[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2023-12792 -- Oracle kernel-uek

ID: oval:org.secpod.oval:def:1506993Date: (C)2023-09-22   (M)2024-05-29
Class: PATCHFamily: unix




[4.14.35-2047.529.3.el7uek] - uek-rpm: Update kernel linux-firmware dependency to 20230516-999.26.git6c9e0ed5. [Orabug: 35724203] - LTS version: v4.14.322 - drm/edid: fix objtool warning in drm_cvt_modes - mtd: rawnand: omap_elm: Fix incorrect type in assignment - test_firmware: fix a memory leak with reqs buffer - ext2: Drop fragment support - net: usbnet: Fix WARNING in usbnet_start_xmit/usb_submit_urb - Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb - fs/sysv: Null check to prevent null-ptr-deref bug - USB: zaurus: Add ID for A-300/B-500/C-700 - libceph: fix potential hang in ceph_osdc_notify - loop: Select I/O scheduler "none" from inside add_disk - tcp_metrics: fix data-race in tcpm_suck_dst vs fastopen - tcp_metrics: annotate data-races around tm-tcpm_net - tcp_metrics: annotate data-races around tm-tcpm_vals[] - tcp_metrics: annotate data-races around tm-tcpm_lock - tcp_metrics: annotate data-races around tm-tcpm_stamp - tcp_metrics: fix addr_same helper - ip6mr: Fix skb_under_panic in ip6mr_cache_report - net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free - net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free - net: add missing data-race annotation for sk_ll_usec - net: add missing data-race annotations around sk-sk_peek_off - perf test uprobe_from_different_cu: Skip if there is no gcc - net/mlx5e: fix return value check in mlx5e_ipsec_remove_trailer - word-at-a-time: use the same return type for has_zero regardless of endianness - perf: Fix function pointer case - net/sched: cls_u32: Fix reference counter leak leading to overflow - net/sched: sch_qfq: account for stab overhead in qfq_enqueue - net/sched: cls_fw: Fix improper refcount update leads to use-after-free - drm/client: Fix memory leak in drm_client_target_cloned - dm cache policy smq: ensure IO doesn"t prevent cleaner policy progress - ASoC: wm8904: Fill the cache for WM8904_ADC_TEST_0 register - s390/dasd: fix hanging device after quiesce/resume - irq-bcm6345-l1: Do not assume a fixed block to cpu mapping - tpm_tis: Explicitly check for error code - hwmon: Fix for temp6 processed even if PECI1 disabled - staging: ks7010: potential buffer overflow in ks_wlan_set_encode_ext - Documentation: security-bugs.rst: update preferences when dealing with the linux-distros group - usb: xhci-mtk: set the dma max_seg_size - usb: ohci-at91: Fix the unhandle interrupt when resume - can: gs_usb: gs_can_close: add missing set of CAN state to CAN_STATE_STOPPED - USB: serial: simple: sort driver entries - USB: serial: simple: add Kaufmann RKS+CAN VCP - USB: serial: option: add Quectel EC200A module support - USB: serial: option: support Quectel EM060K_128 - tracing: Fix warning in trace_buffered_event_disable - ring-buffer: Fix wrong stat of cpu_buffer-read - ata: pata_ns87415: mark ns87560_tf_read static - dm raid: fix missing reconfig_mutex unlock in raid_ctr error paths - block: Fix a source code comment in include/uapi/linux/blkzoned.h - ASoC: fsl_spdif: Silence output on stop - benet: fix return value check in be_lancer_xmit_workarounds - platform/x86: msi-laptop: Fix rfkill out-of-sync on MSI Wind U100 - team: reset team"s flags when down link is P2P device - bonding: reset bond"s flags when down link is P2P device - tcp: Reduce chance of collisions in inet6_hashfn. - ipv6 addrconf: fix bug where deleting a mngtmpaddr can create a new temporary address - ethernet: atheros: fix return value check in atl1e_tso_csum - i40e: Fix an NULL vs IS_ERR bug for debugfs_create_dir - gpio: tps68470: Make tps68470_gpio_output always set the initial value - tcp: annotate data-races around fastopenq.max_qlen - tcp: annotate data-races around tp-notsent_lowat - tcp: annotate data-races around rskq_defer_accept - netfilter: nf_tables: fix spurious set element insertion failure - llc: Don"t drop packet from non-root netns. - fbdev: au1200fb: Fix missing IRQ check in au1200fb_drv_probe - net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field/cpsw_ale_set_field - pinctrl: amd: Use amd_pinconf_set for all config options - fbdev: imxfb: warn about invalid left/right margin - spi: bcm63xx: fix max prepend length - igb: Fix igb_down hung on surprise