Oracle Linux Security Advisory ELSA-2021-5227

https://linux.oracle.com/errata/ELSA-2021-5227.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-abi-stablelists-4.18.0-348.7.1.el8_5.noarch.rpm
kernel-core-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-cross-headers-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-debug-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-debug-core-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-debug-devel-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-debug-modules-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-debug-modules-extra-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-devel-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-doc-4.18.0-348.7.1.el8_5.noarch.rpm
kernel-headers-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-modules-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-modules-extra-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-tools-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-tools-libs-4.18.0-348.7.1.el8_5.x86_64.rpm
perf-4.18.0-348.7.1.el8_5.x86_64.rpm
python3-perf-4.18.0-348.7.1.el8_5.x86_64.rpm
kernel-tools-libs-devel-4.18.0-348.7.1.el8_5.x86_64.rpm

aarch64:
bpftool-4.18.0-348.7.1.el8_5.aarch64.rpm
kernel-cross-headers-4.18.0-348.7.1.el8_5.aarch64.rpm
kernel-headers-4.18.0-348.7.1.el8_5.aarch64.rpm
kernel-tools-4.18.0-348.7.1.el8_5.aarch64.rpm
kernel-tools-libs-4.18.0-348.7.1.el8_5.aarch64.rpm
perf-4.18.0-348.7.1.el8_5.aarch64.rpm
python3-perf-4.18.0-348.7.1.el8_5.aarch64.rpm
kernel-tools-libs-devel-4.18.0-348.7.1.el8_5.aarch64.rpm


SRPMS:
https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-4.18.0-348.7.1.el8_5.src.rpm

Related CVEs:

CVE-2021-20321




Description of changes:

[4.18.0-348.7.1.el8_5.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-11.0.5.el8

[4.18.0-348.7.1.el8_5]
- sched: Fix CPU hotplug / tighten is_per_cpu_kthread() (Waiman Long) [2026450 2024869]
- sched: Prepare to use balance_push in ttwu() (Waiman Long) [2026450 2024869]
- sched: Don't run cpu-online with balance_push() enabled (Waiman Long) [2026450 2024869]
- workqueue: Tag bound workers with KTHREAD_IS_PER_CPU (Waiman Long) [2026450 2024869]
- workqueue: Use cpu_possible_mask instead of cpu_active_mask to break affinity (Waiman Long) [2026450 2024869]
- sched: Fix hotplug vs CPU bandwidth control (Waiman Long) [2026450 2024869]
- workqueue: Manually break affinity on hotplug (Waiman Long) [2026450 2024869]
- sched/hotplug: Consolidate task migration on CPU unplug (Waiman Long) [2026450 2024869]
- sched/core: Wait for tasks being pushed away on hotplug (Waiman Long) [2026450 2024869]

[4.18.0-348.6.1.el8_5]
- x86/Kconfig: Do not enable AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT automatically (Prarit Bhargava) [2024678 2021219]

[4.18.0-348.5.1.el8_5]
- blk-mq: still set q->make_request_fn for blk-mq (Ming Lei) [2016384 1999728]

[4.18.0-348.4.1.el8_5]
- [RHEL8.6 BZ 1849234] cifs: report error instead of invalid when revalidating a dentry fails (Ronnie Sahlberg) [2017177 1849234]
- kthread: Fix PF_KTHREAD vs to_kthread() race (Waiman Long) [2010333 2001497]
- sched/fair: Ignore percpu threads for imbalance pulls (Waiman Long) [2010333 2001497]
- kthread: Extract KTHREAD_IS_PER_CPU (Waiman Long) [2010333 2001497]
- sched: Optimize finish_lock_switch() (Waiman Long) [2010333 2001497]
- sched/hotplug: Ensure only per-cpu kthreads run during hotplug (Waiman Long) [2010333 2001497]
- sched: Fix balance_callback() (Waiman Long) [2010333 2001497]

[4.18.0-348.3.1.el8_5]
- net-sysfs: try not to restart the syscall if it will fail eventually (Antoine Tenart) [2021165 2016005]
- ovl: fix missing negative dentry check in ovl_rename() (Miklos Szeredi) [2016378 2010887 2013318] {CVE-2021-20321}


