Oracle Linux 6277 Published by

A qemu security update (aarch64) has been released for Oracle Linux 7.



ELSA-2023-12835 Moderate: Oracle Linux 7 qemu security update (aarch64)


Oracle Linux Security Advisory ELSA-2023-12835

http://linux.oracle.com/errata/ELSA-2023-12835.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
ivshmem-tools-4.2.1-28.el7.aarch64.rpm
qemu-4.2.1-28.el7.aarch64.rpm
qemu-block-gluster-4.2.1-28.el7.aarch64.rpm
qemu-block-iscsi-4.2.1-28.el7.aarch64.rpm
qemu-block-rbd-4.2.1-28.el7.aarch64.rpm
qemu-common-4.2.1-28.el7.aarch64.rpm
qemu-img-4.2.1-28.el7.aarch64.rpm
qemu-kvm-4.2.1-28.el7.aarch64.rpm
qemu-kvm-core-4.2.1-28.el7.aarch64.rpm
qemu-system-aarch64-4.2.1-28.el7.aarch64.rpm
qemu-system-aarch64-core-4.2.1-28.el7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//qemu-4.2.1-28.el7.src.rpm

Related CVEs:

CVE-2023-0330
CVE-2023-3180
CVE-2023-3301

Description of changes:

[15:4.2.1-28.el7]
- virtio-crypto: verify src&dst buffer length for sym request (Zhenwei Pi) [Orabug: 35724113] {CVE-2023-3180}
- hw/scsi/lsi53c895a: Fix reentrancy issues in the LSI controller (CVE-2023-0330) (Thomas Huth) [Orabug: 35724112] {CVE-2023-0330}
- kvm: Atomic memslot updates (David Hildenbrand) [Orabug: 35719844]
- KVM: keep track of running ioctls (Emanuele Giuseppe Esposito) [Orabug: 35719844]
- accel: introduce accelerator blocker API (Emanuele Giuseppe Esposito) [Orabug: 35719844]
- KVM: Use a big lock to replace per-kml slots_lock (Peter Xu) [Orabug: 35719844]
- pcie: don't set link state active if the slot is empty (Laurent Vivier) [Orabug: 35707933]
- vhost-vdpa: do not cleanup the vdpa/vhost-net structures if peer nic is present (Ani Sinha) [Orabug: 35662850] {CVE-2023-3301}