Oracle Linux 6167 Published by

An Oracle Linux Cloud Native Environment 1.0 Unbreakable Enterprise kernel-container security update has been released.



El-errata: ELSA-2021-9039 Important: Oracle Linux Cloud Native Environment 1.0 Unbreakable Enterprise kernel-container security update


Oracle Linux Cloud Native Environment Security Advisory ELSA-2021-9039

  http://linux.oracle.com/errata/ELSA-2021-9039.html

The following updated rpms for Oracle Linux Cloud Native Environment 1.0
have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-container-4.14.35-2025.405.3.el7.x86_64.rpm

SRPMS:
  http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-container-4.14.35-2025.405.3.el7.src.rpm


Description of changes:

[4.14.35-2025.405.3.el7]
- Revert "rds: Deregister all FRWR mr with free_mr" (aru kolappan) [Orabug:
32426280]

[4.14.35-2025.405.2.el7]
- nfs: Fix security label length not being reset (Jeffrey Mitchell) [Orabug:
32350995]

[4.14.35-2025.405.1.el7]
- net/rds: Fix gfp_t parameter (Hans Westgaard Ry) [Orabug: 32372162]
- uek-rpm: update kABI lists for new symbol (Dan Duval) [Orabug: 32378208]
- sysctl: handle overflow in proc_get_long (Christian Brauner) [Orabug:
32382641]
- net/mlx5: Use a single MSIX vector for all control EQs in VFs (Ariel
Levkovich) [Orabug: 31785275]
- net/mlx5: Fix available EQs FW used to reserve (Denis Drozdov)
[Orabug: 31785275]
- net/mlx5: Use max_num_eqs for calculation of required MSIX vectors
(Denis Drozdov) [Orabug: 31785275]
- net/mlx5: Expose DEVX specification (Yishai Hadas) [Orabug: 31785275]
- x86/process: Mark cpu inactive before offlining (Mridula Shastry)
[Orabug: 32245085]
- target: fix XCOPY NAA identifier lookup (David Disseldorp) [Orabug:
32248040] {CVE-2020-28374}

[4.14.35-2025.405.0.el7]
- KVM: x86: clflushopt should be treated as a no-op by emulation (David
Edmondson) [Orabug: 32251913]
- tty: Fix ->session locking (Jann Horn) [Orabug: 32266681] {CVE-2020-29660}
- tty: Fix ->pgrp locking in tiocspgrp() (Jann Horn) [Orabug: 32266681]
{CVE-2020-29660}
- lockd: don't use interval-based rebinding over TCP (Calum Mackay)
[Orabug: 32337718]
- mwifiex: Fix possible buffer overflows in
mwifiex_cmd_802_11_ad_hoc_start (Zhang Xiaohui) [Orabug: 32349207]
{CVE-2020-36158}
- add license checking to kABI checker (Dan Duval) [Orabug: 32355210]