernel security and bug fix update

Severity Moderate
Affected Packages 27
CVEs 2
  • [5.14.0-427.20.1_4.OL9]
  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates

[5.14.0-427.20.1_4]
- ipv6: sr: fix possible use-after-free and null-ptr-deref (Hangbin Liu) [RHEL-33968 RHEL-31732] {CVE-2024-26735}
- idpf: fix kernel panic on unknown packet types (Michal Schmidt) [RHEL-36145 RHEL-29035]
- idpf: refactor some missing field get/prep conversions (Michal Schmidt) [RHEL-36145 RHEL-29035]
- PCI: Fix pci_rh_check_status() call semantics (Luiz Capitulino) [RHEL-36541 RHEL-35032]
- cxgb4: Properly lock TX queue for the selftest. (John B. Wyatt IV) [RHEL-36530 RHEL-31990 RHEL-9354]

[5.14.0-427.19.1_4]
- x86/mce: Cleanup mce_usable_address() (Prarit Bhargava) [RHEL-33810 RHEL-25415]
- x86/mce: Define amd_mce_usable_address() (Prarit Bhargava) [RHEL-33810 RHEL-25415]
- x86/MCE/AMD: Split amd_mce_is_memory_error() (Prarit Bhargava) [RHEL-33810 RHEL-25415]
- fs: sysfs: Fix reference leak in sysfs_break_active_protection() (Ewan D. Milne) [RHEL-35302 RHEL-35078] {CVE-2024-26993}

Package Affected Version
pkg:rpm/oraclelinux/rv?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/rtla?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/python3-perf?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/perf?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/libperf?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-tools?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-tools-libs?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-tools-libs-devel?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-modules?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-modules-extra?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-modules-core?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-headers?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-doc?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-devel?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-devel-matched?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug-modules?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug-modules-extra?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug-modules-core?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug-devel?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug-devel-matched?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-debug-core?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-cross-headers?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-core?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/kernel-abi-stablelists?distro=oraclelinux-9.4 < 5.14.0-427.20.1.el9_4
pkg:rpm/oraclelinux/bpftool?distro=oraclelinux-9.4 < 7.3.0-427.20.1.el9_4
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/rv?distro=oraclelinux-9.4 oraclelinux rv < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/rtla?distro=oraclelinux-9.4 oraclelinux rtla < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/python3-perf?distro=oraclelinux-9.4 oraclelinux python3-perf < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/perf?distro=oraclelinux-9.4 oraclelinux perf < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/libperf?distro=oraclelinux-9.4 oraclelinux libperf < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel?distro=oraclelinux-9.4 oraclelinux kernel < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-tools?distro=oraclelinux-9.4 oraclelinux kernel-tools < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-tools-libs?distro=oraclelinux-9.4 oraclelinux kernel-tools-libs < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-tools-libs-devel?distro=oraclelinux-9.4 oraclelinux kernel-tools-libs-devel < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-modules?distro=oraclelinux-9.4 oraclelinux kernel-modules < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-modules-extra?distro=oraclelinux-9.4 oraclelinux kernel-modules-extra < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-modules-core?distro=oraclelinux-9.4 oraclelinux kernel-modules-core < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-headers?distro=oraclelinux-9.4 oraclelinux kernel-headers < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-doc?distro=oraclelinux-9.4 oraclelinux kernel-doc < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-devel?distro=oraclelinux-9.4 oraclelinux kernel-devel < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-devel-matched?distro=oraclelinux-9.4 oraclelinux kernel-devel-matched < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug?distro=oraclelinux-9.4 oraclelinux kernel-debug < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug-modules?distro=oraclelinux-9.4 oraclelinux kernel-debug-modules < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug-modules-extra?distro=oraclelinux-9.4 oraclelinux kernel-debug-modules-extra < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug-modules-core?distro=oraclelinux-9.4 oraclelinux kernel-debug-modules-core < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug-devel?distro=oraclelinux-9.4 oraclelinux kernel-debug-devel < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug-devel-matched?distro=oraclelinux-9.4 oraclelinux kernel-debug-devel-matched < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-debug-core?distro=oraclelinux-9.4 oraclelinux kernel-debug-core < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-cross-headers?distro=oraclelinux-9.4 oraclelinux kernel-cross-headers < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-core?distro=oraclelinux-9.4 oraclelinux kernel-core < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/kernel-abi-stablelists?distro=oraclelinux-9.4 oraclelinux kernel-abi-stablelists < 5.14.0-427.20.1.el9_4 oraclelinux-9.4
Affected pkg:rpm/oraclelinux/bpftool?distro=oraclelinux-9.4 oraclelinux bpftool < 7.3.0-427.20.1.el9_4 oraclelinux-9.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...