[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2022-9787 -- Oracle kernel-uek

ID: oval:org.secpod.oval:def:1506009Date: (C)2022-09-19   (M)2024-04-17
Class: PATCHFamily: unix




[4.14.35-2047.517.3.el7uek] - KVM: x86: use raw clock values consistently [Orabug: 34575637] - KVM: x86: reorganize pvclock_gtod_data members [Orabug: 34575637] - KVM: x86: switch KVMCLOCK base to monotonic raw clock [Orabug: 34575637] [4.14.35-2047.517.2.el7uek] - kernfs: Replace global kernfs_open_file_mutex with hashed mutexes. [Orabug: 34476942] - kernfs: Introduce interface to access global kernfs_open_file_mutex. [Orabug: 34476942] - kernfs: make -attr.open RCU protected. [Orabug: 34476942] - kernfs: Rename kernfs_put_open_node to kernfs_unlink_open_file. [Orabug: 34476942] - kernfs: Remove reference counting for kernfs_open_node. [Orabug: 34476942] - rds/ib: handle posted ACK during connection shutdown [Orabug: 34465810] - rds/ib: reap tx completions during connection shutdown [Orabug: 34465810] - scsi: target: Fix WRITE_SAME No Data Buffer crash [Orabug: 34419972] {CVE-2022-21546} - rds/rdma: destroy CQs during user initiated rds connection resets [Orabug: 34414240] - rds: copy_from_user only once per rds_sendmsg system call [Orabug: 34510858] {CVE-2022-21385} [4.14.35-2047.517.1.el7uek] - net_sched: cls_route: remove from list when handle is 0 [Orabug: 34480752] {CVE-2022-2588} - Restore module, async: async_synchronize_full on module init iff async is used [Orabug: 34469834] - net/rds: Replace #ifdef DEBUG with CONFIG_SLUB_DEBUG [Orabug: 34405766] - ext4: Move to shared i_rwsem even without dioread_nolock mount opt [Orabug: 34295843] - ext4: Start with shared i_rwsem in case of DIO instead of exclusive [Orabug: 34295843] - ext4: further refactoring bufferio and dio helper [Orabug: 34295843] - ext4: refactor ext4_file_write_iter [Orabug: 34295843] - xen/manage: Use orderly_reboot to reboot [Orabug: 34211118] - xen/manage: revert xen/manage: enable C_A_D to force reboot [Orabug: 34211118] - Linux 4.14.288 - dmaengine: ti: Add missing put_device in ti_dra7_xbar_route_allocate - dmaengine: ti: Fix refcount leak in ti_dra7_xbar_route_allocate - dmaengine: at_xdma: handle errors of at_xdmac_alloc_desc correctly - ida: don"t use BUG_ON for debugging - i2c: cadence: Unregister the clk notifier in error path - pinctrl: sunxi: a83t: Fix NAND function name for some pins - xfs: remove incorrect ASSERT in xfs_rename - powerpc/powernv: delay rng platform device creation until later in boot - video: of_display_timing.h: include errno.h - fbcon: Disallow setting font bigger than screen size - iommu/vt-d: Fix PCI bus rescan device hot add - net: rose: fix UAF bug caused by rose_t0timer_expiry - usbnet: fix memory leak in error case - can: gs_usb: gs_usb_open/close: fix memory leak - can: grcan: grcan_probe: remove extra of_node_get - mm/slub: add missing TID updates on slab deactivation - esp: limit skb_page_frag_refill use to a single page - Linux 4.14.287 - xen/gntdev: Avoid blocking in unmap_grant_pages - net: usb: qmi_wwan: add Telit 0x1070 composition - net: usb: qmi_wwan: add Telit 0x1060 composition - xen/arm: Fix race in RB-tree based P2M accounting - net: Rename and export copy_skb_header - ipv6/sit: fix ipip6_tunnel_get_prl return value - sit: use min - hwmon: don"t call platform_device_del if platform_device_add fails - NFC: nxp-nci: Don"t issue a zero length i2c_master_read - nfc: nfcmrvl: Fix irq_of_parse_and_map return value - net: bonding: fix use-after-free after 802.3ad slave unbind - net: bonding: fix possible NULL deref in rlb code - netfilter: nft_dynset: restore set element counter when failing to update - caif_virtio: fix race between virtio_device_ready and ndo_open - net: ipv6: unexport __init-annotated seg6_hmac_net_init - usbnet: fix memory allocation in helpers - RDMA/qedr: Fix reporting QP timeout attribute - net: usb: ax88179_178a: Fix packet receiving - net: rose: fix UAF bugs caused by timer handler - SUNRPC: Fix READ_PLUS crasher - s390/archrandom: simplify back to earlier design and initialize earlier - dm raid: fix KASAN warning in raid5_add_disks - dm raid: fix accesses beyond end of raid member array - nvdimm: Fix badblocks clear off-by-one error - Linux 4.14.286 - swiotlb: skip swiotlb_bounce when orig_addr is zero - kexec_file: drop weak attribute from arch_kexec_apply_relocations[_add] - fdt: Update CRC check for rng-seed - xen: unexport __init-annotated xen_xlate_map_ballooned_pages - drm: remove drm_fb_helper_modinit - powerpc/pseries: wire up rng during setup_arch - modpost: fix section mismatch check for exported init/exit sections - ARM: cns3xxx: Fix refcount leak in cns3xxx_init - ARM: Fix refcount leak in axxia_boot_secondary - ARM: exynos: Fix refcount leak in exynos_map_pmu - ARM: dts: imx6qdl: correct PU regulator ramp delay - powerpc/powernv: wire up rng during setup_arch - powerpc/rtas: Allow ibm,platform-dump RTAS call with null buffer address - powerpc: Enable execve syscall exit tracepoint - xtensa: Fix refcount leak bug in time.c - xtensa: xtfpga: Fix refcount leak bug in setup - iio: adc: axp288: Override TS pin bias current for some models - iio: trigger: sysfs: fix use-after-free on remove - iio: gyro: mpu3050: Fix the error handling in mpu3050_power_up - iio: accel: mma8452: ignore the return value of reset operation - iio:accel:bma180: rearrange iio trigger get and register - usb: chipidea: udc: check request status before setting device address - iio: adc: vf610: fix conversion mode sysfs node name - igb: Make DMA faster when CPU is active on the PCIe link - MIPS: Remove repetitive increase irq_err_count - x86/xen: Remove undefined behavior in setup_features - bonding: ARP monitor spams NETDEV_NOTIFY_PEERS notifiers - USB: serial: option: add Quectel RM500K module support - USB: serial: option: add Quectel EM05-G modem - USB: serial: option: add Telit LE910Cx 0x1250 composition - random: quiet urandom warning ratelimit suppression message - dm era: commit metadata in postsuspend after worker stops - ata: libata: add qc-flags in ata_qc_complete_template tracepoint - random: schedule mix_interrupt_randomness less often - vt: drop old FONT ioctls - Linux 4.14.285 - tcp: drop the hash_32 part from the index calculation - tcp: increase source port perturb table to 2^16 - tcp: dynamically allocate the perturb table used by source ports - tcp: add small random increments to the source port - tcp: use different parts of the port_offset for index and offset - tcp: add some entropy in __inet_hash_connect - xprtrdma: fix incorrect header size calculations - usb: gadget: u_ether: fix regression in setting fixed MAC address - s390/mm: use non-quiescing sske for KVM switch to keyed guest - virtio-pci: Remove wrong address verification in vp_del_vqs - ext4: add reserved GDT blocks check - ext4: make variable count signed - ext4: fix bug_on ext4_mb_use_inode_pa - serial: 8250: Store to lsr_save_flags after lsr read - usb: gadget: lpc32xx_udc: Fix refcount leak in lpc32xx_udc_probe - usb: dwc2: Fix memory leak in dwc2_hcd_init - USB: serial: io_ti: add Agilent E5805A support - USB: serial: option: add support for Cinterion MV31 with new baseline - comedi: vmk80xx: fix expression for tx buffer size - irqchip/gic/realview: Fix refcount leak in realview_gic_of_init - certs/blacklist_hashes.c: fix const confusion in certs blacklist - arm64: ftrace: fix branch range checks - net: bgmac: Fix an erroneous kfree in bgmac_remove - misc: atmel-ssc: Fix IRQ check in ssc_probe - tty: goldfish: Fix free_irq on remove - i40e: Fix call trace in setup_tx_descriptors - pNFS: Don"t keep retrying if the server replied NFS4ERR_LAYOUTUNAVAILABLE - random: credit cpu and bootloader seeds by default - net: ethernet: mtk_eth_soc: fix misuse of mem alloc interface netdev[napi]_alloc_frag - ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg - nfc: nfcmrvl: Fix memory leak in nfcmrvl_play_deferred - virtio-mmio: fix