Oracle Linux Security Advisory ELSA-2024-6567

http://linux.oracle.com/errata/ELSA-2024-6567.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-7.3.0-427.35.1.el9_4.x86_64.rpm
kernel-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-abi-stablelists-5.14.0-427.35.1.el9_4.noarch.rpm
kernel-core-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-core-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-devel-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-devel-matched-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-modules-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-debug-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-devel-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-devel-matched-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-doc-5.14.0-427.35.1.el9_4.noarch.rpm
kernel-headers-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-modules-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-tools-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-tools-libs-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm
perf-5.14.0-427.35.1.el9_4.x86_64.rpm
python3-perf-5.14.0-427.35.1.el9_4.x86_64.rpm
rtla-5.14.0-427.35.1.el9_4.x86_64.rpm
rv-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-cross-headers-5.14.0-427.35.1.el9_4.x86_64.rpm
kernel-tools-libs-devel-5.14.0-427.35.1.el9_4.x86_64.rpm
libperf-5.14.0-427.35.1.el9_4.x86_64.rpm

aarch64:
bpftool-7.3.0-427.35.1.el9_4.aarch64.rpm
kernel-headers-5.14.0-427.35.1.el9_4.aarch64.rpm
kernel-tools-5.14.0-427.35.1.el9_4.aarch64.rpm
kernel-tools-libs-5.14.0-427.35.1.el9_4.aarch64.rpm
perf-5.14.0-427.35.1.el9_4.aarch64.rpm
python3-perf-5.14.0-427.35.1.el9_4.aarch64.rpm
kernel-cross-headers-5.14.0-427.35.1.el9_4.aarch64.rpm
kernel-tools-libs-devel-5.14.0-427.35.1.el9_4.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//kernel-5.14.0-427.35.1.el9_4.src.rpm

Related CVEs:

CVE-2023-52463
CVE-2023-52801
CVE-2024-26629
CVE-2024-26630
CVE-2024-26720
CVE-2024-26886
CVE-2024-26946
CVE-2024-35791
CVE-2024-35797
CVE-2024-35875
CVE-2024-36000
CVE-2024-36019
CVE-2024-36883
CVE-2024-36979
CVE-2024-38559
CVE-2024-38619
CVE-2024-40927
CVE-2024-40936
CVE-2024-41040
CVE-2024-41044
CVE-2024-41055
CVE-2024-41073
CVE-2024-41096
CVE-2024-42082
CVE-2024-42096
CVE-2024-42102
CVE-2024-42131




Description of changes:

[5.14.0-427.35.1.el9_4.OL9]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates

