Oracle Linux 6240 Published by

Oracle Linux has received two security updates: ELSA-2024-6997, a kernel security update, and ELSA-2024-7136, a git/lfs security upgrade:

ELSA-2024-6997 Important: Oracle Linux 9 kernel security update
ELSA-2024-7136 Important: Oracle Linux 9 git-lfs security update




ELSA-2024-6997 Important: Oracle Linux 9 kernel security update


Oracle Linux Security Advisory ELSA-2024-6997

http://linux.oracle.com/errata/ELSA-2024-6997.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-7.3.0-427.37.1.el9_4.x86_64.rpm
kernel-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-abi-stablelists-5.14.0-427.37.1.el9_4.noarch.rpm
kernel-core-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-cross-headers-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-core-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-devel-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-devel-matched-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-modules-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-modules-core-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-modules-extra-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-debug-uki-virt-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-devel-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-devel-matched-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-doc-5.14.0-427.37.1.el9_4.noarch.rpm
kernel-headers-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-modules-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-modules-core-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-modules-extra-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-tools-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-tools-libs-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-tools-libs-devel-5.14.0-427.37.1.el9_4.x86_64.rpm
kernel-uki-virt-5.14.0-427.37.1.el9_4.x86_64.rpm
libperf-5.14.0-427.37.1.el9_4.x86_64.rpm
perf-5.14.0-427.37.1.el9_4.x86_64.rpm
python3-perf-5.14.0-427.37.1.el9_4.x86_64.rpm
rtla-5.14.0-427.37.1.el9_4.x86_64.rpm
rv-5.14.0-427.37.1.el9_4.x86_64.rpm

aarch64:
bpftool-7.3.0-427.37.1.el9_4.aarch64.rpm
kernel-cross-headers-5.14.0-427.37.1.el9_4.aarch64.rpm
kernel-headers-5.14.0-427.37.1.el9_4.aarch64.rpm
kernel-tools-5.14.0-427.37.1.el9_4.aarch64.rpm
kernel-tools-libs-5.14.0-427.37.1.el9_4.aarch64.rpm
kernel-tools-libs-devel-5.14.0-427.37.1.el9_4.aarch64.rpm
perf-5.14.0-427.37.1.el9_4.aarch64.rpm
python3-perf-5.14.0-427.37.1.el9_4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//kernel-5.14.0-427.37.1.el9_4.src.rpm

Related CVEs:

CVE-2023-52439
CVE-2023-52884
CVE-2024-26739
CVE-2024-26929
CVE-2024-26930
CVE-2024-26931
CVE-2024-26947
CVE-2024-26991
CVE-2024-27022
CVE-2024-35895
CVE-2024-36016
CVE-2024-36899
CVE-2024-38562
CVE-2024-38570
CVE-2024-38573
CVE-2024-38601
CVE-2024-38615
CVE-2024-40984
CVE-2024-41071
CVE-2024-42225
CVE-2024-42246

Description of changes:

[5.14.0-427.37.1.el9_4.OL9]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64