[Oraclevm-errata] OVMSA-2018-0251 Important: Oracle VM 3.4 xen security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Mon Aug 20 21:15:16 PDT 2018


Oracle VM Security Advisory OVMSA-2018-0251

The following updated rpms for Oracle VM 3.4 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
xen-4.4.4-105.0.53.el6.x86_64.rpm
xen-tools-4.4.4-105.0.53.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/oraclevm/server/3.4/SRPMS-updates/xen-4.4.4-105.0.53.el6.src.rpm



Description of changes:

[4.4.4-105.0.53.el6]
- BUILDINFO: xen commit=18ec2b68e519646188fd26a05b2cd26ebd829035
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Revert "xend: fix memory leak of XendConfig.XendConfig object" (Konrad 
Rzeszutek Wilk)  [Orabug: 28506675]

[4.4.4-105.0.52.el6]
- BUILDINFO: xen commit=7023729bcb7dd5c156bc8ee31a7971f036e43f66
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- l1tf: Utility to offline/online SMT siblings. (Ross Philipson) 
[Orabug: 28487029]  {CVE-2018-3646}
- x86/spec-ctrl: Introduce an option to control L1D_FLUSH for HVM guests 
(Andrew Cooper)  [Orabug: 28487029]  {CVE-2018-3620} {CVE-2018-3646}
- x86/msr: Virtualise MSR_FLUSH_CMD for guests (Andrew Cooper)  [Orabug: 
28487029]  {CVE-2018-3646} {CVE-2018-3646}
- x86/spec-ctrl: CPUID/MSR definitions for L1D_FLUSH (Andrew Cooper) 
[Orabug: 28487029]  {CVE-2018-3646} {CVE-2018-3646}
- x86/spec-ctrl: Calculate safe PTE addresses for L1TF mitigations 
(Andrew Cooper)  [Orabug: 28487029]  {CVE-2018-3620} {CVE-2018-3646}
- x86: command line option to avoid use of secondary hyper-threads (Jan 
Beulich)  [Orabug: 28487029]  {CVE-2018-3646}
- cpupools: fix state when downing a CPU failed (Jan Beulich)  [Orabug: 
28487029]  {CVE-2018-3646}

[4.4.4-105.0.51.el6]
- BUILDINFO: xen commit=63c397f89da7c720208e599696ada989121f3698
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: fix memory leak of XendConfig.XendConfig object (Manjunath 
Patil)  [Orabug: 28223470]



More information about the Oraclevm-errata mailing list