{
  "cves": [
    "CVE-2021-4155",
    "CVE-2022-0185"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[4.18.0-348.12.2_5.OL8]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15-11.0.5\n\n[4.18.0-348.12.2_5]\n- vfs: Out-of-bounds write of heap buffer in fs_context.c (Frantisek Hrbata) [2040585 2040586] {CVE-2022-0185}\n- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Bruno Meneguele) [2034864 2034865] {CVE-2021-4155}\n\n[4.18.0-348.12.1_5]\n- tcp: don't free a FIN sk_buff in tcp_remove_empty_skb() (Guillaume Nault) [2021574 2016210]\n- kernel.spec: Add support to use vmlinux.h (Jiri Olsa) [2031053 1989087]\n- spec: Add vmlinux.h to kernel-devel package (Jiri Olsa) [2031053 1989087]\n- x86/mce: Avoid infinite loop for copy from user recovery (Prarit Bhargava) [2008789 1999550]\n- x86/mce: Rename kill_it to kill_current_task (Prarit Bhargava) [2008789 1999550]\n- x86/mce: Recover from poison found while copying from user space (Prarit Bhargava) [2008789 1999550]\n- x86/mce: Delay clearing IA32_MCG_STATUS to the end of do_machine_check() (Prarit Bhargava) [2008789 1999550]\n- x86/mce: Send #MC singal from task work (Prarit Bhargava) [2008789 1999550]\n\n[4.18.0-348.11.1_5]\n- blk-mq: avoid to iterate over stale request (Ming Lei) [2034396 1997338]\n- rcu: Tighten rcu_advance_cbs_nowake() checks (Daniel Vacek) [2032579 2013408]\n\n[4.18.0-348.10.1_5]\n- selftests: add a test case for mirred egress to ingress (Xin Long) [2024411 1983894]\n- net: sched: act_mirred: drop dst for the direction from egress to ingress (Xin Long) [2024411 1983894]\n\n[4.18.0-348.9.1_5]\n- ixgbe: Revert 'bpf, devmap: Move drop error path to devmap for XDP_REDIRECT' (Ken Cox) [2029845 2024240]\n- i40e: Revert 'bpf, devmap: Move drop error path to devmap for XDP_REDIRECT' (Stefan Assmann) [2029845 2024225]\n- rcu/nocb: Perform deferred wake up before last idle's need_resched() check (Waiman Long) [2029449 2008340]\n\n[4.18.0-348.8.1_5]\n- ice: Fix VF true promiscuous mode (Jonathan Toppins) [2026698 1970643]\n- ice: Remove toggling of antispoof for VF trusted promiscuous mode (Jonathan Toppins) [2026698 1970643]\n- ice: Fix replacing VF hardware MAC to existing MAC filter (Jonathan Toppins) [2026698 1970643]\n- ice: Fix not stopping Tx queues for VFs (Jonathan Toppins) [2026698 1970643]\n- ice: Fix race conditions between virtchnl handling and VF ndo ops (Jonathan Toppins) [2026698 1970643]\n- net/netif_receive_skb_core: Use migrate_disable() (Luis Claudio R. Goncalves) [2027689 2024168]\n- crypto: jitter - consider 32 LSB for APT (Herbert Xu) [2029365 1994390]\n- xfs: fix I_DONTCACHE (Carlos Maiolino) [2028534 2024969]",
  "id": "ELSA-2022-0188",
  "ovalId": "oval:com.oracle.elsa:def:20220188",
  "source": "oracle_linux",
  "title": "ELSA-2022-0188:  kernel security and bug fix update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2022-0188.html"
}