Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10939 http://linux.oracle.com/errata/ELSA-2024-10939.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.4.0-503.16.1.el9_5.x86_64.rpm kernel-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-abi-stablelists-5.14.0-503.16.1.el9_5.noarch.rpm kernel-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-devel-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-devel-matched-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-modules-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-modules-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-modules-extra-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-uki-virt-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-devel-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-devel-matched-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-doc-5.14.0-503.16.1.el9_5.noarch.rpm kernel-headers-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-modules-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-modules-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-modules-extra-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-tools-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-tools-libs-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-uki-virt-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-uki-virt-addons-5.14.0-503.16.1.el9_5.x86_64.rpm perf-5.14.0-503.16.1.el9_5.x86_64.rpm python3-perf-5.14.0-503.16.1.el9_5.x86_64.rpm rtla-5.14.0-503.16.1.el9_5.x86_64.rpm rv-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-cross-headers-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-tools-libs-devel-5.14.0-503.16.1.el9_5.x86_64.rpm libperf-5.14.0-503.16.1.el9_5.x86_64.rpm aarch64: bpftool-7.4.0-503.16.1.el9_5.aarch64.rpm kernel-headers-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-tools-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-tools-libs-5.14.0-503.16.1.el9_5.aarch64.rpm perf-5.14.0-503.16.1.el9_5.aarch64.rpm python3-perf-5.14.0-503.16.1.el9_5.aarch64.rpm rtla-5.14.0-503.16.1.el9_5.aarch64.rpm rv-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-cross-headers-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-tools-libs-devel-5.14.0-503.16.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//kernel-5.14.0-503.16.1.el9_5.src.rpm Related CVEs: CVE-2024-26615 CVE-2024-43854 CVE-2024-44994 CVE-2024-45018 CVE-2024-46695 CVE-2024-49949 CVE-2024-50251 Description of changes: [5.14.0-503.16.1.el9_5.OL9] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8846 http://linux.oracle.com/errata/ELSA-2024-8846.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: aardvark-dns-1.10.1-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm buildah-1.33.8-4.module+el8.10.0+90429+ee702c5c.x86_64.rpm buildah-tests-1.33.8-4.module+el8.10.0+90429+ee702c5c.x86_64.rpm cockpit-podman-84.1-1.module+el8.10.0+90429+ee702c5c.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm containers-common-1-82.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm container-selinux-2.229.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm crit-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm criu-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm criu-devel-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm criu-libs-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm crun-1.14.3-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm libslirp-4.4.0-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm netavark-1.10.3-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-catatonit-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-docker-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.noarch.rpm podman-gvproxy-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-plugins-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-remote-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-tests-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm python3-criu-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm python3-podman-4.9.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm runc-1.1.12-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm skopeo-1.14.5-3.module+el8.10.0+90429+ee702c5c.x86_64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90429+ee702c5c.x86_64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm aarch64: aardvark-dns-1.10.1-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm buildah-1.33.8-4.module+el8.10.0+90429+ee702c5c.aarch64.rpm buildah-tests-1.33.8-4.module+el8.10.0+90429+ee702c5c.aarch64.rpm cockpit-podman-84.1-1.module+el8.10.0+90429+ee702c5c.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm containers-common-1-82.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm container-selinux-2.229.