Oracle VM Server for x86 Bulletin - January 2021

 

Description

The Oracle VM Server for x86 Bulletin lists all CVEs that had been resolved and announced in Oracle VM Server for x86 Security Advisories (OVMSA) in the last one month prior to the release of the bulletin. Oracle VM Server for x86 Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle VM Server for x86 Bulletins may also be updated for vulnerability issues deemed too critical to wait for the next scheduled bulletin publication date.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Oracle VM Server for x86 Bulletin security patches as soon as possible.

 

Patch Availability

Please see ULN Advisory https://linux.oracle.com/ovm-bulletin-pad

 

Oracle VM Server for x86 Bulletin Schedule

Oracle VM Server for x86 Bulletins are released on the Tuesday closest to the 17th day of January, April, July and October. The next four dates are:

  • 20 April 2021
  • 20 July 2021
  • 19 October 2021
  • 18 January 2022

References

 

Modification History

Date Note
2021-March-19 Rev 3. New CVEs added
2021-February-17 Rev 2. New CVEs added
2021-January-19 Rev 1. Initial Release

Oracle VM Server for x86 Executive Summary

This Oracle VM Server for x86 Bulletin contains 42 new security patches for the Oracle VM Server for x86.

Oracle VM Server for x86 Risk Matrix

Revision 3: Published on 2021-03-19

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2020-0431 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2021-26930 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2021-26931 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2021-26932 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2021-27363 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2021-27364 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2021-27365 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4

Revision 2: Published on 2021-02-17

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2021-3156 Oracle VM Server for x86 sudo No 7.8 Local Low Low None Unchanged High High High 3.4
CVE-2020-12653 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-27786 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-29568 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-29660 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-36158 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4

Revision 1: Published on 2021-01-19

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2016-7913 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2016-7917 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2017-9605 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2019-14895 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2019-19037 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2019-19447 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2019-20934 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-10711 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-12464 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-12652 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-14305 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-14351 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-15436 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-16166 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-25643 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-25668 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-25705 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-27673 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-28374 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-28915 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-28974 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-29568 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-29569 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-8694 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-8695 Oracle VM Server for X86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2020-14363 Oracle VM Server for X86 libX11 Undefined 3.4
CVE-2020-8696 Oracle VM Server for X86 microcode_ctl Undefined 3.4
CVE-2020-8698 Oracle VM Server for X86 microcode_ctl Undefined 3.4
CVE-2020-15862 Oracle VM Server for X86 net-snmp Undefined 3.4