Oracle Linux Security Advisory ELSA-2023-13027

https://linux.oracle.com/errata/ELSA-2023-13027.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
AAVMF-1.6.6-1.el7.noarch.rpm


SRPMS:
https://oss.oracle.com:443/ol7/SRPMS-updates//edk2-1.6.6-1.el7.src.rpm

Related CVEs:

CVE-2023-0286
CVE-2023-0215
CVE-2022-4304
CVE-2022-4450




Description of changes:

* Mon Aug 21 2023 Aaron Young 
- Create new 1.6.6 release for OL7 which includes the following fixed CVEs:
  {CVE-2019-14560}
- Update to OpenSSL 1.1.1v which includes the following fixed CVEs:
  {CVE-2023-3817} {CVE-2023-3446} {CVE-2023-2650} {CVE-2023-0465} {CVE-2023-0466} {CVE-2023-0464} {CVE-2023-0286} {CVE-2023-0215} {CVE-2022-4450} {CVE-2022-4304} {CVE-2022-2097} {CVE-2022-2068} {CVE-2022-1292} {CVE-2022-0778} {CVE-2021-4160} {CVE-2021-3712} {CVE-2021-3711} {CVE-2021-3450} {CVE-2021-3449} {CVE-2021-23841} {CVE-2021-23840} {CVE-2020-1971} {CVE-2020-1967} {CVE-2019-1551} {CVE-2019-1563} {CVE-2019-1549} {CVE-2019-1547} {CVE-2019-1552} {CVE-2019-1543} {CVE-2018-0734} {CVE-2018-0735}

* Tue Jun 13 2023 Aaron Young 
- Create new 1.6.5.cvm release for OL7

* Mon Feb 27 2023 Aaron Young 
- Create new 1.6.4.cvm release for OL7 which includes the following fixed CVEs:
  {CVE-2021-38578}

* Tue Jun 28 2022 Aaron Young 
- Create new 1.6.3 release for OL7

* Wed Jun 01 2022 Aaron Young 
- Create new 1.6.2 release for OL7

* Wed May 11 2022 Aaron Young 
- Create new 1.6.1 release for OL7

* Wed Apr 06 2022 Aaron Young 
- Create new 1.6.0 release for OL7 which includes the following fixed CVEs:
  {CVE-2022-0778}

* Tue Nov 23 2021 Aaron Young 
- Create new 1.5.1 release for OL7

* Wed Jun 16 2021 Aaron Young 
- Create new 1.5.0 release for OL7 which includes the following fixed CVEs:
  {CVE-2021-23840} {CVE-2021-23841} {CVE-2021-38575}

* Thu Feb 18 2021 Aaron Young 
- Create new 1.4.3 release for OL7

* Wed Jan 20 2021 Aaron Young 
- Create new 1.4.2 release for OL7

* Thu Dec 03 2020 Aaron Young 
- Create new 1.4.1 release for OL7

* Wed Nov 18 2020 Aaron Young 
- Create new 1.4.0 release for OL7 which includes the following fixed CVEs:
  {CVE-2019-14584} {CVE-2019-14562} {CVE-2019-11098} {CVE-2019-14559} {CVE-2019-14575} {CVE-2019-14559} {CVE-2019-14587} {CVE-2019-14558} {CVE-2019-14586} {CVE-2019-14563}

* Sat Oct 10 2020 Aaron Young 
- Create new 1.3.4 release for OL7

* Wed Oct 07 2020 Aaron Young 
- Create new 1.3.3 release for OL7

* Fri Jul 31 2020 Aaron Young 
- Create new 1.3.2 release for OL7

* Fri May 01 2020 Aaron Young 
- Create new 1.3.1 release for OL7

* Wed Feb 05 2020 Aaron Young 
- Create new 1.3 release for OL7 which includes the following fixed CVEs:
  {CVE-2018-12182} {CVE-2019-13224} {CVE-2019-13225} {CVE-2019-14553}

* Fri May 17 2019 Aaron Young 
- Create new 1.2 release for OL7 which includes the following fixed CVEs:
  {CVE-2017-5715} {CVE-2017-5731} {CVE-2017-5732} {CVE-2017-5733} {CVE-2017-5734} {CVE-2017-5735} {CVE-2017-5753} {CVE-2018-12178} {CVE-2018-12180} {CVE-2018-12181} {CVE-2018-3630}


