[Oraclevm-errata] OVMSA-2018-0021 Important: Oracle VM 3.4 xen security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Fri Mar 2 13:15:45 PST 2018


Oracle VM Security Advisory OVMSA-2018-0021

The following updated rpms for Oracle VM 3.4 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
xen-4.4.4-105.0.36.el6.x86_64.rpm
xen-tools-4.4.4-105.0.36.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/oraclevm/server/3.4/SRPMS-updates/xen-4.4.4-105.0.36.el6.src.rpm



Description of changes:

[4.4.4-105.0.36.el6]
- BUILDINFO: xen commit=b2a6db11ced11291a472bc1bda20ce329eda4d66
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- gnttab: don't blindly free status pages upon version change (Andrew 
Cooper)  [Orabug: 27571750]  {CVE-2018-7541}
- memory: don't implicitly unpin for decrease-reservation (Andrew 
Cooper)  [Orabug: 27571737]  {CVE-2018-7540}

[4.4.4-105.0.35.el6]
- BUILDINFO: xen commit=873b8236e886daa3c26dae28d0c1c53d88447dc0
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: if secure boot is enabled dont write pci config space (Elena 
Ufimtseva)  [Orabug: 27533309]

[4.4.4-105.0.34.el6]
- BUILDINFO: xen commit=81602116e75b6bbc519366b242c71888aa1b1673
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86/spec_ctrl: Fix several bugs in SPEC_CTRL_ENTRY_FROM_INTR_IST 
(Andrew Cooper)  [Orabug: 27553376]  {CVE-2017-5753} {CVE-2017-5715} 
{CVE-2017-5754}
- x86: allow easier disabling of BTI mitigations (Zhenzhong Duan) 
[Orabug: 27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}
- x86/boot: Make alternative patching NMI-safe (Andrew Cooper) [Orabug: 
27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}
- xen/cmdline: Fix parse_boolean() for unadorned values (Andrew Cooper)  
[Orabug: 27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}
- Optimize the context switch code a bit (Zhenzhong Duan)  [Orabug: 
27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}
- Update init_speculation_mitigations() to upstream's (Zhenzhong Duan)  
[Orabug: 27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}
- x86/entry: Avoid using alternatives in NMI/#MC paths (Andrew Cooper)  
[Orabug: 27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}
- Update RSB related implementation to upstream ones (Zhenzhong Duan)  
[Orabug: 27553376]  {CVE-2017-5753} {CVE-2017-5715} {CVE-2017-5754}

[4.4.4-105.0.33.el6]
- BUILDINFO: xen commit=c6a2fe8d72a3eba01b22cbe495e60cb6837fe8d0
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86: Expose CPUID.7, EDX.26->27 and CPUID.0x80000008, EBX.12 (redux) 
(Konrad Rzeszutek Wilk)  [Orabug: 27445678]

[4.4.4-105.0.32.el6]
- BUILDINFO: xen commit=9657d91fcbf49798d2c5135866e1947113d536dc
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86/Spectre: Set thunk to THUNK_NONE if compiler support is not 
available (Boris Ostrovsky)  [Orabug: 27375688]

[4.4.4-105.0.31.el6]
- BUILDINFO: xen commit=4e5826dfcb56d3a868a9934646989f8483f03b3c
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xen: No dependencies on dracut and microcode_ctl RPMs (Boris 
Ostrovsky)  [Orabug: 27409718]




More information about the Oraclevm-errata mailing list