missing put_device when vm_cmdline_parent registration failed - scsi: pmcraid: Fix missing resource cleanup in error case - scsi: ipr: Fix missing/incorrect resource cleanup in error case - scsi: lpfc: Fix port stuck in bypassed state after LIP in PT2PT topology - scsi: vmw_pvscsi: Expand vcpuHint to 16 bits - ASoC: wm8962: Fix suspend while playing music - ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo - ASoC: cs42l56: Correct typo in minimum level for SX volume controls - ASoC: cs42l52: Correct TLV for Bypass Volume - ASoC: cs53l30: Correct number of volume levels on SX controls - ASoC: cs42l52: Fix TLV scales for mixer controls - random: account for arch randomness in bits - random: mark bootloader randomness code as __init - random: avoid checking crng_ready twice in random_init - crypto: drbg - make reseeding from get_random_bytes synchronous - crypto: drbg - always try to free Jitter RNG instance - crypto: drbg - move dynamic -reseed_threshold adjustments to __drbg_seed - crypto: drbg - track whether DRBG was seeded with !rng_is_initialized - crypto: drbg - prepare for more fine-grained tracking of seeding state - crypto: drbg - always seeded with SP800-90B compliant noise source - crypto: drbg - add FIPS 140-2 CTRNG for noise source - Revert random: use static branch for crng_ready - random: check for signals after page of pool writes - random: wire up fops-splice_{read,write}_iter - random: convert to using fops-write_iter - random: move randomize_page into mm where it belongs - random: move initialization functions out of hot pages - random: use proper jiffies comparison macro - random: use symbolic constants for crng_init states - siphash: use one source of truth for siphash permutations - random: help compiler out with fast_mix by using simpler arguments - random: do not use input pool from hard IRQs - random: order timer entropy functions below interrupt functions - random: do not pretend to handle premature next security model - random: do not use batches when !crng_ready - random: insist on random_get_entropy existing in order to simplify - xtensa: use fallback for random_get_entropy instead of zero - sparc: use fallback for random_get_entropy instead of zero - um: use fallback for random_get_entropy instead of zero - x86/tsc: Use fallback for random_get_entropy instead of zero - nios2: use fallback for random_get_entropy instead of zero - arm: use fallback for random_get_entropy instead of zero - mips: use fallback for random_get_entropy instead of just c0 random - m68k: use fallback for random_get_entropy instead of zero - timekeeping: Add raw clock fallback for random_get_entropy - powerpc: define get_cycles macro for arch-override - alpha: define get_cycles macro for arch-override - parisc: define get_cycles macro for arch-override - s390: define get_cycles macro for arch-override - ia64: define get_cycles macro for arch-override - init: call time_init before rand_initialize - random: fix sysctl documentation nits - random: document crng_fast_key_erasure destination possibility - random: make random_get_entropy return an unsigned long - random: check for signals every PAGE_SIZE chunk of /dev/[u]random - random: check for signal_pending outside of need_resched check - random: do not allow user to keep crng key around on stack - random: do not split fast init input in add_hwgenerator_randomness - random: mix build-time latent entropy into pool at init - random: re-add removed comment about get_random_{u32,u64} reseeding - random: treat bootloader trust toggle the same way as cpu trust toggle - random: skip fast_init if hwrng provides large chunk of entropy - random: check for signal and try earlier when generating entropy - random: reseed more often immediately after booting - random: make consistent usage of crng_ready - random: use SipHash as interrupt entropy accumulator - random: replace custom notifier chain with standard one - random: don"t let 644 read-only sysctls be written