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2021-5227: kernel Moderate Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[4.18.0-348.7.1.el8_5.OL8] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 <= 15-11.0.5.el8 [4.18.0-348.7.1.el8_5] - sched: Fix CPU hotplug / tighten is_per_cpu_kthread() (Waiman Long) [2026450 2024869] - sched: Prepare to use balance_push in ttwu() (Waiman Long) [2026450 2024869] - sched: Don't run cpu-online with balance_push() enabled (Waiman Long) [2026450 2024869] - workqueue: Tag bound workers with KTHREAD_IS_PER_CPU (Waiman Long) [2026450 2024869] - workqueue: Use cpu_possible_mask instead of cpu_active_mask to break affinity (Waiman Long) [2026450 2024869] - sched: Fix hotplug vs CPU bandwidth control (Waiman Long) [2026450 2024869] - workqueue: Manually break affinity on hotplug (Waiman Long) [2026450 2024869] - sched/hotplug: Consolidate task migration on CPU unplug (Waiman Long) [2026450 2024869] - sched/core: Wait for tasks being pushed away on hotplug (Waiman Long) [2026450 2024869] [4.18.0-348.6.1.el8_5] - x86/Kconfig: Do not enable AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT automatically (Prarit Bhargava) [2024678 2021219] [4.18.0-348.5.1.el8_5] - blk-mq: still set q->make_request_fn for blk-mq (Ming Lei) [2016384 1999728] [4.18.0-348.4.1.el8_5] - [RHEL8.6 BZ 1849234] cifs: report error instead of invalid when revalidating a dentry fails (Ronnie Sahlberg) [2017177 1849234] - kthread: Fix PF_KTHREAD vs to_kthread() race (Waiman Long) [2010333 2001497] - sched/fair: Ignore percpu threads for imbalance pulls (Waiman Long) [2010333 2001497] - kthread: Extract KTHREAD_IS_PER_CPU (Waiman Long) [2010333 2001497] - sched: Optimize finish_lock_switch() (Waiman Long) [2010333 2001497] - sched/hotplug: Ensure only per-cpu kthreads run during hotplug (Waiman Long) [2010333 2001497] - sched: Fix balance_callback() (Waiman Long) [2010333 2001497] [4.18.0-348.3.1.el8_5] - net-sysfs: try not to restart the syscall if it will fail eventually (Antoine Tenart) [2021165 2016005] - ovl: fix missing negative dentry check in ovl_rename() (Miklos Szeredi) [2016378 2010887 2013318] {CVE-2021-20321}

SRPMs

https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-4.18.0-348.7.1.el8_5.src.rpm

x86_64

bpftool-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-abi-stablelists-4.18.0-348.7.1.el8_5.noarch.rpm kernel-core-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-cross-headers-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-debug-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-debug-core-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-debug-devel-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-debug-modules-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-debug-modules-extra-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-devel-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-doc-4.18.0-348.7.1.el8_5.noarch.rpm kernel-headers-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-modules-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-modules-extra-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-tools-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-tools-libs-4.18.0-348.7.1.el8_5.x86_64.rpm perf-4.18.0-348.7.1.el8_5.x86_64.rpm python3-perf-4.18.0-348.7.1.el8_5.x86_64.rpm kernel-tools-libs-devel-4.18.0-348.7.1.el8_5.x86_64.rpm

aarch64

bpftool-4.18.0-348.7.1.el8_5.aarch64.rpm kernel-cross-headers-4.18.0-348.7.1.el8_5.aarch64.rpm kernel-headers-4.18.0-348.7.1.el8_5.aarch64.rpm kernel-tools-4.18.0-348.7.1.el8_5.aarch64.rpm kernel-tools-libs-4.18.0-348.7.1.el8_5.aarch64.rpm perf-4.18.0-348.7.1.el8_5.aarch64.rpm python3-perf-4.18.0-348.7.1.el8_5.aarch64.rpm kernel-tools-libs-devel-4.18.0-348.7.1.el8_5.aarch64.rpm

i386

Severity
Related CVEs: CVE-2021-20321

Related News