elsa-2023-13053

oracle_linux
Description

conmon [2.1.3-7] - Resolve CVE-2023-39325 [2.1.3-6] - Add ol8_baseos_latest, and ol9_baseos_latest, to Jenkinsfile [2.1.3-5] - Add systemd-devel as build requirement [2.1.3-4] - Add support ARM build cri-o [1.26.3-3] - Resolve CVE-2023-39325 [1.26.3-2] - Add support for ARM build cri-tools [1.26.1-3] - Resolve CVE-2023-39325 [1.26.1-2] - Add ARM build support etcd [3.5.9-2] - Bump up version [3.5.9-1] - Added Oracle specific build files flannel-cni-plugin [1.1.2-3] - Resolve CVE-2023-44487 and CVE-2023-39325 [1.1.2-2] - Add ARM build support helm [3.12.0-3] - address CVE-2023-44487 and CVE-2023-39325 [-] - Add support for ARM build istio [1.17.8-1] - Added Oracle specific files for 1.17.8-1 kata [1.12.1-14] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-13] - Rebuild kata to fix timestamp issue [1.12.1-12] - Add support for ARM build kata-agent [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Remove build_date global variable in kata-image specfile [1.12.1-7] - Add support for ARM build kata-image [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Remove build_date global variable in specfile [1.12.1-7] - Add support for ARM build kata-ksm-throttler [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kata-proxy [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kata-runtime [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kata-shim [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kubernetes [1.26.10-2] - Allow dashes DNS image [1.26.10-1] - Added Oracle specific build files for Kubernetes kubernetes-cni [1.1.2-3] - Resolve CVE-2023-44487 and CVE-2023-39325 [1.1.2-2] - Add support for ARM build kubernetes-cni-plugins [1.2.0-4] - Fix go.mod [1.2.0-3] - Resolve CVE-2023-44487 and CVE-2023-39325 [1.2.0-2] - Add support for ARM build [1.2.0-1] - Added Oracle specific build files for Kubernetes CNI Plugins kubevirt [0.58.0-4] - Updated to address CVE-2023-44487 and CVE-2023-39325 olcne [1.7.5-17] - Fix update issue from 1.6.x - 1.7.5 [1.7.5-16] - Pass imagetag to the metallb tool that converts configmap to crs [1.7.5-15] - Fix metallb upgrade failure when proxy is needed [1.7.5-14] - Update conmon to 2.1.3-7 in scripts [1.7.5-13] - Update module-operator to address CVE-2023-44487, CVE-2023-39325 [1.7.5-12] - Update multus-cni 3.9.3 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-11] - Update multus-cni 4.0.1 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-10] - Update metallb 0.13.9 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-9] - Update externalip-webhook 1.0.0 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-8] - Update calico-3.25.0 and 3.25.1 to address CVE-2023-44487, CVE-2023-39325 [1.7.5-7] - Update rook-1.10.9 and 1.11.6 to address golang CVE-2023-44487, CVE-2023-39325 [1.7.5-6] - update configmap-registry to 1.28.0 and update olm 0.23.1 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-5] - Update Istio, Grafana, Prometheus, and Kubernetes-dashboard to address CVE's - CVE-2023-44487 - CVE-2023-39325 [1.7.5-4] - update helm 3.12.0 to Address CVE-2023-44487 and CVE-2023-39325 [1.7.5-3] - Update kubernetes and components to address golang CVE-2023-44487, CVE-2023-39325 [1.7.5-2] - Add olm 0.23.1 charts [1.7.5-1] - Update kubevirt 0.58.0 to address CVE-2023-44487 and CVE-2023-39325 yq [4.34.1-3] - address CVE-2023-44487 and CVE-2023-3932A [4.34.1-2] - Add support for ARM build