[5.14.0-427.35.1.el9_4]
- usb-storage: alauda: Check whether the media is initialized (CKI Backport Bot) [RHEL-43716] {CVE-2024-38619}
- ceph: force sending a cap update msg back to MDS for revoke op (Xiubo Li) [RHEL-55437]
- ceph: periodically flush the cap releases (Xiubo Li) [RHEL-55437]
- mm: avoid overflows in dirty throttling logic (Jay Shin) [RHEL-51848 RHEL-50004] {CVE-2024-42131}
- Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again" (Jay Shin) [RHEL-51701 RHEL-50004] {CVE-2024-42102}
- mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (Jay Shin) [RHEL-42628 RHEL-5619] {CVE-2024-26720}
- net: fix out-of-bounds access in ops_init (Paolo Abeni) [RHEL-43188 RHEL-46610] {CVE-2024-36883}
- nvme: avoid double free special payload (CKI Backport Bot) [RHEL-51311] {CVE-2024-41073}
- kernfs: change kernfs_rename_lock into a read-write lock (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: Separate kernfs_pr_cont_buf and rename_lock (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: fix missing kernfs_iattr_rwsem locking (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: Use a per-fs rwsem to protect per-fs list of kernfs_super_info (Jay Shin) [RHEL-55253 RHEL-52956]
- kernfs: Introduce separate rwsem to protect inode attributes (Jay Shin) [RHEL-55253 RHEL-52956]
- xhci: Handle TD clearing for multiple streams case (CKI Backport Bot) [RHEL-47894 RHEL-47892] {CVE-2024-40927}
- Bluetooth: af_bluetooth: Fix deadlock (Bastien Nocera) [RHEL-34161] {CVE-2024-26886}
- xdp: Remove WARN() from __xdp_reg_mem_model() (CKI Backport Bot) [RHEL-51586] {CVE-2024-42082}
- nfsd: don't take fi_lock in nfsd_break_deleg_cb() (Benjamin Coddington) [RHEL-42578 RHEL-34875]
- nfsd: fix RELEASE_LOCKOWNER (Benjamin Coddington) [RHEL-42578 RHEL-34875] {CVE-2024-26629}
- net: bridge: mst: fix suspicious rcu usage in br_mst_set_state (CKI Backport Bot) [RHEL-43729 RHEL-43727]
- net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state (CKI Backport Bot) [RHEL-43729 RHEL-43727]
- net: bridge: mst: fix vlan use-after-free (cki-backport-bot) [RHEL-43729] {CVE-2024-36979}
- efivarfs: force RO when remounting if SetVariable is not supported (Pavel Reichl) [RHEL-42343 RHEL-26588] {CVE-2023-52463}
- ACPI: arm64: export acpi_arch_thermal_cpufreq_pctg() (Charles Mirabile) [RHEL-34234 RHEL-1697]
- ACPI: processor: reduce CPUFREQ thermal reduction pctg for Tegra241 (Charles Mirabile) [RHEL-34234 RHEL-1697]
- ACPI: thermal: Add Thermal fast Sampling Period (_TFP) support (Scott Weaver) [RHEL-34234 RHEL-1697]


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle9: ELSA-2024-6567: kernel security Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[5.14.0-427.35.1.el9_4.OL9] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5] - Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535] - Add Oracle Linux IMA certificates [5.14.0-427.35.1.el9_4] - usb-storage: alauda: Check whether the media is initialized (CKI Backport Bot) [RHEL-43716] {CVE-2024-38619} - ceph: force sending a cap update msg back to MDS for revoke op (Xiubo Li) [RHEL-55437] - ceph: periodically flush the cap releases (Xiubo Li) [RHEL-55437] - mm: avoid overflows in dirty throttling logic (Jay Shin) [RHEL-51848 RHEL-50004] {CVE-2024-42131} - Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again" (Jay Shin) [RHEL-51701 RHEL-50004] {CVE-2024-42102} - mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (Jay Shin) [RHEL-42628 RHEL-5619] {CVE-2024-26720} - net: fix out-of-bounds access in ops_init (Paolo Abeni) [RHEL-43188 RHEL-46610] {CVE-2024-36883} - nvme: avoid double free special payload (CKI Backport Bot) [RHEL-51311] {CVE-2024-41073} - kernfs: change kernfs_rename_lock into a read-write lock (Jay Shin) [RHEL-55253 RHEL-52956] - kernfs: Separate kernfs_pr_cont_buf and rename_lock (Jay Shin) [RHEL-55253 RHEL-52956] - kernfs: fix missing kernfs_iattr_rwsem locking (Jay Shin) [RHEL-55253 RHEL-52956] - kernfs: Use a per-fs rwsem to protect per-fs list of kernfs_super_info (Jay Shin) [RHEL-55253 RHEL-52956] - kernfs: Introduce separate rwsem to protect inode attributes (Jay Shin) [RHEL-55253 RHEL-52956] - xhci: Handle TD clearing for multiple streams case (CKI Backport Bot) [RHEL-47894 RHEL-47892] {CVE-2024-40927} - Bluetooth: af_bluetooth: Fix deadlock (Bastien Nocera) [RHEL-34161] {CVE-2024-26886} - xdp: Remove WARN() from __xdp_reg_mem_model() (CKI Backport Bot) [RHEL-51586] {CVE-2024-42082} - nfsd: don't take fi_lock in nfsd_break_deleg_cb() (Benjamin Coddington) [RHEL-42578 RHEL-34875] - nfsd: fix RELEASE_LOCKOWNER (Benjamin Coddington) [RHEL-42578 RHEL-34875] {CVE-2024-26629} - net: bridge: mst: fix suspicious rcu usage in br_mst_set_state (CKI Backport Bot) [RHEL-43729 RHEL-43727] - net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state (CKI Backport Bot) [RHEL-43729 RHEL-43727] - net: bridge: mst: fix vlan use-after-free (cki-backport-bot) [RHEL-43729] {CVE-2024-36979} - efivarfs: force RO when remounting if SetVariable is not supported (Pavel Reichl) [RHEL-42343 RHEL-26588] {CVE-2023-52463} - ACPI: arm64: export acpi_arch_thermal_cpufreq_pctg() (Charles Mirabile) [RHEL-34234 RHEL-1697] - ACPI: processor: reduce CPUFREQ thermal reduction pctg for Tegra241 (Charles Mirabile) [RHEL-34234 RHEL-1697] - ACPI: thermal: Add Thermal fast Sampling Period (_TFP) support (Scott Weaver) [RHEL-34234 RHEL-1697]

