Oracle Linux Security Advisory ELSA-2022-0188

https://linux.oracle.com/errata/ELSA-2022-0188.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-abi-stablelists-4.18.0-348.12.2.el8_5.noarch.rpm
kernel-core-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-cross-headers-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-debug-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-debug-core-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-debug-devel-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-debug-modules-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-debug-modules-extra-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-devel-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-doc-4.18.0-348.12.2.el8_5.noarch.rpm
kernel-headers-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-modules-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-modules-extra-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-tools-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-tools-libs-4.18.0-348.12.2.el8_5.x86_64.rpm
perf-4.18.0-348.12.2.el8_5.x86_64.rpm
python3-perf-4.18.0-348.12.2.el8_5.x86_64.rpm
kernel-tools-libs-devel-4.18.0-348.12.2.el8_5.x86_64.rpm

aarch64:
bpftool-4.18.0-348.12.2.el8_5.aarch64.rpm
kernel-cross-headers-4.18.0-348.12.2.el8_5.aarch64.rpm
kernel-headers-4.18.0-348.12.2.el8_5.aarch64.rpm
kernel-tools-4.18.0-348.12.2.el8_5.aarch64.rpm
kernel-tools-libs-4.18.0-348.12.2.el8_5.aarch64.rpm
perf-4.18.0-348.12.2.el8_5.aarch64.rpm
python3-perf-4.18.0-348.12.2.el8_5.aarch64.rpm
kernel-tools-libs-devel-4.18.0-348.12.2.el8_5.aarch64.rpm


SRPMS:
https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-4.18.0-348.12.2.el8_5.src.rpm

Related CVEs:

CVE-2021-4155
CVE-2022-0185




Description of changes:

[4.18.0-348.12.2.el8_5.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-11.0.5.el8

[4.18.0-348.12.2.el8_5]
- vfs: Out-of-bounds write of heap buffer in fs_context.c (Frantisek Hrbata) [2040585 2040586] {CVE-2022-0185}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Bruno Meneguele) [2034864 2034865] {CVE-2021-4155}

[4.18.0-348.12.1.el8_5]
- tcp: don't free a FIN sk_buff in tcp_remove_empty_skb() (Guillaume Nault) [2021574 2016210]
- kernel.spec: Add support to use vmlinux.h (Jiri Olsa) [2031053 1989087]
- spec: Add vmlinux.h to kernel-devel package (Jiri Olsa) [2031053 1989087]
- x86/mce: Avoid infinite loop for copy from user recovery (Prarit Bhargava) [2008789 1999550]
- x86/mce: Rename kill_it to kill_current_task (Prarit Bhargava) [2008789 1999550]
- x86/mce: Recover from poison found while copying from user space (Prarit Bhargava) [2008789 1999550]
- x86/mce: Delay clearing IA32_MCG_STATUS to the end of do_machine_check() (Prarit Bhargava) [2008789 1999550]
- x86/mce: Send #MC singal from task work (Prarit Bhargava) [2008789 1999550]

[4.18.0-348.11.1.el8_5]
- blk-mq: avoid to iterate over stale request (Ming Lei) [2034396 1997338]
- rcu: Tighten rcu_advance_cbs_nowake() checks (Daniel Vacek) [2032579 2013408]

[4.18.0-348.10.1.el8_5]
- selftests: add a test case for mirred egress to ingress (Xin Long) [2024411 1983894]
- net: sched: act_mirred: drop dst for the direction from egress to ingress (Xin Long) [2024411 1983894]

[4.18.0-348.9.1.el8_5]
- ixgbe: Revert "bpf, devmap: Move drop error path to devmap for XDP_REDIRECT" (Ken Cox) [2029845 2024240]
- i40e: Revert "bpf, devmap: Move drop error path to devmap for XDP_REDIRECT" (Stefan Assmann) [2029845 2024225]
- rcu/nocb: Perform deferred wake up before last idle's need_resched() check (Waiman Long) [2029449 2008340]

[4.18.0-348.8.1.el8_5]
- ice: Fix VF true promiscuous mode (Jonathan Toppins) [2026698 1970643]
- ice: Remove toggling of antispoof for VF trusted promiscuous mode (Jonathan Toppins) [2026698 1970643]
- ice: Fix replacing VF hardware MAC to existing MAC filter (Jonathan Toppins) [2026698 1970643]
- ice: Fix not stopping Tx queues for VFs (Jonathan Toppins) [2026698 1970643]
- ice: Fix race conditions between virtchnl handling and VF ndo ops (Jonathan Toppins) [2026698 1970643]
- net/netif_receive_skb_core: Use migrate_disable() (Luis Claudio R. Goncalves) [2027689 2024168]
- crypto: jitter - consider 32 LSB for APT (Herbert Xu) [2029365 1994390]
- xfs: fix I_DONTCACHE (Carlos Maiolino) [2028534 2024969]