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm crit-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm criu-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm criu-devel-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm criu-libs-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm crun-1.14.3-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm libslirp-4.4.0-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm netavark-1.10.3-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-catatonit-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-docker-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.noarch.rpm podman-gvproxy-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-plugins-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-remote-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-tests-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm python3-criu-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm python3-podman-4.9.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm runc-1.1.12-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm skopeo-1.14.5-3.module+el8.10.0+90429+ee702c5c.aarch64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90429+ee702c5c.aarch64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//aardvark-dns-1.10.1-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//buildah-1.33.8-4.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//cockpit-podman-84.1-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//conmon-2.1.10-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containernetworking-plugins-1.4.0-5.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containers-common-1-82.0.1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//container-selinux-2.229.0-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//criu-3.18-5.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//crun-1.14.3-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//fuse-overlayfs-1.13-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//libslirp-4.4.0-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//netavark-1.10.3-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//podman-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-podman-4.9.0-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//runc-1.1.12-5.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//skopeo-1.14.5-3.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//slirp4netns-1.2.3-1.module+el8.10.0+90429+ee702c5c.src.rpm Related CVEs: CVE-2024-9341 CVE-2024-9407 CVE-2024-9675 Description of changes: aardvark-dns buildah cockpit-podman conmon containernetworking-plugins containers-common [1-82.0.1] - Updated removed references [Orabug: 33473101] (Alex Burmashev) - Adjust registries.conf (Nikita Gerasimov) - removereferences to RedHat registry (Nikita Gerasimov) container-selinux criu crun fuse-overlayfs libslirp netavark oci-seccomp-bpf-hook podman [4:4.9.4-15.0.1] - Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813] - Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802] - Fixes issue of podman execvp error while using podmansh [Orabug: 36756665] [4:4.9.4-15] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/235a22c) - Resolves: RHEL-61837 [4:4.9.4-14] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/6cf9920) - Resolves: RHEL-60962 python-podman runc skopeo slirp4netns _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1310 https://linux.oracle.com/errata/ELSA-2024-1310.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-apphost-pack-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-host-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-hostfxr-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-runtime-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-sdk-8.0-8.0.103-2.0.1.el9_3.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.103-2.0.1.el9_3.x86_64.rpm dotnet-targeting-pack-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-templates-8.0-8.0.103-2.0.1.el9_3.x86_64.rpm netstandard-targeting-pack-2.1-8.0.103-2.0.1.el9_3.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.103-2.0.1.el9_3.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-apphost-pack-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-host-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-hostfxr-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-runtime-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-sdk-8.0-8.0.103-2.0.1.el9_3.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.103-2.0.1.el9_3.aarch64.rpm dotnet-targeting-pack-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-templates-8.0-8.0.103-2.0.1.el9_3.aarch64.rpm netstandard-targeting-pack-2.1-8.0.103-2.0.1.el9_3.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.103-2.0.1.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//dotnet8.0-8.0.103-2.0.1.el9_3.src.rpm Related CVEs: CVE-2024-21392 Description of changes: [- 8.0.103-2.0.1] - Update to .NET SDK 8.0.103 and Runtime 8.0.3 -Disable checking the signature of the last certificate in a chain if the certificate is supposedly self-signed. - Resolves: RHEL-25254 - Backport MSBuild locale fix - Resolves: RHEL-23936 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12069 https://linux.oracle.com/errata/ELSA-2024-12069.