[Oraclevm-errata] OVMSA-2017-0100 Important: Oracle VM 3.4 bind security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Tue May 9 09:07:26 PDT 2017

Oracle VM Security Advisory OVMSA-2017-0100

The following updated rpms for Oracle VM 3.4 have been uploaded to the 
Unbreakable Linux Network:



Description of changes:

- Fix DNSKEY that encountered a CNAME (#1447869, ISC change 3391)

- Fix CVE-2017-3136 (ISC change 4575)
- Fix CVE-2017-3137 (ISC change 4578)

- Fix and test caching CNAME before DNAME (ISC change 4558)

- Fix CVE-2016-9147 (ISC change 4510)
- Fix regression introduced by CVE-2016-8864 (ISC change 4530)

- Restore SELinux contexts before named restart

- Use /lib or /lib64 only if directory in chroot already exists
- Tighten NSS library pattern, escape chroot mount path

- Fix CVE-2016-8864

- Do not change lib permissions in chroot (#1321239)
- Support WKS records in chroot (#1297562)

- Do not include patch backup in docs (fixes #1325081 patch)

- Backported relevant parts of [RT #39567] (#1259923)

- Increase ISC_SOCKET_MAXEVENTS to 2048 (#1326283)

- Fix multiple realms in nsupdate script like upstream (#1313286)

- Fix multiple realm in nsupdate script (#1313286)

- Use resolver-query-timeout high enough to recover all forwarders 

More information about the Oraclevm-errata mailing list