The following updated rpms for Oracle Linux Cloud Native Environment 1.0 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Cloud Native Environment Security Advisory ELSA-2022-9201 https://linux.oracle.com/errata/ELSA-2022-9201.html The following updated rpms for Oracle Linux Cloud Native Environment 1.0 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-container-4.14.35-2047.511.5.4.el7.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/kernel-uek-container-4.14.35-2047.511.5.4.el7.src.rpm Related CVEs: CVE-2021-26341 Description of changes: - 4.14.35-2047.511.5.4.el7 - x86/speculation: Add knob for eibrs_retpoline_enabled (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Extend our code to properly support eibrs+lfence and eibrs+retpoline (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Update link to AMD speculation whitepaper (Kim Phillips) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Use generic retpoline by default on AMD (Kim Phillips) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting (Josh Poimboeuf) [Orabug: 33922122] {CVE-2021-26341} - Documentation/hw-vuln: Update spectre doc (Peter Zijlstra) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Add eIBRS + Retpoline options (Peter Zijlstra) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE (Peter Zijlstra (Intel)) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Merge one test in spectre_v2_user_select_mitigation() (Borislav Petkov) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Update ALTERNATIVEs to (more closely) match upstream (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341} - x86/speculation: Fix bug in retpoline mode on AMD with `spectre_v2=none` (Patrick Colp) [Orabug: 33922122] {CVE-2021-26341} - bpf: Add kconfig knob for disabling unpriv bpf by default (Daniel Borkmann) [Orabug: 33926438] _______________________________________________ El-errata mailing list
The 5.9.10 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-4700a73bd5 2020-11-25 01:42:11.864491 --------------------------------------------------------------------------------Name : kernel Product : Fedora 32 Version : 5.9.10 Release : 100.fc32 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: The 5.9.10 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Mon Nov 23 2020 Justin M. Forbes - 5.9.10-100 - Linux v5.9.10 - Fix CVE-2020-28941 (rhbz 1899985 1899986) - Fix CVE-2020-4788 (rhbz 1888433 1900437) --------------------------------------------------------------------------------References: [ 1 ] Bug #1888433 - CVE-2020-4788 kernel: speculation on incompletely validated data on IBM Power9 https://bugzilla.redhat.com/show_bug.cgi?id=1888433 [ 2 ] Bug #1899985 - CVE-2020-28941 kernel: NULL pointer dereference in spk_ttyio_ldisc_close function in drivers/accessibility/speakup/spk_ttyio.c https://bugzilla.redhat.com/show_bug.cgi?id=1899985 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-4700a73bd5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.