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-core-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-cross-headers-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-core-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-modules-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-modules-extra-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-doc-4.18.0-513.11.0.1.el8_9.noarch.rpm kernel-headers-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-modules-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-modules-extra-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-libs-4.18.0-513.11.0.1.el8_9.x86_64.rpm perf-4.18.0-513.11.0.1.el8_9.x86_64.rpm python3-perf-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-libs-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-abi-stablelists-4.18.0-513.11.0.1.el8_9.noarch.rpm aarch64: bpftool-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-cross-headers-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-headers-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-libs-4.18.0-513.11.0.1.el8_9.aarch64.rpm perf-4.18.0-513.11.0.1.el8_9.aarch64.rpm python3-perf-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-libs-devel-4.18.0-513.11.0.1.el8_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//kernel-4.18.0-513.11.0.1.el8_9.src.rpm Related CVEs: CVE-2023-2162 CVE-2023-4622 CVE-2023-42753 Description of changes: [4.18.0-513.11.1.0.1.el8_9.OL8] - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress{CVE-2023-2162} - af_unix: Fix null-ptr-deref in unix_stream_sendpage() {CVE-2023-4622} - netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet {CVE-2023-42753} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7749 https://linux.oracle.com/errata/ELSA-2023-7749.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.2.0-362.13.1.el9_3.x86_64.rpm kernel-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-abi-stablelists-5.14.0-362.13.1.el9_3.noarch.rpm kernel-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-devel-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-devel-matched-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-modules-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-modules-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-modules-extra-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-devel-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-devel-matched-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-doc-5.14.0-362.13.1.el9_3.noarch.rpm kernel-headers-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-modules-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-modules-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-modules-extra-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-tools-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-tools-libs-5.14.0-362.13.1.el9_3.x86_64.rpm perf-5.14.0-362.13.1.el9_3.x86_64.rpm python3-perf-5.14.0-362.13.1.el9_3.x86_64.rpm rtla-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-cross-headers-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-tools-libs-devel-5.14.0-362.13.1.el9_3.x86_64.rpm aarch64: bpftool-7.2.0-362.13.1.el9_3.aarch64.rpm kernel-headers-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-tools-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-tools-libs-5.14.0-362.13.1.el9_3.aarch64.rpm perf-5.14.0-362.13.1.el9_3.aarch64.rpm python3-perf-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-cross-headers-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-tools-libs-devel-5.14.0-362.13.1.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//kernel-5.14.0-362.13.1.el9_3.src.rpm Related CVEs: CVE-2023-1192 CVE-2023-5345 CVE-2023-20569 CVE-2023-45871 Description of changes: [5.14.0-362.13.1.el9_3.OL9] - x86/retpoline: Document some thunk handling aspects (Borislav Petkov) {CVE-2023-20569} - objtool: Fix return thunk patching in retpolines (Josh Poimboeuf){CVE-2023-20569} - x86/srso: Remove unnecessary semicolon (Yang Li) {CVE-2023-20569} - x86/calldepth: Rename __x86_return_skl() to call_depth_return_thunk() (Josh Poimboeuf) {CVE-2023-20569} - x86/nospec: Refactor UNTRAIN_RET[_*] (Josh Poimboeuf) {CVE-2023-20569} - x86/rethunk: Use SYM_CODE_START[_LOCAL]_NOALIGN macros (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Disentangle rethunk-dependent options (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Move retbleed IBPB check into existing 'has_microcode' code block (Josh Poimboeuf) {CVE-2023-20569} - x86/bugs: Remove default case for fully switched enums (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Remove 'pred_cmd' label (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Unexport untraining functions (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Improve i-cache locality for alias mitigation (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix unret validation dependencies (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix vulnerability reporting for missing microcode (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Print mitigation for retbleed IBPB case (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Print actual mitigation if requested mitigation isn't possible (Josh Poimboeuf) [RHEL-8594] {CVE-2023-20569} - x86/srso: Fix SBPB enablement for (possible) future fixed HW (Josh Poimboeuf) {CVE-2023-20569} - x86,static_call: Fix static-call vs return-thunk (Peter Zijlstra) {CVE-2023-20569} - x86/alternatives: Remove faulty optimization (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix SBPB enablement for spec_rstack_overflow=off (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Don't