elsa-2023-13053
oracle_linuxconmon [2.1.3-7] - Resolve CVE-2023-39325 [2.1.3-6] - Add ol8_baseos_latest, and ol9_baseos_latest, to Jenkinsfile [2.1.3-5] - Add systemd-devel as build requirement [2.1.3-4] - Add support ARM build cri-o [1.26.3-3] - Resolve CVE-2023-39325 [1.26.3-2] - Add support for ARM build cri-tools [1.26.1-3] - Resolve CVE-2023-39325 [1.26.1-2] - Add ARM build support etcd [3.5.9-2] - Bump up version [3.5.9-1] - Added Oracle specific build files flannel-cni-plugin [1.1.2-3] - Resolve CVE-2023-44487 and CVE-2023-39325 [1.1.2-2] - Add ARM build support helm [3.12.0-3] - address CVE-2023-44487 and CVE-2023-39325 [-] - Add support for ARM build istio [1.17.8-1] - Added Oracle specific files for 1.17.8-1 kata [1.12.1-14] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-13] - Rebuild kata to fix timestamp issue [1.12.1-12] - Add support for ARM build kata-agent [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Remove build_date global variable in kata-image specfile [1.12.1-7] - Add support for ARM build kata-image [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Remove build_date global variable in specfile [1.12.1-7] - Add support for ARM build kata-ksm-throttler [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kata-proxy [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kata-runtime [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kata-shim [1.12.1-9] - Updated to address CVE-2023-44487 and CVE-2023-39325 [1.12.1-8] - Bump release inline with other kata packages for fixing timestamp issue [1.12.1-7] - Add support for ARM build kubernetes [1.26.10-2] - Allow dashes DNS image [1.26.10-1] - Added Oracle specific build files for Kubernetes kubernetes-cni [1.1.2-3] - Resolve CVE-2023-44487 and CVE-2023-39325 [1.1.2-2] - Add support for ARM build kubernetes-cni-plugins [1.2.0-4] - Fix go.mod [1.2.0-3] - Resolve CVE-2023-44487 and CVE-2023-39325 [1.2.0-2] - Add support for ARM build [1.2.0-1] - Added Oracle specific build files for Kubernetes CNI Plugins kubevirt [0.58.0-4] - Updated to address CVE-2023-44487 and CVE-2023-39325 olcne [1.7.5-17] - Fix update issue from 1.6.x - 1.7.5 [1.7.5-16] - Pass imagetag to the metallb tool that converts configmap to crs [1.7.5-15] - Fix metallb upgrade failure when proxy is needed [1.7.5-14] - Update conmon to 2.1.3-7 in scripts [1.7.5-13] - Update module-operator to address CVE-2023-44487, CVE-2023-39325 [1.7.5-12] - Update multus-cni 3.9.3 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-11] - Update multus-cni 4.0.1 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-10] - Update metallb 0.13.9 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-9] - Update externalip-webhook 1.0.0 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-8] - Update calico-3.25.0 and 3.25.1 to address CVE-2023-44487, CVE-2023-39325 [1.7.5-7] - Update rook-1.10.9 and 1.11.6 to address golang CVE-2023-44487, CVE-2023-39325 [1.7.5-6] - update configmap-registry to 1.28.0 and update olm 0.23.1 to address CVE-2023-44487 and CVE-2023-39325 [1.7.5-5] - Update Istio, Grafana, Prometheus, and Kubernetes-dashboard to address CVE's - CVE-2023-44487 - CVE-2023-39325 [1.7.5-4] - update helm 3.12.0 to Address CVE-2023-44487 and CVE-2023-39325 [1.7.5-3] - Update kubernetes and components to address golang CVE-2023-44487, CVE-2023-39325 [1.7.5-2] - Add olm 0.23.1 charts [1.7.5-1] - Update kubevirt 0.58.0 to address CVE-2023-44487 and CVE-2023-39325 yq [4.34.1-3] - address CVE-2023-44487 and CVE-2023-3932A [4.34.1-2] - Add support for ARM build
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2023-39325",
