Oracle Linux Security Advisory ELSA-2024-1959

http://linux.oracle.com/errata/ELSA-2024-1959.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
mokutil-15.8-1.0.3.el7.x86_64.rpm
shim-unsigned-x64-15.8-2.0.3.el7.x86_64.rpm
shim-x64-15.8-1.0.3.el7.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//shim-15.8-2.0.3.el7.src.rpm
http://oss.oracle.com/ol7/SRPMS-updates//shim-signed-15.8-1.0.3.el7.src.rpm

Related CVEs:

CVE-2023-40546
CVE-2023-40547
CVE-2023-40548
CVE-2023-40549
CVE-2023-40550
CVE-2023-40551




Description of changes:

shim
[- 15.8-2.0.3.el7]
- Set shim.ol sbat generation to 3 [Orabug: 36271343]

[- 15.8-2.0.1.el7]
- Set SBAT_AUTOMATIC_DATE to 2021030218 [Orabug: 36271343]
- Rebuild with Oracle certificates [Orabug: 36271343]
- Full list of fixed CVEs: CVE-2023-40546, CVE-2023-40547,
  CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551 [Orabug: 36271343]

[15.8-2.el7]
- Rebuild to fix the commit ident and MAKEFLAGS
  Resolves: RHEL-11254

[15.8-1.el7]
- Update to shim-15.8 for CVE-2023-40547
  Resolves: RHEL-11254

shim-signed
[15.8-1.0.3]
- Update shimx64.efi signed by Microsoft [Orabug: 36271343]

[15.8-1.0.1]
- Set shim.ol sbat generation to 3 [Orabug: 36271343]
- Set SBAT_AUTOMATIC_DATE to 2021030218 [Orabug: 36271343]
- Rebuild with Oracle certificates [Orabug: 36271343]
- Full list of fixed CVEs: CVE-2023-40546, CVE-2023-40547,
  CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551 [Orabug: 36271343]
- Disable ia32 build [Orabug: 36271343]


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle7: ELSA-2024-1959: shim security Important Security Advisory Updates

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

shim [- 15.8-2.0.3.el7] - Set shim.ol sbat generation to 3 [Orabug: 36271343] [- 15.8-2.0.1.el7] - Set SBAT_AUTOMATIC_DATE to 2021030218 [Orabug: 36271343] - Rebuild with Oracle certificates [Orabug: 36271343] - Full list of fixed CVEs: CVE-2023-40546, CVE-2023-40547, CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551 [Orabug: 36271343] [15.8-2.el7] - Rebuild to fix the commit ident and MAKEFLAGS Resolves: RHEL-11254 [15.8-1.el7] - Update to shim-15.8 for CVE-2023-40547 Resolves: RHEL-11254 shim-signed [15.8-1.0.3] - Update shimx64.efi signed by Microsoft [Orabug: 36271343] [15.8-1.0.1] - Set shim.ol sbat generation to 3 [Orabug: 36271343] - Set SBAT_AUTOMATIC_DATE to 2021030218 [Orabug: 36271343] - Rebuild with Oracle certificates [Orabug: 36271343] - Full list of fixed CVEs: CVE-2023-40546, CVE-2023-40547, CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551 [Orabug: 36271343] - Disable ia32 build [Orabug: 36271343]

SRPMs

http://oss.oracle.com/ol7/SRPMS-updates//shim-15.8-2.0.3.el7.src.rpm http://oss.oracle.com/ol7/SRPMS-updates//shim-signed-15.8-1.0.3.el7.src.rpm

x86_64

mokutil-15.8-1.0.3.el7.x86_64.rpm shim-unsigned-x64-15.8-2.0.3.el7.x86_64.rpm shim-x64-15.8-1.0.3.el7.x86_64.rpm

aarch64

i386

Severity
Related CVEs: CVE-2023-40546 CVE-2023-40547 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551

Related News