probe microcode in a guest (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Set CPUID feature bits independently of bug or mitigation status (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix srso_show_state() side effect (Josh Poimboeuf) {CVE-2023-20569} - x86/cpu: Fix amd_check_microcode() declaration (Arnd Bergmann) {CVE-2023-20569} - x86/srso: Correct the mitigation status when SMT is disabled (BorislavPetkov) {CVE-2023-20569} - x86/static_call: Fix __static_call_fixup() (Peter Zijlstra) {CVE-2023-20569} - objtool/x86: Fixup frame-pointer vs rethunk (Peter Zijlstra) {CVE-2023-20569} - x86/srso: Explain the untraining sequences a bit more (Borislav Petkov) {CVE-2023-20569} - x86/cpu/kvm: Provide UNTRAIN_RET_VM (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Cleanup the untrain mess (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Rename srso_(.*)_alias to srso_alias_\1 (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Rename original retbleed methods (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Clean up SRSO return thunk mess (Peter Zijlstra) {CVE-2023-20569} - x86/alternative: Make custom return thunk unconditional (Peter Zijlstra) {CVE-2023-20569} - objtool/x86: Fix SRSO mess (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Fix up srso_safe_ret() and __x86_return_thunk() (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Fix __x86_return_thunk symbol type (Peter Zijlstra) {CVE-2023-20569} - x86/retpoline,kprobes: Skip optprobe check for indirect jumps with retpolines and IBT (Petr Pavlu) {CVE-2023-20569} - x86/retpoline,kprobes: Fix position of thunk sections with CONFIG_LTO_CLANG (Petr Pavlu) {CVE-2023-20569} - x86/srso: Disable the mitigation on unaffected configurations (Borislav Petkov) {CVE-2023-20569} - x86/CPU/AMD: Fix the DIV(0) initial fix attempt (Borislav Petkov) {CVE-2023-20588} - x86/retpoline: Don't clobber RFLAGS during srso_safe_ret() (Sean Christopherson) {CVE-2023-20569} - x86/cpu/amd: Enable Zenbleed fix for AMD Custom APU 0405 (Cristian Ciocaltea) {CVE-2023-20593} - driver core: cpu: Fix the fallback cpu_show_gds() name (Borislav Petkov) {CVE-2023-20569} - x86: Move gds_ucode_mitigated() declaration to header (Arnd Bergmann) {CVE-2023-20569} - x86/speculation: Add cpu_show_gds() prototype (Arnd Bergmann) {CVE-2023-20569} - driver core: cpu: Make cpu_show_not_affected() static (Borislav Petkov) {CVE-2023-20569} - x86/srso: Fix build breakage with the LLVM linker (Nick Desaulniers) {CVE-2023-20569} -Documentation/srso: Document IBPB aspect and fix formatting (Borislav Petkov) {CVE-2023-20569} - driver core: cpu: Unify redundant silly stubs (Borislav Petkov) {CVE-2023-20569} - Documentation/hw-vuln: Unify filename specification in index (Borislav Petkov) {CVE-2023-20569} - x86/CPU/AMD: Do not leak quotient data after a division by 0 (Borislav Petkov) {CVE-2023-20588} - x86/srso: Tie SBPB bit setting to microcode patch detection (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add a forgotten NOENDBR annotation (Borislav Petkov) {CVE-2023-20569} - x86/srso: Fix return thunks in generated code (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Add IBPB on VMEXIT (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add IBPB (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add SRSO_NO support (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add IBPB_BRTYPE support (Borislav Petkov) {CVE-2023-20569} - redhat/configs/x86: Enable CONFIG_CPU_SRSO (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add a Speculative RAS Overflow mitigation (Borislav Petkov) {CVE-2023-20569} - x86/retbleed: Add __x86_return_thunk alignment checks (Borislav Petkov) {CVE-2023-20569} - x86/retbleed: Fix return thunk alignment (Borislav Petkov) {CVE-2023-20569} - x86/alternative: Optimize returns patching (Borislav Petkov) {CVE-2023-20569} - x86,objtool: Separate unret validation from unwind hints (Josh Poimboeuf) {CVE-2023-20569} - objtool: Add objtool_types.h (Josh Poimboeuf) {CVE-2023-20569} - objtool: Union instruction::{call_dest,jump_table} (Peter Zijlstra) {CVE-2023-20569} - x86/kprobes: Fix optprobe optimization check with CONFIG_RETHUNK (Peter Zijlstra) {CVE-2023-20569} - objtool: Fix SEGFAULT (Christophe Leroy) {CVE-2023-20569} - vmlinux.lds.h: add BOUNDED_SECTION* macros (Jim Cromie) {CVE-2023-20569} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0113 https://linux.oracle.com/errata/ELSA-2023-0113.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: postgresql-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-contrib-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-docs-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-plperl-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-plpython3-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-pltcl-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-server-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-server-devel-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-static-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-test-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-test-rpm-macros-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-upgrade-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-upgrade-devel-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm aarch64: postgresql-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-contrib-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-docs-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-plperl-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-plpython3-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-pltcl-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-server-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-server-devel-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-static-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-test-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-test-rpm-macros-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-upgrade-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-upgrade-devel-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/postgresql-10.23-1.module+el8.7.0+20896+16771be9.src.rpm Related CVEs: CVE-2022-2625 Description of changes: [10.23-1] - Fix CVE-2022-2625 - Resolves: #2143167 - Rebase to10.23 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9469 https://linux.oracle.com/errata/ELSA-2022-9469.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: grub2-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-common-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-efi-ia32-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-ia32-modules-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-efi-x64-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-x64-modules-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-pc-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-pc-modules-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-tools-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-tools-extra-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-tools-minimal-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-ia32-cdboot-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-x64-cdboot-2.02-0.87.0.21.el7_9.9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/grub2-2.02-0.87.0.21.el7_9.9.src.rpm Related CVEs: CVE-2021-3695 CVE-2021-3696 CVE-2021-3697 CVE-2022-28733 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 Description of changes: [2.02-0.87.0.21.el7_9.9] - Add CVE-2022-28736 to the list [JIRA: OLDIS-16371] [2.02-0.87.0.19.el7_9.9] - Fix: CVE-2021-3695, CVE-2021-3696, CVE-2021-3697, CVE-2022-28733, CVE-2022-28734, CVE-2022-28735 [JIRA: OLDIS-16371] - Various coverity fixes [JIRA: OLDIS-16371] - bump SBAT generation [JIRA: OLDIS-16371] _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2013-2542 The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: kernel-uek-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-debug-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-debug-devel-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-headers-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-devel-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-doc-2.6.32-400.29.3.el5uek.noarch.rpm kernel-uek-firmware-2.6.32-400.29.3.el5uek.noarch.rpm ofa-2.6.32-400.29.3.el5uek-1.5.1-4.0.58.i686.rpm ofa-2.6.32-400.29.3.el5uekdebug-1.5.1-4.0.58.i686.rpm mlnx_en-2.6.32-400.29.3.el5uek-1.5.7-2.i686.rpm mlnx_en-2.6.32-400.29.3.el5uekdebug-1.5.7-2.i686.rpm x86_64: kernel-uek-firmware-2.6.32-400.29.3.el5uek.noarch.rpm kernel-uek-doc-2.6.32-400.29.3.el5uek.noarch.rpm kernel-uek-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-headers-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-devel-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-debug-devel-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-debug-2.6.32-400.29.3.el5uek.x86_64.rpm ofa-2.6.32-400.29.3.el5uek-1.5.1-4.0.58.x86_64.rpm ofa-2.6.32-400.29.3.el5uekdebug-1.5.1-4.0.58.x86_64.rpm mlnx_en-2.6.32-400.29.3.el5uek-1.5.7-2.x86_64.rpm mlnx_en-2.6.32-400.29.3.el5uekdebug-1.5.7-2.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol5/SRPMS-updates/kernel-uek-2.6.32-400.29.3.el5uek.src.rpm https://oss.oracle.com:443/ol5/SRPMS-updates/ofa-2.6.32-400.29.3.el5uek-1.5.1-4.0.58.src.rpm https://oss.oracle.com:443/ol5/SRPMS-updates/mlnx_en-2.6.32-400.29.3.el5uek-1.5.7-2.src.rpm Description of changes: kernel-uek [2.6.32-400.29.3.el5uek] - block: do not pass disk names as format strings (Jerry Snitselaar) [Orabug: 17230124] {CVE-2013-2851} - af_key: initialize satype in key_notify_policy_flush() (Nicolas Dichtel) [Orabug: 17370765] {CVE-2013-2237} - Bluetooth: L2CAP - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17371054]{CVE-2012-6544} - Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) (Mathias Krause) [Orabug: 17371072] {CVE-2012-6544} - ipv6: ip6_sk_dst_check() must not assume ipv6 dst (Eric Dumazet) [Orabug: 17371079] {CVE-2013-2232} - sctp: Use correct sideffect command in duplicate cookie handling (Vlad Yasevich) [Orabug: 17371121] {CVE-2013-2206} - sctp: deal with multiple COOKIE_ECHO chunks (Max Matveev) [Orabug: 17372129] {CVE-2013-2206} . Key revisions for Oracle Linux 5 rpms tackling major security vulnerabilities. Vital kernel improvements incorporated.. Oracle Linux, Kernel Updates, Security Issues, RPM Packages. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.