[El-errata] ELSA-2024-3741 Important: Oracle Linux 7 bind, bind-dyndb-ldap, and dhcp security update (aarch64)
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Thu Jun 13 20:44:31 UTC 2024
Oracle Linux Security Advisory ELSA-2024-3741
http://linux.oracle.com/errata/ELSA-2024-3741.html
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
aarch64:
bind-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-license-9.11.4-26.P2.el7_9.16.noarch.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-sdb-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm
bind-dyndb-ldap-11.1-7.el7_9.1.aarch64.rpm
dhclient-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-common-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-libs-4.2.5-83.0.3.el7_9.2.aarch64.rpm
dhcp-devel-4.2.5-83.0.3.el7_9.2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//bind-9.11.4-26.P2.el7_9.16.src.rpm
http://oss.oracle.com/ol7/SRPMS-updates//bind-dyndb-ldap-11.1-7.el7_9.1.src.rpm
http://oss.oracle.com/ol7/SRPMS-updates//dhcp-4.2.5-83.0.3.el7_9.2.src.rpm
Related CVEs:
CVE-2023-4408
CVE-2023-50387
CVE-2023-50868
Description of changes:
bind
[32:9.11.4-26.P2.16]
- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
bind-dyndb-ldap
[11.1-7.1]
- Rebuild required for BIND changes for KeyTrap change (CVE-2023-50387)
dhcp
[12:4.2.5-83.0.3.2]
- Update bug reporting URL [Orabug: 35496820]
- Direct users to Oracle Linux support site.
[12:4.2.5-83.2]
- Rebuild because of bind ABI changes related to CVE-2023-50387
More information about the El-errata
mailing list