Lucene search

K
oraclelinuxOracleLinuxELSA-2024-12190
HistoryMar 01, 2024 - 12:00 a.m.

conmon security update

2024-03-0100:00:00
linux.oracle.com
13
security updates
conmon
cri-o
cri-tools
flannel-cni-plugin
helm
istio
kata
kata-agent
kata-image
kata-ksm-throttler
kata-proxy
kata-runtime
kata-shim
kubernetes
kubernetes-cni
kubernetes-cni-plugins
olcne
yq
cve-2023-39326
golang
oracle specifile files
kernel-uek-container
uekr7_developer_preview
pod-network:calico
unix

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.4%

conmon
[2.1.3-8]

  • address CVE-2023-39326
    cri-o
    [1.25.5-1]
  • Added Oracle Specifile Files for cri-o
    cri-tools
    [1.25.0-3]
  • Resolve CVE-2023-39326
    flannel-cni-plugin
    [1.0.1-4]
  • Resolve CVE-2023-39326
    helm
    [3.11.1-3]
  • address CVE-2023-39326
    istio
    [1.16.7-3]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata
    [1.12.1-17]
  • Include OL9 for kernel-uek-container (currently in UEKR7_developer_preview)
    kata-agent
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-image
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-ksm-throttler
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-proxy
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-runtime
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-shim
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kubernetes
    [1.25.15-2]
  • Address CVE-2023-39326 by upgrading golang to 1.20.12
    kubernetes-cni
    [1.0.1-4]
  • address CVE-2023-39326
    kubernetes-cni-plugins
    [1.0.1-5]
  • address CVE-2023-39326
    olcne
    [1.6.6-3]
  • Fixed pod-network:calico update
    yq
    [4.34.1-4]
  • Update Golang to 1.20.12 to address CVE-2023-39326

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.4%