[ELSA-2021-9268] olcne security update

Severity Important
Affected Packages 31
CVEs 1

coredns
[1.7.0-1]
- Added Oracle specific build files

cri-o
[1.18.4-2]
- Fix for CVE-2021-27918

[1.18.4-1]
- Added Oracle Specifile Files for cri-o

cri-tools
[1.18.0-2]
- Address CVE-2021-27918

etcd
[3.4.3-1.0.5]
- Address CVE-2021-27918

flannel
[0.12.0-2]
- Address CVE-2021-27918

yq
[3.4.0-2]
- Address CVE-2021-27918

conmon
[2.0.20-4]
- Address CVE-2021-27918

conmon
[3:2.0.21-4]
- Address CVE-2021-27918

helm
[3.3.4-2]
- Address CVE-2021-27918

kata-proxy
[1.11.5-2]
- Address CVE-2021-27918

kata-shim
[1.11.5-2]
- Address CVE-2021-27918

kata-runtime
[1.11.5-2]
- Address CVE-2021-27918

kata-ksm-throttler
[1.11.5-2]
- Address CVE-2021-27918

kata-image
[1.11.5-2]
- Address CVE-2021-27918

kata-agent
[1.11.5-2]
- Fix for CVE-2021-27918

kata
[1.11.5-4]
- Address CVE-2021-27918

[1.11.5-3]
- Support 1.19, 1.20 k8s

kubernetes-cni-plugins
[0.8.7-2]
- Removed BuildArch to support ARM builds

kubernetes-cni
[0.8.0-3]
- Address CVE-2021-27918

kubernetes-dashboard
[2.0.3-2]
- Address CVE-2021-27918

kubernetes
[1.18.18-1]
- Address CVE-2021-27918

istio
[1.7.3-1.0.2]
- Address CVE-2021-27918

[1.7.3-1.0.1]
- Run gateway pods as root user to workaround ports lessthan 1024 binding failures

[1.7.3-1.0.0]
- Added Oracle Specific Build Files for istio/istio

olcne
[1.2.3-9]
- Updated version for istio-module grafana: v6.7.4-3 and prometheus: v2.20.0-1

[1.2.3-8]
- Revert istio version to 1.7.3-1 which has just golang CVE fixes

[1.2.3-7]
- Fix k8s update path
- Update el8 conmon pre-install

[1.2.3-6]
- Updated updatepath in kubernetes.yaml and image version in templates

[1.2.3-5]
- Added missing info for 1.18.18 in kubernetes.yaml and helm.yaml
- Updated image repository in templates

[1.2.3-4]
- Fix for the failure of kubernetes restore [Orabug: 32310718]

[1.2.3-3]
- Address Istio CVE-2021-28683, CVE-2021-28682 & CVE-2021-29258

[1.2.3-2]
- fix bug where externalip cidr's can't fully be disabled

[1.2.3-1]
- Bug Fix: Update istio module definition to pass instance name for release resource

