Oracle Linux Security Advisory ELSA-2023-12835

https://linux.oracle.com/errata/ELSA-2023-12835.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
ivshmem-tools-4.2.1-28.el7.aarch64.rpm
qemu-4.2.1-28.el7.aarch64.rpm
qemu-block-gluster-4.2.1-28.el7.aarch64.rpm
qemu-block-iscsi-4.2.1-28.el7.aarch64.rpm
qemu-block-rbd-4.2.1-28.el7.aarch64.rpm
qemu-common-4.2.1-28.el7.aarch64.rpm
qemu-img-4.2.1-28.el7.aarch64.rpm
qemu-kvm-4.2.1-28.el7.aarch64.rpm
qemu-kvm-core-4.2.1-28.el7.aarch64.rpm
qemu-system-aarch64-4.2.1-28.el7.aarch64.rpm
qemu-system-aarch64-core-4.2.1-28.el7.aarch64.rpm


SRPMS:
https://oss.oracle.com:443/ol7/SRPMS-updates//qemu-4.2.1-28.el7.src.rpm

Related CVEs:

CVE-2023-0330
CVE-2023-3180
CVE-2023-3301




Description of changes:

[15:4.2.1-28.el7]
- virtio-crypto: verify src&dst buffer length for sym request (Zhenwei Pi)  [Orabug: 35724113]  {CVE-2023-3180}
- hw/scsi/lsi53c895a: Fix reentrancy issues in the LSI controller (CVE-2023-0330) (Thomas Huth)  [Orabug: 35724112]  {CVE-2023-0330}
- kvm: Atomic memslot updates (David Hildenbrand)  [Orabug: 35719844]
- KVM: keep track of running ioctls (Emanuele Giuseppe Esposito)  [Orabug: 35719844]
- accel: introduce accelerator blocker API (Emanuele Giuseppe Esposito)  [Orabug: 35719844]
- KVM: Use a big lock to replace per-kml slots_lock (Peter Xu)  [Orabug: 35719844]
- pcie: don't set link state active if the slot is empty (Laurent Vivier)  [Orabug: 35707933]
- vhost-vdpa: do not cleanup the vdpa/vhost-net structures if peer nic is present (Ani Sinha)  [Orabug: 35662850]  {CVE-2023-3301}


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle7: ELSA-2023-12835: qemu security Moderate (aarch64) Security Update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[15:4.2.1-28.el7] - virtio-crypto: verify src&dst buffer length for sym request (Zhenwei Pi) [Orabug: 35724113] {CVE-2023-3180} - hw/scsi/lsi53c895a: Fix reentrancy issues in the LSI controller (CVE-2023-0330) (Thomas Huth) [Orabug: 35724112] {CVE-2023-0330} - kvm: Atomic memslot updates (David Hildenbrand) [Orabug: 35719844] - KVM: keep track of running ioctls (Emanuele Giuseppe Esposito) [Orabug: 35719844] - accel: introduce accelerator blocker API (Emanuele Giuseppe Esposito) [Orabug: 35719844] - KVM: Use a big lock to replace per-kml slots_lock (Peter Xu) [Orabug: 35719844] - pcie: don't set link state active if the slot is empty (Laurent Vivier) [Orabug: 35707933] - vhost-vdpa: do not cleanup the vdpa/vhost-net structures if peer nic is present (Ani Sinha) [Orabug: 35662850] {CVE-2023-3301}

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates//qemu-4.2.1-28.el7.src.rpm

x86_64

aarch64

ivshmem-tools-4.2.1-28.el7.aarch64.rpm qemu-4.2.1-28.el7.aarch64.rpm qemu-block-gluster-4.2.1-28.el7.aarch64.rpm qemu-block-iscsi-4.2.1-28.el7.aarch64.rpm qemu-block-rbd-4.2.1-28.el7.aarch64.rpm qemu-common-4.2.1-28.el7.aarch64.rpm qemu-img-4.2.1-28.el7.aarch64.rpm qemu-kvm-4.2.1-28.el7.aarch64.rpm qemu-kvm-core-4.2.1-28.el7.aarch64.rpm qemu-system-aarch64-4.2.1-28.el7.aarch64.rpm qemu-system-aarch64-core-4.2.1-28.el7.aarch64.rpm

i386

Severity
Related CVEs: CVE-2023-0330 CVE-2023-3180 CVE-2023-3301

Related News