Oracle VM Server for x86 Bulletin - October 2022

 

Description

The Oracle VM Server for x86 Bulletin lists all CVEs that had been resolved and announced in Oracle VM Server for x86 Security Advisories (OVMSA) in the last one month prior to the release of the bulletin. Oracle VM Server for x86 Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle VM Server for x86 Bulletins may also be updated for vulnerability issues deemed too critical to wait for the next scheduled bulletin publication date.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Oracle VM Server for x86 Bulletin security patches as soon as possible.

 

Patch Availability

Please see ULN Advisory https://linux.oracle.com/ovm-bulletin-pad

 

Oracle VM Server for x86 Bulletin Schedule

Oracle VM Server for x86 Bulletins are released on the third Tuesday of January, April, July, and October. The next four dates are:

  • 17 January 2023
  • 18 April 2023
  • 18 July 2023
  • 17 October 2023

References

 

Modification History

Date Note
2022-December-20 Rev 3. New CVEs added
2022-November-16 Rev 2. New CVEs added
2022-October-18 Rev 1. Initial Release

Oracle VM Server for x86 Executive Summary

This Oracle VM Server for x86 Bulletin contains 33 new security patches for the Oracle VM Server for x86.

Oracle VM Server for x86 Risk Matrix

Revision 3: Published on 2022-12-20

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2022-3565 Oracle VM Server for x86 Unbreakable Enterprise kernel No 8.0 Local Low Low None Unchanged High High High 3
CVE-2019-19377 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.8 Local Low None Required Unchanged High High High 3
CVE-2022-20368 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.0 Local High Low None Unchanged High High High 3
CVE-2022-2639 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.0 Local High Low None Unchanged High High High 3
CVE-2021-20292 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.7 Local Low High None Unchanged High High High 3
CVE-2022-33746 Oracle VM Server for x86 xen No 6.5 Local Low Low None Changed None None High 3
CVE-2022-2663 Oracle VM Server for x86 Unbreakable Enterprise kernel Yes 5.9 Network High None None Unchanged None High None 3
CVE-2022-40768 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.5 Local Low Low None Unchanged High None None 3
CVE-2022-3629 Oracle VM Server for x86 Unbreakable Enterprise kernel No 3.3 Local Low Low None Unchanged None None Low 3
CVE-2022-4378 Oracle VM Server for x86 Unbreakable Enterprise kernel No 3.3 Local Low Low None Unchanged None None Low 3

Revision 2: Published on 2022-11-15

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2017-13166 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.8 Local Low Low None Unchanged High High High 3
CVE-2020-12654 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.1 Adjacent Network High None Required Unchanged High High High 3
CVE-2022-3239 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.0 Local High Low None Unchanged High High High 3
CVE-2021-42739 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.7 Local Low High None Unchanged High High High 3
CVE-2020-10690 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.5 Local Low High Required Unchanged High High High 3
CVE-2022-36946 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.2 Local Low None None Unchanged None None High 3
CVE-2015-1350 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.5 Local Low Low None Unchanged None None High 3
CVE-2020-12655 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.5 Local Low None Required Unchanged None None High 3

Revision 1: Published on 2022-10-17

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2022-2964 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.8 Local Low Low None Unchanged High High High 3
CVE-2020-12770 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.7 Local Low High None Unchanged High High High 3
CVE-2022-3028 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.7 Local Low High None Unchanged High High High 3
CVE-2021-30002 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.2 Local Low None None Unchanged None None High 3
CVE-2020-14390 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.7 Local High High None Unchanged High High None 3
CVE-2017-7472 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.5 Local Low Low None Unchanged None None High 3
CVE-2022-1184 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.5 Local Low Low None Unchanged None None High 3
CVE-2022-36879 Oracle VM Server for x86 Unbreakable Enterprise kernel No 5.5 Local Low Low None Unchanged None None High 3
CVE-2017-16537 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.6 Physical Low None None Unchanged None None High 3
CVE-2021-43976 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.6 Physical Low None None Unchanged None None High 3
CVE-2017-18270 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.4 Local Low Low None Unchanged None Low Low 3
CVE-2022-0850 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.4 Local Low Low None Unchanged Low None Low 3
CVE-2022-2503 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.4 Local Low High None Unchanged None High None 3
CVE-2021-45486 Oracle VM Server for x86 Unbreakable Enterprise kernel No 3.5 Adjacent Low Low None Unchanged Low None None 3
CVE-2018-9422 Oracle VM Server for x86 Unbreakable Enterprise kernel No 2.5 Local High Low None Unchanged None None Low 3