Oracle Linux Security Advisory ELSA-2024-1335

https://linux.oracle.com/errata/ELSA-2024-1335.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
dnsmasq-2.79-31.el8_9.2.x86_64.rpm
dnsmasq-utils-2.79-31.el8_9.2.x86_64.rpm

aarch64:
dnsmasq-2.79-31.el8_9.2.aarch64.rpm
dnsmasq-utils-2.79-31.el8_9.2.aarch64.rpm


SRPMS:
https://oss.oracle.com:443/ol8/SRPMS-updates//dnsmasq-2.79-31.el8_9.2.src.rpm

Related CVEs:

CVE-2023-50387
CVE-2023-50868




Description of changes:

[2.79-31.2]
- Fix CVE 2023-50387 and CVE 2023-50868
- Resolves: RHEL-25628
- Resolves: RHEL-25666

[2.79-31.1]
- Do not crash on invalid domain in --synth-domain option (RHEL-22741)

[2.79-31]
- Do not create and search --local and --address=/x/# domains (#2233542)

[2.79-30]
- Make create logfile writeable by root (#2156789)

[2.79-29]
- Fix also dynamically set resolvers over dbus (#2186481)

[2.79-28]
- Correct possible crashes when server=/example.net/# is used (#2186481)

[2.79-27]
- Limit offered EDNS0 size to 1232 (CVE-2023-28450)


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2024-1335: dnsmasq security Important Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[2.79-31.2] - Fix CVE 2023-50387 and CVE 2023-50868 - Resolves: RHEL-25628 - Resolves: RHEL-25666 [2.79-31.1] - Do not crash on invalid domain in --synth-domain option (RHEL-22741) [2.79-31] - Do not create and search --local and --address=/x/# domains (#2233542) [2.79-30] - Make create logfile writeable by root (#2156789) [2.79-29] - Fix also dynamically set resolvers over dbus (#2186481) [2.79-28] - Correct possible crashes when server=/example.net/# is used (#2186481) [2.79-27] - Limit offered EDNS0 size to 1232 (CVE-2023-28450)

SRPMs

https://oss.oracle.com:443/ol8/SRPMS-updates//dnsmasq-2.79-31.el8_9.2.src.rpm

x86_64

dnsmasq-2.79-31.el8_9.2.x86_64.rpm dnsmasq-utils-2.79-31.el8_9.2.x86_64.rpm

aarch64

dnsmasq-2.79-31.el8_9.2.aarch64.rpm dnsmasq-utils-2.79-31.el8_9.2.aarch64.rpm

i386

Severity
Related CVEs: CVE-2023-50387 CVE-2023-50868

Related News