Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-13054

Опубликовано: 19 дек. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-13054: conmon security update (IMPORTANT)

conmon [2.1.3-7]

  • Resolve CVE-2023-39325

[2.1.3-6]

  • Add ol8_baseos_latest, and ol9_baseos_latest, to Jenkinsfile

[2.1.3-5]

  • Add systemd-devel as build requirement

[2.1.3-4]

  • Add support ARM build

cri-o [1.26.3-3]

  • Resolve CVE-2023-39325

[1.26.3-2]

  • Add support for ARM build

cri-tools [1.26.1-3]

  • Resolve CVE-2023-39325

[1.26.1-2]

  • Add ARM build support

etcd [3.5.9-2]

  • Bump up version

[3.5.9-1]

  • Added Oracle specific build files

flannel-cni-plugin [1.1.2-3]

  • Resolve CVE-2023-44487 and CVE-2023-39325

[1.1.2-2]

  • Add ARM build support

helm [3.12.0-3]

  • address CVE-2023-44487 and CVE-2023-39325

[-]

  • Add support for ARM build

istio [1.17.8-1]

  • Added Oracle specific files for 1.17.8-1

kata [1.12.1-14]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-13]

  • Rebuild kata to fix timestamp issue

[1.12.1-12]

  • Add support for ARM build

kata-agent [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Remove build_date global variable in kata-image specfile

[1.12.1-7]

  • Add support for ARM build

kata-image [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Remove build_date global variable in specfile

[1.12.1-7]

  • Add support for ARM build

kata-ksm-throttler [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

kata-proxy [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

kata-runtime [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

kata-shim [1.12.1-9]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

[1.12.1-8]

  • Bump release inline with other kata packages for fixing timestamp issue

[1.12.1-7]

  • Add support for ARM build

kubernetes [1.26.10-2]

  • Allow dashes DNS image

[1.26.10-1]

  • Added Oracle specific build files for Kubernetes

kubernetes-cni [1.1.2-3]

  • Resolve CVE-2023-44487 and CVE-2023-39325

[1.1.2-2]

  • Add support for ARM build

kubernetes-cni-plugins [1.2.0-4]

  • Fix go.mod

[1.2.0-3]

  • Resolve CVE-2023-44487 and CVE-2023-39325

[1.2.0-2]

  • Add support for ARM build

kubevirt [0.58.0-4]

  • Updated to address CVE-2023-44487 and CVE-2023-39325

olcne [1.7.5-17]

  • Fix update issue from 1.6.x -> 1.7.5

[1.7.5-16]

  • Pass imagetag to the metallb tool that converts configmap to crs

[1.7.5-15]

  • Fix metallb upgrade failure when proxy is needed

[1.7.5-14]

  • Update conmon to 2.1.3-7 in scripts

[1.7.5-13]

  • Update module-operator to address CVE-2023-44487, CVE-2023-39325

[1.7.5-12]

  • Update multus-cni 3.9.3 to address CVE-2023-44487 and CVE-2023-39325

[1.7.5-11]

  • Update multus-cni 4.0.1 to address CVE-2023-44487 and CVE-2023-39325

[1.7.5-10]

  • Update metallb 0.13.9 to address CVE-2023-44487 and CVE-2023-39325

[1.7.5-9]

  • Update externalip-webhook 1.0.0 to address CVE-2023-44487 and CVE-2023-39325

[1.7.5-8]

  • Update calico-3.25.0 and 3.25.1 to address CVE-2023-44487, CVE-2023-39325

[1.7.5-7]

  • Update rook-1.10.9 and 1.11.6 to address golang CVE-2023-44487, CVE-2023-39325

[1.7.5-6]

  • update configmap-registry to 1.28.0 and update olm 0.23.1 to address CVE-2023-44487 and CVE-2023-39325

[1.7.5-5]

  • Update Istio, Grafana, Prometheus, and Kubernetes-dashboard to address CVE's
  • CVE-2023-44487
  • CVE-2023-39325

[1.7.5-4]

  • update helm 3.12.0 to Address CVE-2023-44487 and CVE-2023-39325

[1.7.5-3]

  • Update kubernetes and components to address golang CVE-2023-44487, CVE-2023-39325

[1.7.5-2]

  • Add olm 0.23.1 charts

[1.7.5-1]

  • Update kubevirt 0.58.0 to address CVE-2023-44487 and CVE-2023-39325

yq [4.34.1-3]

  • address CVE-2023-44487 and CVE-2023-3932A

[4.34.1-2]

  • Add support for ARM build

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

yq

4.34.1-3.el8

Oracle Linux x86_64

conmon

2.1.3-7.el8

cri-o

1.26.3-3.el8

cri-tools

1.26.1-3.el8

etcd

3.5.9-2.el8

flannel-cni-plugin

1.1.2-3.el8

helm

3.12.0-3.el8

istio

1.17.8-1.el8

istio-istioctl

1.17.8-1.el8

kata

1.12.1-14.el8

kata-agent

1.12.1-9.el8

kata-image

1.12.1-9.9.ol8_202311161805

kata-ksm-throttler

1.12.1-9.el8

kata-proxy

1.12.1-9.el8

kata-runtime

1.12.1-9.el8

kata-shim

1.12.1-9.el8

kubeadm

1.26.10-2.el8

kubectl

1.26.10-2.el8

kubelet

1.26.10-2.el8

kubernetes-cni

1.1.2-3.el8

kubernetes-cni-plugins

1.2.0-4.el8

olcne-agent

1.7.5-17.el8

olcne-api-server

1.7.5-17.el8

olcne-calico-chart

1.7.5-17.el8

olcne-gluster-chart

1.7.5-17.el8

olcne-grafana-chart

1.7.5-17.el8

olcne-istio-chart

1.7.5-17.el8

olcne-kubevirt-chart

1.7.5-17.el8

olcne-metallb-chart

1.7.5-17.el8

olcne-multus-chart

1.7.5-17.el8

olcne-nginx

1.7.5-17.el8

olcne-oci-ccm-chart

1.7.5-17.el8

olcne-olm-chart

1.7.5-17.el8

olcne-prometheus-chart

1.7.5-17.el8

olcne-rook-chart

1.7.5-17.el8

olcne-utils

1.7.5-17.el8

olcnectl

1.7.5-17.el8

virtctl

0.58.0-4.el8

yq

4.34.1-3.el8

Связанные CVE

Связанные уязвимости

suse-cvrf
больше 1 года назад

Security update for go1.21

suse-cvrf
больше 1 года назад

Security update for go1.20

rocky
больше 1 года назад

Moderate: toolbox security update

rocky
больше 1 года назад

Moderate: grafana security update

oracle-oval
больше 1 года назад

ELSA-2023-5867: grafana security update (MODERATE)

Уязвимость ELSA-2023-13054