removal - wifi: wext-core: Fix -Wstringop-overflow warning in ioctl_standard_iw_point - bpf: Address KCSAN report on bpf_lru_list - sched/fair: Don"t balance task to its current running CPU - posix-timers: Ensure timer ID search-loop limit is valid - md/raid10: prevent soft lockup while flush writes - md: fix data corruption for raid456 when reshape restart while grow up - nbd: Add the maximum limit of allocated index in nbd_dev_add - debugobjects: Recheck debug_objects_enabled before reporting - ext4: correct inline offset when handling xattrs in inode body - can: bcm: Fix UAF in bcm_proc_show - fuse: revalidate: don"t invalidate if interrupted - perf probe: Add test for regression introduced by switch to die_get_decl_file - serial: atmel: don"t enable IRQs prematurely - scsi: qla2xxx: Pointer may be dereferenced - scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport - scsi: qla2xxx: Fix potential NULL pointer dereference - scsi: qla2xxx: Wait for io return on terminate rport - xtensa: ISS: fix call to split_if_spec - ring-buffer: Fix deadloop issue on reading trace_pipe - tty: serial: samsung_tty: Fix a memory leak in s3c24xx_serial_getclk when iterating clk - tty: serial: samsung_tty: Fix a memory leak in s3c24xx_serial_getclk in case of error - Revert 8250: add support for ASIX devices with a FIFO bug - meson saradc: fix clock divider mask length - hwrng: imx-rngc - fix the timeout for init and self check - fs: dlm: return positive pid value for F_GETLK - md/raid0: add discard support for the "original" layout - misc: pci_endpoint_test: Re-init completion for every test - PCI: Add function 1 DMA alias quirk for Marvell 88SE9235 - jfs: jfs_dmap: Validate db_l2nbperpage while mounting - ext4: only update i_reserved_data_blocks on successful block allocation - ext4: fix wrong unit use in ext4_mb_clear_bb - perf intel-pt: Fix CYC timestamps after standalone CBR - SUNRPC: Fix UAF in svc_tcp_listen_data_ready - tpm: tpm_vtpm_proxy: fix a race condition in /dev/vtpmx creation - net/sched: make psched_mtu RTNL-less safe - wifi: airo: avoid uninitialized warning in airo_get_rate - ipv6/addrconf: fix a potential refcount underflow for idev - NTB: ntb_transport: fix possible memory leak while device_register fails - ntb: intel: Fix error handling in intel_ntb_pci_driver_init - NTB: amd: Fix error handling in amd_ntb_pci_driver_init - ntb: idt: Fix error handling in idt_pci_driver_init - udp6: fix udp6_ehashfn typo - net: mvneta: fix txq_map in case of txq_number==1 - workqueue: clean up WORK_* constant types, clarify masking - netfilter: nf_tables: prevent OOB access in nft_byteorder_eval - netfilter: conntrack: Avoid nf_ct_helper_hash uses after free - netfilter: nf_tables: unbind non-anonymous set if rule construction fails - netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE - spi: spi-fsl-spi: allow changing bits_per_word while CS is still active - spi: spi-fsl-spi: relax message sanity checking a little - spi: spi-fsl-spi: remove always-true conditional in fsl_spi_do_one_msg - ARM: orion5x: fix d2net gpio initialization - btrfs: fix race when deleting quota root from the dirty cow roots list - jffs2: reduce stack usage in jffs2_build_xattr_subsystem - integrity: Fix possible multiple allocation in integrity_inode_get - mmc: core: disable TRIM on Micron MTFC4GACAJCN-1M - mmc: core: disable TRIM on Kingston EMMC04G-M627 - NFSD: add encoding of op_recall flag for write delegation - sh: dma: Fix DMA channel offset calculation - net/sched: act_pedit: Add size check for TCA_PEDIT_PARMS_EX - tcp: annotate data races in __tcp_oow_rate_limited - net: bridge: keep ports without IFF_UNICAST_FLT in BR_PROMISC mode - powerpc: allow PPC_EARLY_DEBUG_CPM only when SERIAL_CPM=y - mailbox: ti-msgmgr: Fill non-message tx data fields with 0x0 - spi: bcm-qspi: return error if neither hif_mspi nor mspi is available - Add MODULE_FIRMWARE for FIRMWARE_TG357766. - sctp: fix potential deadlock on amp;net-sctp.addr_wq_lock - rtc: st-lpc: Release some resources in st_rtc_probe in case of error - mfd: stmpe: Only disable the regulators if they are enabled - mfd: intel-lpss: Add missing check for platform_get_resource - mfd: rt5033: Drop rt5033-battery sub-device - usb: phy: phy-tahvo: fix memory leak in tahvo_usb_probe - extcon: Fix kernel doc of property capability fields to avoid warnings - extcon: Fix kernel doc of