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2023-39325",
    "CVE-2023-44487"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "conmon\n[2.1.3-7]\n- Resolve CVE-2023-39325\n\n[2.1.3-6]\n- Add ol8_baseos_latest, and ol9_baseos_latest, to Jenkinsfile\n\n[2.1.3-5]\n- Add systemd-devel as build requirement\n\n[2.1.3-4]\n- Add support ARM build\n\ncri-o\n[1.26.3-3]\n- Resolve CVE-2023-39325\n\n[1.26.3-2]\n- Add support for ARM build\n\ncri-tools\n[1.26.1-3]\n- Resolve CVE-2023-39325\n\n[1.26.1-2]\n- Add ARM build support\n\netcd\n[3.5.9-2]\n- Bump up version\n\n[3.5.9-1]\n- Added Oracle specific build files\n\nflannel-cni-plugin\n[1.1.2-3]\n- Resolve CVE-2023-44487 and CVE-2023-39325\n\n[1.1.2-2]\n- Add ARM build support\n\nhelm\n[3.12.0-3]\n- address CVE-2023-44487 and CVE-2023-39325\n\n[-]\n- Add support for ARM build\n\nistio\n[1.17.8-1]\n- Added Oracle specific files for 1.17.8-1\n\nkata\n[1.12.1-14]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-13]\n- Rebuild kata to fix timestamp issue\n\n[1.12.1-12]\n- Add support for ARM build\n\nkata-agent\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Remove build_date global variable in kata-image specfile\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-image\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Remove build_date global variable in specfile\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-ksm-throttler\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-proxy\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-runtime\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-shim\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkubernetes\n[1.26.10-2]\n- Allow dashes DNS image\n\n[1.26.10-1]\n- Added Oracle specific build files for Kubernetes\n\nkubernetes-cni\n[1.1.2-3]\n- Resolve CVE-2023-44487 and CVE-2023-39325\n\n[1.1.2-2]\n- Add support for ARM build\n\nkubernetes-cni-plugins\n[1.2.0-4]\n- Fix go.mod\n\n[1.2.0-3]\n- Resolve CVE-2023-44487 and CVE-2023-39325\n\n[1.2.0-2]\n- Add support for ARM build\n\n[1.2.0-1]\n- Added Oracle specific build files for Kubernetes CNI Plugins\n\nkubevirt\n[0.58.0-4]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\nolcne\n[1.7.5-17]\n- Fix update issue from 1.6.x - 1.7.5\n\n[1.7.5-16]\n- Pass imagetag to the metallb tool that converts configmap to crs\n\n[1.7.5-15]\n- Fix metallb upgrade failure when proxy is needed\n\n[1.7.5-14]\n- Update conmon to 2.1.3-7 in scripts\n\n[1.7.5-13]\n- Update module-operator to address CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-12]\n- Update multus-cni 3.9.3 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-11]\n- Update multus-cni 4.0.1 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-10]\n- Update metallb 0.13.9 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-9]\n- Update externalip-webhook 1.0.0 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-8]\n- Update calico-3.25.0 and 3.25.1 to address CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-7]\n- Update rook-1.10.9  and 1.11.6 to address golang CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-6]\n- update configmap-registry to 1.28.0 and update olm 0.23.1 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-5]\n- Update Istio, Grafana, Prometheus, and Kubernetes-dashboard to address CVE's\n- CVE-2023-44487\n- CVE-2023-39325\n\n[1.7.5-4]\n- update helm 3.12.0 to Address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-3]\n- Update kubernetes and components to address golang CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-2]\n- Add olm 0.23.1 charts\n\n[1.7.5-1]\n- Update kubevirt 0.58.0 to address CVE-2023-44487 and CVE-2023-39325\n\nyq\n[4.34.1-3]\n- address CVE-2023-44487 and CVE-2023-3932A\n\n[4.34.1-2]\n- Add support for ARM build",
  "id": "ELSA-2023-13053",
  "ovalId": "oval:com.oracle.elsa:def:202313053",
  "source": "oracle_linux",
  "title": "ELSA-2023-13053: conmon security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2023-13053.html"
}
View JSON API Download JSON