Package Affected Version
pkg:rpm/oraclelinux/yq?distro=oraclelinux-7 < 3.4.0-2.el7
pkg:rpm/oraclelinux/olcnectl?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/olcne-utils?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/olcne-prometheus-chart?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/olcne-nginx?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/olcne-istio-chart?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/olcne-api-server?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/olcne-agent?distro=oraclelinux-7 < 1.2.3-9.el7
pkg:rpm/oraclelinux/kubernetes-dashboard?distro=oraclelinux-7 < 2.0.3-2.el7
pkg:rpm/oraclelinux/kubernetes-cni?distro=oraclelinux-7 < 0.8.0-3.el7
pkg:rpm/oraclelinux/kubernetes-cni-plugins?distro=oraclelinux-7 < 0.8.7-2.el7
pkg:rpm/oraclelinux/kubelet?distro=oraclelinux-7 < 1.18.18-2.el7
pkg:rpm/oraclelinux/kubectl?distro=oraclelinux-7 < 1.18.18-2.el7
pkg:rpm/oraclelinux/kubeadm?distro=oraclelinux-7 < 1.18.18-2.el7
pkg:rpm/oraclelinux/kata?distro=oraclelinux-7 < 1.11.5-4.el7
pkg:rpm/oraclelinux/kata-shim?distro=oraclelinux-7 < 1.11.5-2.el7
pkg:rpm/oraclelinux/kata-runtime?distro=oraclelinux-7 < 1.11.5-2.el7
pkg:rpm/oraclelinux/kata-proxy?distro=oraclelinux-7 < 1.11.5-2.el7
pkg:rpm/oraclelinux/kata-ksm-throttler?distro=oraclelinux-7 < 1.11.5-2.el7
pkg:rpm/oraclelinux/kata-image < 1.11.5-2.2.ol7_202104281557
pkg:rpm/oraclelinux/kata-agent?distro=oraclelinux-7 < 1.11.5-2.el7
pkg:rpm/oraclelinux/istio?distro=oraclelinux-7 < 1.7.3-1.0.2.el7
pkg:rpm/oraclelinux/istio-istioctl?distro=oraclelinux-7 < 1.7.3-1.0.2.el7
pkg:rpm/oraclelinux/helm?distro=oraclelinux-7 < 3.3.4-2.el7
pkg:rpm/oraclelinux/flannel?distro=oraclelinux-7 < 0.12.0-2.el7
pkg:rpm/oraclelinux/etcd?distro=oraclelinux-7 < 3.4.3-1.0.5.el7
pkg:rpm/oraclelinux/cri-tools?distro=oraclelinux-7 < 1.18.0-2.el7
pkg:rpm/oraclelinux/cri-o?distro=oraclelinux-7 < 1.18.4-2.el7
pkg:rpm/oraclelinux/coredns?distro=oraclelinux-7 < 1.7.0-1.el7
pkg:rpm/oraclelinux/conmon?distro=oraclelinux-7 < 2.0.20-4.el7
pkg:rpm/oraclelinux/conmon?distro=oraclelinux-7 < 2.0.21-4.el7
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/yq?distro=oraclelinux-7 oraclelinux yq < 3.4.0-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcnectl?distro=oraclelinux-7 oraclelinux olcnectl < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcne-utils?distro=oraclelinux-7 oraclelinux olcne-utils < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcne-prometheus-chart?distro=oraclelinux-7 oraclelinux olcne-prometheus-chart < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcne-nginx?distro=oraclelinux-7 oraclelinux olcne-nginx < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcne-istio-chart?distro=oraclelinux-7 oraclelinux olcne-istio-chart < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcne-api-server?distro=oraclelinux-7 oraclelinux olcne-api-server < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/olcne-agent?distro=oraclelinux-7 oraclelinux olcne-agent < 1.2.3-9.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kubernetes-dashboard?distro=oraclelinux-7 oraclelinux kubernetes-dashboard < 2.0.3-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kubernetes-cni?distro=oraclelinux-7 oraclelinux kubernetes-cni < 0.8.0-3.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kubernetes-cni-plugins?distro=oraclelinux-7 oraclelinux kubernetes-cni-plugins < 0.8.7-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kubelet?distro=oraclelinux-7 oraclelinux kubelet < 1.18.18-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kubectl?distro=oraclelinux-7 oraclelinux kubectl < 1.18.18-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kubeadm?distro=oraclelinux-7 oraclelinux kubeadm < 1.18.18-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kata?distro=oraclelinux-7 oraclelinux kata < 1.11.5-4.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kata-shim?distro=oraclelinux-7 oraclelinux kata-shim < 1.11.5-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kata-runtime?distro=oraclelinux-7 oraclelinux kata-runtime < 1.11.5-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kata-proxy?distro=oraclelinux-7 oraclelinux kata-proxy < 1.11.5-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kata-ksm-throttler?distro=oraclelinux-7 oraclelinux kata-ksm-throttler < 1.11.5-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/kata-image oraclelinux kata-image < 1.11.5-2.2.ol7_202104281557
Affected pkg:rpm/oraclelinux/kata-agent?distro=oraclelinux-7 oraclelinux kata-agent < 1.11.5-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/istio?distro=oraclelinux-7 oraclelinux istio < 1.7.3-1.0.2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/istio-istioctl?distro=oraclelinux-7 oraclelinux istio-istioctl < 1.7.3-1.0.2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/helm?distro=oraclelinux-7 oraclelinux helm < 3.3.4-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/flannel?distro=oraclelinux-7 oraclelinux flannel < 0.12.0-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/etcd?distro=oraclelinux-7 oraclelinux etcd < 3.4.3-1.0.5.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/cri-tools?distro=oraclelinux-7 oraclelinux cri-tools < 1.18.0-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/cri-o?distro=oraclelinux-7 oraclelinux cri-o < 1.18.4-2.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/coredns?distro=oraclelinux-7 oraclelinux coredns < 1.7.0-1.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/conmon?distro=oraclelinux-7 oraclelinux conmon < 2.0.20-4.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/conmon?distro=oraclelinux-7 oraclelinux conmon < 2.0.21-4.el7 oraclelinux-7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...