Linux Operating System (MOSC)

MOSC Banner

How to resolve ELSA-2023-13044 & CVE-2023-5178

edited Nov 19, 2024 10:42PM in Linux Operating System (MOSC) 3 commentsAnswered ✓

I need to resolve a vulnerability on a Linux OS (Oracle Linux Server release 7.9). I have these two yum packages installed which controls yum repos for updates:

oracle-release-el7.x86_64
oraclelinux-release-el7.x86_64

After all yum updates applied I'm still showing this kernel as containing a vulnerability:

kernel-uek-5.4.17-2136.315.5.el7uek

I need to upgrade to:

kernel-uek-5.4.17-2136.328.3.el7uek or later.

Is it safe to manually download and update to latest kernel from :

"https://yum.oracle.com/repo/OracleLinux/OL7/UEKR6/x86_64"

It looks like I can re-enable a disabled repo in yum.repos.d named:

uek-ol7.repo which would get the latest kernel-uek (5.4.17-2136.336.5.1.el7uek), but concerned about getting a stable version as this is a production server.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center