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2022-0188: kernel Important Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[4.18.0-348.12.2.el8_5.OL8] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 <= 15-11.0.5.el8 [4.18.0-348.12.2.el8_5] - vfs: Out-of-bounds write of heap buffer in fs_context.c (Frantisek Hrbata) [2040585 2040586] {CVE-2022-0185} - xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Bruno Meneguele) [2034864 2034865] {CVE-2021-4155} [4.18.0-348.12.1.el8_5] - tcp: don't free a FIN sk_buff in tcp_remove_empty_skb() (Guillaume Nault) [2021574 2016210] - kernel.spec: Add support to use vmlinux.h (Jiri Olsa) [2031053 1989087] - spec: Add vmlinux.h to kernel-devel package (Jiri Olsa) [2031053 1989087] - x86/mce: Avoid infinite loop for copy from user recovery (Prarit Bhargava) [2008789 1999550] - x86/mce: Rename kill_it to kill_current_task (Prarit Bhargava) [2008789 1999550] - x86/mce: Recover from poison found while copying from user space (Prarit Bhargava) [2008789 1999550] - x86/mce: Delay clearing IA32_MCG_STATUS to the end of do_machine_check() (Prarit Bhargava) [2008789 1999550] - x86/mce: Send #MC singal from task work (Prarit Bhargava) [2008789 1999550] [4.18.0-348.11.1.el8_5] - blk-mq: avoid to iterate over stale request (Ming Lei) [2034396 1997338] - rcu: Tighten rcu_advance_cbs_nowake() checks (Daniel Vacek) [2032579 2013408] [4.18.0-348.10.1.el8_5] - selftests: add a test case for mirred egress to ingress (Xin Long) [2024411 1983894] - net: sched: act_mirred: drop dst for the direction from egress to ingress (Xin Long) [2024411 1983894] [4.18.0-348.9.1.el8_5] - ixgbe: Revert "bpf, devmap: Move drop error path to devmap for XDP_REDIRECT" (Ken Cox) [2029845 2024240] - i40e: Revert "bpf, devmap: Move drop error path to devmap for XDP_REDIRECT" (Stefan Assmann) [2029845 2024225] - rcu/nocb: Perform deferred wake up before last idle's need_resched() check (Waiman Long) [2029449 2008340] [4.18.0-348.8.1.el8_5] - ice: Fix VF true promiscuous mode (Jonathan Toppins) [2026698 1970643] - ice: Remove toggling of antispoof for VF trusted promiscuous mode (Jonathan Toppins) [2026698 1970643] - ice: Fix replacing VF hardware MAC to existing MAC filter (Jonathan Toppins) [2026698 1970643] - ice: Fix not stopping Tx queues for VFs (Jonathan Toppins) [2026698 1970643] - ice: Fix race conditions between virtchnl handling and VF ndo ops (Jonathan Toppins) [2026698 1970643] - net/netif_receive_skb_core: Use migrate_disable() (Luis Claudio R. Goncalves) [2027689 2024168] - crypto: jitter - consider 32 LSB for APT (Herbert Xu) [2029365 1994390] - xfs: fix I_DONTCACHE (Carlos Maiolino) [2028534 2024969]

SRPMs

https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-4.18.0-348.12.2.el8_5.src.rpm

x86_64

bpftool-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-abi-stablelists-4.18.0-348.12.2.el8_5.noarch.rpm kernel-core-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-cross-headers-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-debug-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-debug-core-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-debug-devel-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-debug-modules-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-debug-modules-extra-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-devel-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-doc-4.18.0-348.12.2.el8_5.noarch.rpm kernel-headers-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-modules-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-modules-extra-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-tools-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-tools-libs-4.18.0-348.12.2.el8_5.x86_64.rpm perf-4.18.0-348.12.2.el8_5.x86_64.rpm python3-perf-4.18.0-348.12.2.el8_5.x86_64.rpm kernel-tools-libs-devel-4.18.0-348.12.2.el8_5.x86_64.rpm

aarch64

bpftool-4.18.0-348.12.2.el8_5.aarch64.rpm kernel-cross-headers-4.18.0-348.12.2.el8_5.aarch64.rpm kernel-headers-4.18.0-348.12.2.el8_5.aarch64.rpm kernel-tools-4.18.0-348.12.2.el8_5.aarch64.rpm kernel-tools-libs-4.18.0-348.12.2.el8_5.aarch64.rpm perf-4.18.0-348.12.2.el8_5.aarch64.rpm python3-perf-4.18.0-348.12.2.el8_5.aarch64.rpm kernel-tools-libs-devel-4.18.0-348.12.2.el8_5.aarch64.rpm

i386

Severity
Related CVEs: CVE-2021-4155 CVE-2022-0185

Related News