Lucene search

K
oraclelinuxOracleLinuxELSA-2024-12225
HistoryMar 18, 2024 - 12:00 a.m.

conmon security update

2024-03-1800:00:00
linux.oracle.com
29
security updates
cve-2023-39326
cri-o
etcd
flannel-cni-plugin
helm
istio
kata
kubernetes
kubevirt
olcne
golang 1.20.12

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

20.4%

conmon
[2.1.3-8]

  • address CVE-2023-39326
    cri-o
    [1.26.4-1]
  • Added Oracle Specific Files for cri-o
  • Cherry-picked upstream commits for OCPBUGS-17150: oci: simplify stopping code https://github.com/cri-o/cri-o/pull/7185
  • Fixed CVE-2023-39325: bump golang.org/x/net to v0.17.0
    cri-tools
    [1.26.1-4]
  • Address CVE-2023-39326
    etcd
    [3.5.9-3]
  • Address CVE-2023-39326 by upgrading golang to version 1.20.12
    flannel-cni-plugin
    [1.2.0-3]
  • Build for aarch64
    [1.2.0-2]
  • Rebuild with golang 1.20.12
    [1.2.0-1]
  • Added Oracle specific build files for Flannel CNI Plugins
  • Address CVE-2023-44487 and CVE-2023-39325
    helm
    [3.12.0-4]
  • address CVE-2023-39326 by updating golang version to 1.20.12
    istio
    [1.17.8-2]
  • Address CVE-2023-39326
    kata
    [1.12.1-17]
  • Include OL9 for kernel-uek-container (currently in UEKR7_developer_preview)
    [1.12.1-16]
  • Rebuild with golang 1.20.12
    [1.12.1-15]
  • Updated for kubernetes 1.27 and 1.28
    kata-agent
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-image
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-ksm-throttler
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-proxy
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-runtime
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kata-shim
    [1.12.1-11]
  • Rebuild with -11 tag
    [1.12.1-10]
  • Updated Golang to 1.20.12 to address CVE CVE-2023-39326
    kubernetes
    [1.26.10-3]
  • Build with golang 1.20.12
    kubernetes-cni
    [1.1.2-4]
  • Address CVE-2023-39326, update golang version to 1.20.12
    kubernetes-cni-plugins
    [1.2.0-6]
  • Rebuild with golang 1.20.12
    [1.2.0-5]
  • update flannel-cni-plugin to 1.2.0
    kubevirt
    [0.58.0-5]
  • Updated to address CVE-2023-39326
    olcne
    [1.7.6-5]
  • Fix OLM upgrade failure
    [1.7.6-4]
  • Fixed unable to deploy new module(s) using config file containing already existing modules
    [1.7.6-2]
  • Corrected olcne repo version in the prompt text of the ‘olcnectl provision’ command
    [1.7.6-1]
  • Update kubernetes and components to address golang CVE-2023-39326
  • Update istio and components to address golang CVE-2023-39326
  • Update metallb, multus-cni, kubevirt, module-operator, calico, rook to address golang CVE-2023-39326
  • Update cri-o to 1.26-4 patched
  • add conmon resource to kubernetes module
    [1.7.5-22]
  • Fix OLM upgrade failure - same version upgrade
    [1.7.5-21]
  • Migrate ModuleOperator from verrazzano-install to ocne-modules namespace
    [1.7.5-20]
  • Update module-operator to address CVE-2023-39326
    [1.7.5-19]
  • Updated kubevirt 0.58.0 to address CVE-2023-39326
    [1.7.5-18]
  • Back port rebuild of calico 3.25.1
    yq
    [4.34.1-4]
  • Update Golang to 1.20.12 to address CVE-2023-39326

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

20.4%