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates//kernel-5.14.0-427.35.1.el9_4.src.rpm

x86_64

bpftool-7.3.0-427.35.1.el9_4.x86_64.rpm kernel-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-abi-stablelists-5.14.0-427.35.1.el9_4.noarch.rpm kernel-core-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-core-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-devel-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-devel-matched-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-modules-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-debug-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-devel-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-devel-matched-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-doc-5.14.0-427.35.1.el9_4.noarch.rpm kernel-headers-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-modules-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-modules-core-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-modules-extra-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-tools-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-tools-libs-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-uki-virt-5.14.0-427.35.1.el9_4.x86_64.rpm perf-5.14.0-427.35.1.el9_4.x86_64.rpm python3-perf-5.14.0-427.35.1.el9_4.x86_64.rpm rtla-5.14.0-427.35.1.el9_4.x86_64.rpm rv-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-cross-headers-5.14.0-427.35.1.el9_4.x86_64.rpm kernel-tools-libs-devel-5.14.0-427.35.1.el9_4.x86_64.rpm libperf-5.14.0-427.35.1.el9_4.x86_64.rpm

aarch64

bpftool-7.3.0-427.35.1.el9_4.aarch64.rpm kernel-headers-5.14.0-427.35.1.el9_4.aarch64.rpm kernel-tools-5.14.0-427.35.1.el9_4.aarch64.rpm kernel-tools-libs-5.14.0-427.35.1.el9_4.aarch64.rpm perf-5.14.0-427.35.1.el9_4.aarch64.rpm python3-perf-5.14.0-427.35.1.el9_4.aarch64.rpm kernel-cross-headers-5.14.0-427.35.1.el9_4.aarch64.rpm kernel-tools-libs-devel-5.14.0-427.35.1.el9_4.aarch64.rpm

i386

Severity
Related CVEs: CVE-2023-52463 CVE-2023-52801 CVE-2024-26629 CVE-2024-26630 CVE-2024-26720 CVE-2024-26886 CVE-2024-26946 CVE-2024-35791 CVE-2024-35797 CVE-2024-35875 CVE-2024-36000 CVE-2024-36019 CVE-2024-36883 CVE-2024-36979 CVE-2024-38559 CVE-2024-38619 CVE-2024-40927 CVE-2024-40936 CVE-2024-41040 CVE-2024-41044 CVE-2024-41055 CVE-2024-41073 CVE-2024-41096 CVE-2024-42082 CVE-2024-42096 CVE-2024-42102 CVE-2024-42131

Related News