"CVE-2023-44487"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "conmon\n[2.1.3-7]\n- Resolve CVE-2023-39325\n\n[2.1.3-6]\n- Add ol8_baseos_latest, and ol9_baseos_latest, to Jenkinsfile\n\n[2.1.3-5]\n- Add systemd-devel as build requirement\n\n[2.1.3-4]\n- Add support ARM build\n\ncri-o\n[1.26.3-3]\n- Resolve CVE-2023-39325\n\n[1.26.3-2]\n- Add support for ARM build\n\ncri-tools\n[1.26.1-3]\n- Resolve CVE-2023-39325\n\n[1.26.1-2]\n- Add ARM build support\n\netcd\n[3.5.9-2]\n- Bump up version\n\n[3.5.9-1]\n- Added Oracle specific build files\n\nflannel-cni-plugin\n[1.1.2-3]\n- Resolve CVE-2023-44487 and CVE-2023-39325\n\n[1.1.2-2]\n- Add ARM build support\n\nhelm\n[3.12.0-3]\n- address CVE-2023-44487 and CVE-2023-39325\n\n[-]\n- Add support for ARM build\n\nistio\n[1.17.8-1]\n- Added Oracle specific files for 1.17.8-1\n\nkata\n[1.12.1-14]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-13]\n- Rebuild kata to fix timestamp issue\n\n[1.12.1-12]\n- Add support for ARM build\n\nkata-agent\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Remove build_date global variable in kata-image specfile\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-image\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Remove build_date global variable in specfile\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-ksm-throttler\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-proxy\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-runtime\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkata-shim\n[1.12.1-9]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\n[1.12.1-8]\n- Bump release inline with other kata packages for fixing timestamp issue\n\n[1.12.1-7]\n- Add support for ARM build\n\nkubernetes\n[1.26.10-2]\n- Allow dashes DNS image\n\n[1.26.10-1]\n- Added Oracle specific build files for Kubernetes\n\nkubernetes-cni\n[1.1.2-3]\n- Resolve CVE-2023-44487 and CVE-2023-39325\n\n[1.1.2-2]\n- Add support for ARM build\n\nkubernetes-cni-plugins\n[1.2.0-4]\n- Fix go.mod\n\n[1.2.0-3]\n- Resolve CVE-2023-44487 and CVE-2023-39325\n\n[1.2.0-2]\n- Add support for ARM build\n\n[1.2.0-1]\n- Added Oracle specific build files for Kubernetes CNI Plugins\n\nkubevirt\n[0.58.0-4]\n- Updated to address CVE-2023-44487 and CVE-2023-39325\n\nolcne\n[1.7.5-17]\n- Fix update issue from 1.6.x - 1.7.5\n\n[1.7.5-16]\n- Pass imagetag to the metallb tool that converts configmap to crs\n\n[1.7.5-15]\n- Fix metallb upgrade failure when proxy is needed\n\n[1.7.5-14]\n- Update conmon to 2.1.3-7 in scripts\n\n[1.7.5-13]\n- Update module-operator to address CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-12]\n- Update multus-cni 3.9.3 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-11]\n- Update multus-cni 4.0.1 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-10]\n- Update metallb 0.13.9 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-9]\n- Update externalip-webhook 1.0.0 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-8]\n- Update calico-3.25.0 and 3.25.1 to address CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-7]\n- Update rook-1.10.9 and 1.11.6 to address golang CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-6]\n- update configmap-registry to 1.28.0 and update olm 0.23.1 to address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-5]\n- Update Istio, Grafana, Prometheus, and Kubernetes-dashboard to address CVE's\n- CVE-2023-44487\n- CVE-2023-39325\n\n[1.7.5-4]\n- update helm 3.12.0 to Address CVE-2023-44487 and CVE-2023-39325\n\n[1.7.5-3]\n- Update kubernetes and components to address golang CVE-2023-44487, CVE-2023-39325\n\n[1.7.5-2]\n- Add olm 0.23.1 charts\n\n[1.7.5-1]\n- Update kubevirt 0.58.0 to address CVE-2023-44487 and CVE-2023-39325\n\nyq\n[4.34.1-3]\n- address CVE-2023-44487 and CVE-2023-3932A\n\n[4.34.1-2]\n- Add support for ARM build",
"id": "ELSA-2023-13053",
"ovalId": "oval:com.oracle.elsa:def:202313053",
"source": "oracle_linux",
"title": "ELSA-2023-13053: conmon security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2023-13053.html"
}