to - random: give sysctl_random_min_urandom_seed a more sensible value - random: do crng pre-init loading in worker rather than irq - random: unify cycles_t and jiffies usage and types - random: cleanup UUID handling - random: only wake up writers after zap if threshold was passed - random: round-robin registers as ulong, not u32 - random: pull add_hwgenerator_randomness declaration into random.h - random: check for crng_init == 0 in add_device_randomness - random: unify early init crng load accounting - random: do not take pool spinlock at boot - random: defer fast pool mixing to worker - random: rewrite header introductory comment - random: group sysctl functions - random: group userspace read/write functions - random: group entropy collection functions - random: group entropy extraction functions - random: remove useless header comment - random: introduce drain_entropy helper to declutter crng_reseed - random: deobfuscate irq u32/u64 contributions - random: add proper SPDX header - random: remove unused tracepoints - random: remove ifdef"d out interrupt bench - random: tie batched entropy generation to base_crng generation - random: zero buffer after reading entropy from userspace - random: remove outdated INT_MAX 6 check in urandom_read - random: use hash function for crng_slow_load - random: absorb fast pool into input pool after fast load - random: do not xor RDRAND when writing into /dev/random - random: ensure early RDSEED goes through mixer on init - random: inline leaves of rand_initialize - random: use RDSEED instead of RDRAND in entropy extraction - random: fix locking in crng_fast_load - random: remove batched entropy locking - random: remove use_input_pool parameter from crng_reseed - random: make credit_entropy_bits always safe - random: always wake up entropy writers after extraction - random: use linear min-entropy accumulation crediting - random: simplify entropy debiting - random: use computational hash for entropy extraction - random: only call crng_finalize_init for primary_crng - random: access primary_pool directly rather than through pointer - random: continually use hwgenerator randomness - random: simplify arithmetic function flow in account - random: access input_pool_data directly rather than through pointer - random: cleanup fractional entropy shift constants - random: prepend remaining pool constants with POOL_ - random: de-duplicate INPUT_POOL constants - random: remove unused OUTPUT_POOL constants - random: rather than entropy_store abstraction, use global - random: try to actively add entropy rather than passively wait for it - random: remove unused extract_entropy reserved argument - random: remove incomplete last_data logic - random: cleanup integer types - crypto: chacha20 - Fix chacha20_block keystream alignment - random: cleanup poolinfo abstraction - random: fix typo in comments - random: don"t reset crng_init_cnt on urandom_read - random: avoid superfluous call to RDRAND in CRNG extraction - random: early initialization of ChaCha constants - random: initialize ChaCha20 constants with correct endianness - random: use IS_ENABLED instead of ifdefs - random: harmonize crng init done messages - random: mix bootloader randomness into pool - random: do not re-init if crng_reseed completes before primary init - random: do not sign extend bytes for rotation when mixing - random: use BLAKE2s instead of SHA1 in extraction - random: remove unused irq_flags argument from add_interrupt_randomness - random: document add_hwgenerator_randomness with other input functions - crypto: blake2s - adjust include guard naming - MAINTAINERS: co-maintain random.c - random: remove dead code left over from blocking pool - random: avoid arch_get_random_seed_long when collecting IRQ randomness - random: add arch_get_random_*long_early - powerpc: Use bool in archrandom.h - linux/random.h: Mark CONFIG_ARCH_RANDOM functions __must_check - linux/random.h: Use false with bool - linux/random.h: Remove