Lucene search

K
oraclelinuxOracleLinuxELSA-2023-7549
HistoryDec 01, 2023 - 12:00 a.m.

kernel security and bug fix update

2023-12-0100:00:00
linux.oracle.com
25
media dvb-core fix
cifs uaf
nvmet-tcp uaf
net tun bug
bpf verifier bug
oracle linux certificates update
aarch64 signing disable
oracle linux rhck module signing key
x509.genkey update
shim conflict
upstream reference removal
patch drop
unix

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7.1 High

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

90.1%

[4.18.0-513.9.1_9.OL8]

  • media: dvb-core: Fix use-after-free due to race at dvb_register_device() (Mauro Carvalho Chehab) {CVE-2022-45884}
  • cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu) {CVE-2023-1192}
  • nvmet-tcp: Fix a possible UAF in queue intialization setup (Sagi Grimberg) {CVE-2023-5178}
  • net: tun: fix bugs for oversize packet when napi frags enabled (Ziyang Xuan) {CVE-2023-3812}
  • bpf: Fix incorrect verifier pruning due to missing register precision taints (Daniel Borkmann) (Andrii Nakryiko) {CVE-2023-2163}
  • media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 (Hyunwoo Kim) {CVE-2022-45919}
  • media: dvbdev: fix error logic at dvb_register_device() (Mauro Carvalho Chehab)
  • media: dvbdev: Fix memleak in dvb_register_device (Dinghao Liu)
  • media: dvb-core: Fix use-after-free due on race condition at dvb_net (Hyunwoo Kim} {CVE-2022-45886}
    [4.18.0-513.5.1_9.OL8]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
  • Drop not needed patch

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7.1 High

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

90.1%