Oracle Linux 6268 Published by

The following kernel updates has been released for Oracle Linux:

ELSA-2019-4531 Important: Oracle Linux 6 Unbreakable Enterprise kernel security update
ELSA-2019-4531 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update



ELSA-2019-4531 Important: Oracle Linux 6 Unbreakable Enterprise kernel security update

Oracle Linux Security Advisory ELSA-2019-4531

http://linux.oracle.com/errata/ELSA-2019-4531.html

The following updated rpms for Oracle Linux 6 have been uploaded to the
Unbreakable Linux Network:

x86_64:
kernel-uek-doc-4.1.12-124.25.1.el6uek.noarch.rpm
kernel-uek-firmware-4.1.12-124.25.1.el6uek.noarch.rpm
kernel-uek-4.1.12-124.25.1.el6uek.x86_64.rpm
kernel-uek-devel-4.1.12-124.25.1.el6uek.x86_64.rpm
kernel-uek-debug-4.1.12-124.25.1.el6uek.x86_64.rpm
kernel-uek-debug-devel-4.1.12-124.25.1.el6uek.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/kernel-uek-4.1.12-124.25.1.el6uek.src.rpm



Description of changes:

[4.1.12-124.25.1.el6uek]
- x86/bugs: Fix the AMD SSBD usage of the SPEC_CTRL MSR (Tom Lendacky)
[Orabug: 28870524] {CVE-2018-3639}
- x86/bugs: Add AMD's SPEC_CTRL MSR usage (Konrad Rzeszutek Wilk)
[Orabug: 28870524] {CVE-2018-3639}
- x86/cpufeatures: rename X86_FEATURE_AMD_SSBD to
X86_FEATURE_LS_CFG_SSBD (Mihai Carabas) [Orabug: 28870524] {CVE-2018-3639}
- Make file credentials available to the seqfile interfaces (Linus
Torvalds) [Orabug: 29114879] {CVE-2018-17972}
- proc: restrict kernel stack dumps to root (Jann Horn) [Orabug:
29114879] {CVE-2018-17972}
- x86/speculation: Clean up retpoline code in bugs.c (Alejandro Jimenez)
[Orabug: 29211617] - x86, modpost: Replace last remnants of RETPOLINE
with CONFIG_RETPOLINE (WANG Chao) [Orabug: 29211617] - x86/build: Fix
compiler support check for CONFIG_RETPOLINE (Masahiro Yamada) [Orabug:
29211617] - x86/retpoline: Remove minimal retpoline support (Zhenzhong
Duan) [Orabug: 29211617] - x86/retpoline: Make CONFIG_RETPOLINE depend
on compiler support (Zhenzhong Duan) [Orabug: 29211617] - nl80211: check
for the required netlink attributes presence (Vladis Dronov) [Orabug:
29245533] {CVE-2017-12153} {CVE-2017-12153}
- scsi: lpfc: Fix PT2PT PRLI reject (reapply patch) (James Smart)
[Orabug: 29281346]

ELSA-2019-4531 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update

Oracle Linux Security Advisory ELSA-2019-4531

http://linux.oracle.com/errata/ELSA-2019-4531.html

The following updated rpms for Oracle Linux 7 have been uploaded to the
Unbreakable Linux Network:

x86_64:
kernel-uek-doc-4.1.12-124.25.1.el7uek.noarch.rpm
kernel-uek-firmware-4.1.12-124.25.1.el7uek.noarch.rpm
kernel-uek-4.1.12-124.25.1.el7uek.x86_64.rpm
kernel-uek-devel-4.1.12-124.25.1.el7uek.x86_64.rpm
kernel-uek-debug-4.1.12-124.25.1.el7uek.x86_64.rpm
kernel-uek-debug-devel-4.1.12-124.25.1.el7uek.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-4.1.12-124.25.1.el7uek.src.rpm



Description of changes:

[4.1.12-124.25.1.el7uek]
- x86/bugs: Fix the AMD SSBD usage of the SPEC_CTRL MSR (Tom Lendacky)
[Orabug: 28870524] {CVE-2018-3639}
- x86/bugs: Add AMD's SPEC_CTRL MSR usage (Konrad Rzeszutek Wilk)
[Orabug: 28870524] {CVE-2018-3639}
- x86/cpufeatures: rename X86_FEATURE_AMD_SSBD to
X86_FEATURE_LS_CFG_SSBD (Mihai Carabas) [Orabug: 28870524] {CVE-2018-3639}
- Make file credentials available to the seqfile interfaces (Linus
Torvalds) [Orabug: 29114879] {CVE-2018-17972}
- proc: restrict kernel stack dumps to root (Jann Horn) [Orabug:
29114879] {CVE-2018-17972}
- x86/speculation: Clean up retpoline code in bugs.c (Alejandro Jimenez)
[Orabug: 29211617] - x86, modpost: Replace last remnants of RETPOLINE
with CONFIG_RETPOLINE (WANG Chao) [Orabug: 29211617] - x86/build: Fix
compiler support check for CONFIG_RETPOLINE (Masahiro Yamada) [Orabug:
29211617] - x86/retpoline: Remove minimal retpoline support (Zhenzhong
Duan) [Orabug: 29211617] - x86/retpoline: Make CONFIG_RETPOLINE depend
on compiler support (Zhenzhong Duan) [Orabug: 29211617] - nl80211: check
for the required netlink attributes presence (Vladis Dronov) [Orabug:
29245533] {CVE-2017-12153} {CVE-2017-12153}
- scsi: lpfc: Fix PT2PT PRLI reject (reapply patch) (James Smart)
[Orabug: 29281346]