arch_has_random, arch_has_random_seed - s390: Remove arch_has_random, arch_has_random_seed - powerpc: Remove arch_has_random, arch_has_random_seed - x86: Remove arch_has_random, arch_has_random_seed - random: avoid warnings for !CONFIG_NUMA builds - random: split primary/secondary crng init paths - random: remove some dead code of poolinfo - random: fix typo in add_timer_randomness - random: Add and use pr_fmt - random: convert to ENTROPY_BITS for better code readability - random: remove unnecessary unlikely - random: remove kernel.random.read_wakeup_threshold - random: delete code to pull data into pools - random: remove the blocking pool - random: fix crash on multiple early calls to add_bootloader_randomness - char/random: silence a lockdep splat with printk - random: make /dev/random be almost like /dev/urandom - random: ignore GRND_RANDOM in getentropy - random: add GRND_INSECURE to return best-effort non-cryptographic bytes - random: Add a urandom_read_nowait for random APIs that don"t warn - random: Don"t wake crng_init_wait when crng_init == 1 - lib/crypto: sha1: re-roll loops to reduce code size - lib/crypto: blake2s: move hmac construction into wireguard - crypto: blake2s - generic C library implementation and selftest - crypto: Deduplicate le32_to_cpu_array and cpu_to_le32_array - Revert hwrng: core - Freeze khwrng thread during suspend - char/random: Add a newline at the end of the file - random: Use wait_event_freezable in add_hwgenerator_randomness - fdt: add support for rng-seed - random: Support freezable kthreads in add_hwgenerator_randomness - random: fix soft lockup when trying to read from an uninitialized blocking pool - latent_entropy: avoid build error when plugin cflags are not set - random: document get_random_int family - random: move rand_initialize earlier - random: only read from /dev/random after its pool has received 128 bits - drivers/char/random.c: make primary_crng static - drivers/char/random.c: remove unused stuct poolinfo::poolbits - drivers/char/random.c: constify poolinfo_table - random: make CPU trust a boot parameter - random: Make crng state queryable - random: remove preempt disabled region - random: add a config option to trust the CPU"s hwrng - random: Return nbytes filled from hw RNG - random: Fix whitespace pre random-bytes work - drivers/char/random.c: remove unused dont_count_entropy - random: optimize add_interrupt_randomness - random: always fill buffer in get_random_bytes_wait - crypto: chacha20 - Fix keystream alignment for chacha20_block - 9p: missing chunk of fs/9p: Don"t update file type when updating file attributes [4.14.35-2047.517.0.el7uek] - mpt3sas: Fix panic observed while accessing the hw ctx queue [Orabug: 34446738] - driver: marvell: mmc: Add new bus modes overrides from DT [Orabug: 34440004] - octeontx2: mmc: Adds mechanism to modify all MMC bus modes timings [Orabug: 34440004] - rds/rdma: correctly assign the dest qp num in rds ib connection [Orabug: 34429478] - Revert uek-rpm: Enable config CONFIG_SCSI_MQ_DEFAULT [Orabug: 34419153] - net/rds : Adding support to print SCQ and RCQ completion vectors in rds-info. [Orabug: 34398210] - IB/mlx5: Disable BME for unbound devices too [Orabug: 34395378] - net/mlx5: Rearm the FW tracer after each tracer event [Orabug: 34387281] - net/mlx5: FW tracer, Add debug prints [Orabug: 34387281] - perf script: Fix crash because of missing evsel-priv [Orabug: 34382257] - net/rds: Fix a NULL dereference in rds_tcp_accept_one [Orabug: 34371946] - ocfs2: kill EBUSY from dlmfs_evict_inode [Orabug: 34364338] - ocfs2: dlmfs: don"t clear USER_LOCK_ATTACHED when destroying lock [Orabug: 34364338] - rds: ib: Qualify RNR Retry Timer check with firmware version [Orabug: 33665743]

Platform:
Oracle Linux 7
Product:
kernel-uek
Reference:
ELSA-2022-9787
CVE-2022-21385
CVE-2022-21546
CVE-2022-2588
CVE    3
CVE-2022-21385
CVE-2022-21546
CVE-2022-2588
CPE    2
cpe:/o:oracle:kernel-uek:4.x
cpe:/o:oracle:linux:7

© SecPod Technologies