property fields to avoid warnings - media: usb: siano: Fix warning due to null work_func_t function pointer - media: videodev2.h: Fix struct v4l2_input tuner index comment - media: usb: Check az6007_read return value - sh: j2: Use ioremap to translate device tree address into kernel memory - w1: fix loop in w1_fini - block: change all __u32 annotations to __be32 in affs_hardblocks.h - USB: serial: option: add LARA-R6 01B PIDs - modpost: fix off by one in is_executable_section - modpost: fix section mismatch message for R_ARM_{PC24,CALL,JUMP24} - modpost: fix section mismatch message for R_ARM_ABS32 - crypto: nx - fix build warnings when DEBUG_FS is not enabled - pinctrl: at91-pio4: check return value of devm_kasprintf - perf dwarf-aux: Fix off-by-one in die_get_varname - pinctrl: cherryview: Return correct value if pin in push-pull mode - PCI: Add pci_clear_master stub for non-CONFIG_PCI - scsi: 3w-xxxx: Add error handling for initialization failure in tw_probe - ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer - drm/radeon: fix possible division-by-zero errors - fbdev: omapfb: lcd_mipid: Fix an error handling path in mipid_spi_probe - soc/fsl/qe: fix usb.c build errors - ASoC: es8316: Increment max value for ALC Capture Target Volume control - ARM: ep93xx: fix missing-prototype warnings - drm/panel: simple: fix active size for Ampire AM-480272H3TMQW-T01H - Input: adxl34x - do not hardcode interrupt trigger type - ARM: dts: BCM5301X: Drop clock-names from the SPI node - Input: drv260x - sleep between polling GO bit - radeon: avoid double free in ci_dpm_init - netlink: Add __sock_i_ino for __netlink_diag_dump. - netfilter: nf_conntrack_sip: fix the ct_sip_parse_numerical_param return value. - lib/ts_bm: reset initial match offset for every block of text - gtp: Fix use-after-free in __gtp_encap_destroy. - netlink: do not hard code device address lenth in fdb dumps - netlink: fix potential deadlock in netlink_set_err - wifi: ath9k: convert msecs to jiffies where needed - wifi: ath9k: Fix possible stall on ath9k_txq_list_has_key - memstick r592: make memstick_debug_get_tpc_name static - kexec: fix a memory leak in crash_shrink_memory - watchdog/perf: more properly prevent false positives with turbo modes - watchdog/perf: define dummy watchdog_update_hrtimer_threshold on correct config - wifi: ath9k: don"t allow to overwrite ENDPOINT0 attributes - wifi: ray_cs: Fix an error handling path in ray_probe - wifi: wl3501_cs: Fix an error handling path in wl3501_probe - wifi: atmel: Fix an error handling path in atmel_probe - wifi: orinoco: Fix an error handling path in orinoco_cs_probe - wifi: orinoco: Fix an error handling path in spectrum_cs_probe - wifi: ath9k: avoid referencing uninit memory in ath9k_wmi_ctrl_rx - wifi: ath9k: fix AR9003 mac hardware hang check register offset calculation - evm: Complete description of evm_inode_setattr - PM: domains: fix integer overflow issues in genpd_parse_state - md/raid10: fix io loss while replacement replace rdev - md/raid10: fix wrong setting of max_corr_read_errors - md/raid10: fix overflow of md/safe_mode_delay - treewide: Remove uninitialized_var usage - drm/amdgpu: Validate VM ioctl flags. - scripts/tags.sh: Resolve gtags empty index generation - drm/edid: Fix uninitialized variable in drm_cvt_modes - fbdev: imsttfb: Fix use after free bug in imsttfb_probe - x86/smp: Use dedicated cache-line for mwait_play_dead - x86/microcode/AMD: Load late on both threads too - gfs2: Don"t deref jdesc in evict - LTS version: v4.14.321 [4.14.35-2047.529.2.el7uek] - x86/cpu: persist X86_FEATURE_NT_GOOD for late reload [Orabug: 35693947] - uek-rpm: Disable cls_tcindex in file tcindex-disable.conf [Orabug: 35678739] - uek-rpm: Update kernel"s linux-firmware dependency. [Orabug: 35678693] - Revert sched/fair: sanitize vruntime of entity being placed [Orabug: 35651310] - Revert sched/fair: Sanitize vruntime of entity being migrated [Orabug: 35651310] - x86/microcode/AMD: Clean up per-family patch size checks [Orabug: 35643967] [4.14.35-2047.529.1.el7uek] - vc_screen: move load of struct vc_data pointer in vcs_read to avoid UAF [Orabug: 35649492] {CVE-2023-3567} - ocfs2: always read both high and low parts of dinode link count [Orabug: 35643004]

Platform:
Oracle Linux 7
Product:
kernel-uek
Reference:
ELSA-2023-12792
CVE-2023-3567
CVE    1
CVE-2023-3567

© SecPod Technologies