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle7: ELSA-2023-13027: edk2 security Important (aarch64) Security U

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

* Mon Aug 21 2023 Aaron Young - Create new 1.6.6 release for OL7 which includes the following fixed CVEs: {CVE-2019-14560} - Update to OpenSSL 1.1.1v which includes the following fixed CVEs: {CVE-2023-3817} {CVE-2023-3446} {CVE-2023-2650} {CVE-2023-0465} {CVE-2023-0466} {CVE-2023-0464} {CVE-2023-0286} {CVE-2023-0215} {CVE-2022-4450} {CVE-2022-4304} {CVE-2022-2097} {CVE-2022-2068} {CVE-2022-1292} {CVE-2022-0778} {CVE-2021-4160} {CVE-2021-3712} {CVE-2021-3711} {CVE-2021-3450} {CVE-2021-3449} {CVE-2021-23841} {CVE-2021-23840} {CVE-2020-1971} {CVE-2020-1967} {CVE-2019-1551} {CVE-2019-1563} {CVE-2019-1549} {CVE-2019-1547} {CVE-2019-1552} {CVE-2019-1543} {CVE-2018-0734} {CVE-2018-0735} * Tue Jun 13 2023 Aaron Young - Create new 1.6.5.cvm release for OL7 * Mon Feb 27 2023 Aaron Young - Create new 1.6.4.cvm release for OL7 which includes the following fixed CVEs: {CVE-2021-38578} * Tue Jun 28 2022 Aaron Young - Create new 1.6.3 release for OL7 * Wed Jun 01 2022 Aaron Young - Create new 1.6.2 release for OL7 * Wed May 11 2022 Aaron Young - Create new 1.6.1 release for OL7 * Wed Apr 06 2022 Aaron Young - Create new 1.6.0 release for OL7 which includes the following fixed CVEs: {CVE-2022-0778} * Tue Nov 23 2021 Aaron Young - Create new 1.5.1 release for OL7 * Wed Jun 16 2021 Aaron Young - Create new 1.5.0 release for OL7 which includes the following fixed CVEs: {CVE-2021-23840} {CVE-2021-23841} {CVE-2021-38575} * Thu Feb 18 2021 Aaron Young - Create new 1.4.3 release for OL7 * Wed Jan 20 2021 Aaron Young - Create new 1.4.2 release for OL7 * Thu Dec 03 2020 Aaron Young - Create new 1.4.1 release for OL7 * Wed Nov 18 2020 Aaron Young - Create new 1.4.0 release for OL7 which includes the following fixed CVEs: {CVE-2019-14584} {CVE-2019-14562} {CVE-2019-11098} {CVE-2019-14559} {CVE-2019-14575} {CVE-2019-14559} {CVE-2019-14587} {CVE-2019-14558} {CVE-2019-14586} {CVE-2019-14563} * Sat Oct 10 2020 Aaron Young - Create new 1.3.4 release for OL7 * Wed Oct 07 2020 Aaron Young - Create new 1.3.3 release for OL7 * Fri Jul 31 2020 Aaron Young - Create new 1.3.2 release for OL7 * Fri May 01 2020 Aaron Young - Create new 1.3.1 release for OL7 * Wed Feb 05 2020 Aaron Young - Create new 1.3 release for OL7 which includes the following fixed CVEs: {CVE-2018-12182} {CVE-2019-13224} {CVE-2019-13225} {CVE-2019-14553} * Fri May 17 2019 Aaron Young - Create new 1.2 release for OL7 which includes the following fixed CVEs: {CVE-2017-5715} {CVE-2017-5731} {CVE-2017-5732} {CVE-2017-5733} {CVE-2017-5734} {CVE-2017-5735} {CVE-2017-5753} {CVE-2018-12178} {CVE-2018-12180} {CVE-2018-12181} {CVE-2018-3630}

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates//edk2-1.6.6-1.el7.src.rpm

x86_64

aarch64

AAVMF-1.6.6-1.el7.noarch.rpm

i386

Severity
Related CVEs: CVE-2023-0286 CVE-2023-0215 CVE-2022-4304 CVE-2022-4450

Related News