Oracle Linux Security Advisory ELSA-2024-3741

http://linux.oracle.com/errata/ELSA-2024-3741.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
bind-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-license-9.11.4-26.P2.el7_9.16.noarch.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-sdb-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-dyndb-ldap-11.1-7.el7_9.1.aarch64.rpm
dhclient-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-common-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-libs-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-devel-4.2.5-83.0.3.el7_9.2.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//bind-9.11.4-26.P2.el7_9.16.src.rpm
http://oss.oracle.com/ol7/SRPMS-updates//bind-dyndb-ldap-11.1-7.el7_9.1.src.rpm
http://oss.oracle.com/ol7/SRPMS-updates//dhcp-4.2.5-83.0.3.el7_9.2.src.rpm

Related CVEs:

CVE-2023-4408
CVE-2023-50387
CVE-2023-50868




Description of changes:

bind
[32:9.11.4-26.P2.16]
- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers

bind-dyndb-ldap
[11.1-7.1]
- Rebuild required for BIND changes for KeyTrap change (CVE-2023-50387)

dhcp
[12:4.2.5-83.0.3.2]
- Update bug reporting URL [Orabug: 35496820]
- Direct users to Oracle Linux support site.

[12:4.2.5-83.2]
- Rebuild because of bind ABI changes related to CVE-2023-50387


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle7: ELSA-2024-3741 : bind, bind-dyndb-ldap, and dhcp Important (aarch64) Security Advisory Updates

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

bind [32:9.11.4-26.P2.16] - Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387 CVE-2023-50868) - Add missing design by contract tests to dns_catz* - Speed up parsing of DNS messages with many different names (CVE-2023-4408) - Do not use header_prev in expire_lru_headers bind-dyndb-ldap [11.1-7.1] - Rebuild required for BIND changes for KeyTrap change (CVE-2023-50387) dhcp [12:4.2.5-83.0.3.2] - Update bug reporting URL [Orabug: 35496820] - Direct users to Oracle Linux support site. [12:4.2.5-83.2] - Rebuild because of bind ABI changes related to CVE-2023-50387

SRPMs

http://oss.oracle.com/ol7/SRPMS-updates//bind-9.11.4-26.P2.el7_9.16.src.rpm http://oss.oracle.com/ol7/SRPMS-updates//bind-dyndb-ldap-11.1-7.el7_9.1.src.rpm http://oss.oracle.com/ol7/SRPMS-updates//dhcp-4.2.5-83.0.3.el7_9.2.src.rpm

x86_64

aarch64

bind-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-export-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-libs-lite-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-license-9.11.4-26.P2.el7_9.16.noarch.rpm bind-pkcs11-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-pkcs11-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-pkcs11-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-export-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-lite-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-pkcs11-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-sdb-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-sdb-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-dyndb-ldap-11.1-7.el7_9.1.aarch64.rpm dhclient-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-common-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-libs-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-devel-4.2.5-83.0.3.el7_9.2.aarch64.rpm

i386

Severity
Related CVEs: CVE-2023-4408 CVE-2023-50387 CVE-2023-50868

Related News