[Oraclevm-errata] OVMBA-2023-0002 Oracle VM 3 Extended Lifecycle Support (ELS) Unbreakable Enterprise kernel bug fix update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Sat Feb 18 03:12:11 UTC 2023


Oracle VM Bug Fix Advisory OVMBA-2023-0002

The following updated rpms for Oracle VM 3 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-4.1.12-124.71.3.1.el6uek.x86_64.rpm
kernel-uek-firmware-4.1.12-124.71.3.1.el6uek.noarch.rpm





Description of changes:

[4.1.12-124.71.3.1.el6uek]
- target: Invoke transport_lun_remove_cmd() to remove  tmr form the list (Gulam Mohamed)  [Orabug: 34812128]
- scsi: target: core: Remove from tmr_list during LUN  unlink (Gulam Mohamed)  [Orabug: 34812128]
- target: Inline transport_cmd_check_stop() (Gulam Mohamed)  [Orabug: 34812128]
- target: Stop execution if CMD_T_STOP has been set (Gulam Mohamed)  [Orabug: 34812128]

[4.1.12-124.71.3.el6uek]
- USB: core: Prevent nested device-reset calls (Alan Stern)  [Orabug: 34951641]  {CVE-2022-4662}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (Luiz Augusto von Dentz)  [Orabug: 34833307]  {CVE-2022-42896} {CVE-2022-42896}
- Bluetooth: L2CAP: Introduce proper defines for PSM ranges (Johan Hedberg)  [Orabug: 34833307]
- ext4: fix data corruption caused by overlapping unaligned and aligned IO (Lukas Czerner)  [Orabug: 34190035]

[4.1.12-124.71.2.el6uek]
- scsi: qla2xxx: Fix use after free in eh_abort path (Quinn Tran)  [Orabug: 34970763]
- check-kabi provides exception on broken symbols (Alok Tiwari)  [Orabug: 34742865]
- KABI validation broken on UEK4 for symbols change (Alok Tiwari)  [Orabug: 34742865]
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Maxim Mikityanskiy)  [Orabug: 34719829]  {CVE-2022-3564}
- Bluetooth: remove unneeded variable in l2cap_stream_rx (Prasanna Karthik)  [Orabug: 34719829]  {CVE-2022-3564}

[4.1.12-124.71.1.el6uek]
- Bluetooth: L2CAP: Fix attempting to access uninitialized memory (Luiz Augusto von Dentz)  [Orabug: 34951662]  {CVE-2022-42895} {CVE-2022-42895}
- wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker() (Dokyung Song)  [Orabug: 34951546]  {CVE-2022-3628}
- tcp/udp: Fix memory leak in ipv6_renew_options(). (Kuniyuki Iwashima)  [Orabug: 34719347]  {CVE-2022-3524}




More information about the Oraclevm-errata mailing list