[Oraclevm-errata] OVMSA-2021-0033 Important: Oracle VM 3 Extended Lifecycle Support (ELS) xen security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Mon Oct 11 20:57:50 PDT 2021


Oracle VM Security Advisory OVMSA-2021-0033

The following updated rpms for Oracle VM 3 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

x86_64:
xen-4.4.4-222.0.42.el6.x86_64.rpm
xen-tools-4.4.4-222.0.42.el6.x86_64.rpm



Related CVEs:

CVE-2021-28698
CVE-2021-28697
CVE-2021-28701
CVE-2021-28694
CVE-2021-28695
CVE-2021-28696




Description of changes:

[4.4.4-222.0.42.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=e648ffdcf91e7b77229705ce5ba1d4446fe17660
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional commit=4a8ded640f04b41cdb15ce7c4c0a2c812c1b9e4d
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- gnttab: replace mapkind() (Jan Beulich)  [Orabug: 33215771]  {CVE-2021-28698} {CVE-2021-28698}
- gnttab: add preemption check to gnttab_release_mappings() (Jan Beulich)  [Orabug: 33215771]  {CVE-2021-28698} {CVE-2021-28698}
- xe/grant: Limit availability of version 2 of grant table interfaces. (Boris Ostrovsky)  [Orabug: 33215748]  {CVE-2021-28697} {CVE-2021-28701}
- pci: Do not allow passthrough on AMD systems (Boris Ostrovsky)  [Orabug: 33215714]  {CVE-2021-28695} {CVE-2021-28696} {CVE-2021-28695} {CVE-2021-28696}
- x86/p2m: guard (in particular) identity mapping entries (Jan Beulich)  [Orabug: 33215714]  {CVE-2021-28694} {CVE-2021-28694}
- x86/p2m: introduce p2m_is_special() (Jan Beulich)  [Orabug: 33215714]  {CVE-2021-28694}
- x86/p2m: don't assert that the passed in MFN matches for a remove (Jan Beulich)  [Orabug: 33215714]
- x86/p2m: don't ignore p2m_remove_page()'s return value (Jan Beulich)  [Orabug: 33215714]
- x86/p2m: fix PoD accounting in guest_physmap_add_entry() (Jan Beulich)  [Orabug: 33215714]

[4.4.4-222.0.41.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=af11c8054b2c02d72e519d66645fa4b598b14778
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional commit=4a8ded640f04b41cdb15ce7c4c0a2c812c1b9e4d
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86/vpt: fully init timers before putting onto list (Jan Beulich)  [Orabug: 33010521]



More information about the Oraclevm-errata mailing list