Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-13028

Опубликовано: 07 дек. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-13028: olcne security update (IMPORTANT)

conmon [2.1.3-7]

  • Resolve CVE-2023-39325

[2.1.3-6]

  • Add ol8_baseos_latest, and ol9_baseos_latest, to Jenkinsfile

[2.1.3-5]

  • Add systemd-devel as build requirement

[2.1.3-4]

  • Add support ARM build

[2.1.3.3]

  • Add OL9 support

[2.1.3.2]

  • Update inline with Linux team building conmon for all but OL7.

cri-o [1.25.2-3]

  • Resolve CVE-2023-39325

cri-tools [1.25.0-2]

  • Resolve CVE-2023-39325

etcd [3.5.9-2]

  • Bump up version

[3.5.9-1]

  • Added Oracle specific build files

flannel-cni-plugin [1.0.1-3]

  • Resolve CVE-2023-44487 and CVE-2023-39325

helm [3.11.1-2]

  • address CVE-2023-44487 and CVE-2023-39325

istio kata [1.12.1-14]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-13]

  • Rebuild kata to fix timestamp issue

[1.12.1-12]

  • Add support for ARM build

[1.12.1-11]

  • Add OL9 support

[1.12.1-10]

  • Updated kata-runtime version to work with more versions of kvm_utils

kata-agent [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Remove build_date global variable in kata-image specfile

[1.12.1-7]

  • Add support for ARM build

[1.12.1-6]

  • Add OL9 support

kata-image [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Remove build_date global variable in specfile

[1.12.1-7]

  • Add support for ARM build

[1.12.1-6]

  • Restore OL7 and bump release

[1.12.1-5]

  • Add support for Oracle Linux 9

[1.12.1-4]

  • build for kata-agent-1.12.1-4

kata-ksm-throttler [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

[1.12.1-6]

  • Bump releaase inline with others for reversion of removal of OL7.

[1.12.1-5]

  • Add support for Oracle Linux 9

kata-proxy [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

[1.12.1-6]

  • Revert OL7 removal

[1.12.1-5]

  • Add support for Oracle Linux 9

kata-runtime [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

[1.12.1-6]

  • Add OL9 support

[1.12.1-5]

  • Updated qemu-kvm machine options to work with more versions of kvm_utils

kata-shim [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

[1.12.1-6]

  • Bump releaase inline with others for reversion of removal of OL7.

[1.12.1-5]

  • Add support for Oracle Linux 9

kubernetes kubernetes-cni [1.0.1-3]

  • Resolve CVE-2023-44487 and CVE-2023-39325

kubernetes-cni-plugins [1.0.1-4]

  • Resolve CVE-2023-44487 and CVE-2023-39325

olcne [1.6.5-9]

  • Mark container-registry as updatable

[1.6.5-9]

  • update metallb 0.12.1 to address CVE-2023-44487 and CVE-2023-39325

[1.6.5-8]

  • Update externalip-webhook 1.0.0-3 to address CVE-2023-44487, CVE-2023-39325

[1.6.5-7]

  • Update multus-cni 3.9.3 to address CVE-2023-44487 and CVE-2023-39325

[1.6.5-6]

  • Update rook-1.10.9 to address CVE-2023-44487, CVE-2023-39325

[1.6.5-5]

  • Update Istio, Grafana, Prometheus, and Kubernetes-dashboard to address CVE's
  • CVE-2023-44487
  • CVE-2023-39325

[1.6.5-4]

  • Update kubernetes and components to address golang CVE-2023-44487, CVE-2023-39325

[1.6.5-3]

  • update configmap-registry to 1.28.0 to address CVE-2023-44487 and CVE-2023-39325

[1.6.5-2]

  • Update kubevirt 0.58.0 to address CVE-2023-44487 and CVE-2023-39325

[1.6.5-1]

  • Update calico image versions to address golang CVE-2023-44487, CVE-2023-39325

yq [4.34.1-3]

  • address CVE-2023-44487 and CVE-2023-3932A

[4.34.1-2]

  • Add support for ARM build

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

yq

4.34.1-3.el8

Oracle Linux x86_64

conmon

2.1.3-7.el8

cri-o

1.25.2-3.el8

cri-tools

1.25.0-2.el8

etcd

3.5.9-2.el8

flannel-cni-plugin

1.0.1-3.el8

helm

3.11.1-2.el8

istio

1.16.7-2.el8

istio-istioctl

1.16.7-2.el8

kata

1.12.1-14.el8

kata-agent

1.12.1-9.el8

kata-image

1.12.1-9.9.ol8_202311161805

kata-ksm-throttler

1.12.1-9.el8

kata-proxy

1.12.1-9.el8

kata-runtime

1.12.1-9.el8

kata-shim

1.12.1-9.el8

kubeadm

1.25.15-1.el8

kubectl

1.25.15-1.el8

kubelet

1.25.15-1.el8

kubernetes-cni

1.0.1-3.el8

kubernetes-cni-plugins

1.0.1-4.el8

olcne-agent

1.6.5-10.el8

olcne-api-server

1.6.5-10.el8

olcne-calico-chart

1.6.5-10.el8

olcne-gluster-chart

1.6.5-10.el8

olcne-grafana-chart

1.6.5-10.el8

olcne-istio-chart

1.6.5-10.el8

olcne-metallb-chart

1.6.5-10.el8

olcne-multus-chart

1.6.5-10.el8

olcne-nginx

1.6.5-10.el8

olcne-oci-ccm-chart

1.6.5-10.el8

olcne-olm-chart

1.6.5-10.el8

olcne-prometheus-chart

1.6.5-10.el8

olcne-utils

1.6.5-10.el8

olcnectl

1.6.5-10.el8

yq

4.34.1-3.el8

Связанные CVE

Связанные уязвимости

suse-cvrf
больше 1 года назад

Security update for go1.21

suse-cvrf
больше 1 года назад

Security update for go1.20

rocky
больше 1 года назад

Moderate: toolbox security update

rocky
больше 1 года назад

Moderate: grafana security update

oracle-oval
больше 1 года назад

ELSA-2023-5867: grafana security update (MODERATE)

Уязвимость ELSA-2023-13028