Oracle VM Server for x86 Bulletin - July 2018

Description

The Oracle VM Server for x86 Bulletin lists all CVEs that had been resolved and announced in Oracle VM Server for x86 Security Advisories (OVMSA) in the last one month prior to the release of the bulletin. Oracle VM Server for x86 Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle VM Server for x86 Bulletins may also be updated for vulnerability fixes deemed too critical to wait for the next scheduled bulletin publication date.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Oracle VM Server for x86 Bulletin fixes as soon as possible.

Patch Availability

Please see ULN Advisory http://linux.oracle.com/ovm-bulletin-pad

Oracle VM Server for x86 Bulletin Schedule

Oracle VM Server for x86 Bulletins are released on the Tuesday closest to the 17th day of January, April, July and October. The next four dates are:

  • 16 October 2018
  • 15 January 2019
  • 16 April 2019
  • 16 July 2019

References

Modification History

2018-September-18 Rev 3. New CVEs added.
2018-August-20 Rev 2. New CVEs added.
2018-July-17 Rev 1. Initial Release

Oracle VM Server for x86 Executive Summary

This Oracle VM Server for x86 Bulletin contains 28 new security fixes for the Oracle VM Server for x86.  13 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password. 

Oracle VM Server for x86 Risk Matrix

Revision 3: Published on 2018-09-18

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2018-10938 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-14678 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-15594 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-5390 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-5740 Oracle VM Server for x86 bind Undefined 3.3,3.4

Revision 2: Published on 2018-08-20

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2018-3646 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.7 Local Medium None Complete None None 3.4
CVE-2018-3646 Oracle VM Server for x86 xen No 4.7 Local Medium None Complete None None 3.4
CVE-2017-18344 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-3620 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-5391 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4
CVE-2018-7566 Oracle VM Server for x86 Unbreakable Enterprise kernel Undefined 3.4

Revision 1: Published on 2018-07-17

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2017-18017 Oracle VM Server for x86 Unbreakable Enterprise kernel Yes 10.0 Network Low None Complete Complete Complete 3.4
CVE-2017-15670 Oracle VM Server for x86 glibc Yes 7.5 Network Low None Partial Partial Partial 3.3,3.4
CVE-2017-15804 Oracle VM Server for x86 glibc Yes 7.5 Network Low None Partial Partial Partial 3.3,3.4
CVE-2018-8781 Oracle VM Server for x86 Unbreakable Enterprise kernel No 7.2 Local Low None Complete Complete Complete 3.3
CVE-2017-11600 Oracle VM Server for x86 Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 3.3,3.4
CVE-2018-12020 Oracle VM Server for x86 gnupg2 Yes 5.0 Network Low None None Partial None 3.3,3.4
CVE-2018-1130 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.9 Local Low None None None Complete 3.3,3.4
CVE-2018-5803 Oracle VM Server for x86 Unbreakable Enterprise kernel No 4.9 Local Low None None None Complete 3.3,3.4
CVE-2018-3639 Oracle VM Server for x86 qemu-kvm No 4.9 Local Low None Complete None None 3.4
CVE-2018-3639 Oracle VM Server for x86 xen No 4.9 Local Low None Complete None None 3.4
CVE-2018-3665 Oracle VM Server for x86 xen No 4.7 Local Medium None Complete None None 3.4
CVE-2015-8575 Oracle VM Server for x86 Unbreakable Enterprise kernel No 2.1 Local Low None Partial None None 3.3
CVE-2017-7616 Oracle VM Server for x86 Unbreakable Enterprise kernel No 2.1 Local Low None Partial None None 3.3,3.4
CVE-2018-10087 Oracle VM Server for x86 Unbreakable Enterprise kernel No 2.1 Local Low None None None Partial 3.3,3.4
CVE-2018-10124 Oracle VM Server for x86 Unbreakable Enterprise kernel No 2.1 Local Low None None None Partial 3.3,3.4
CVE-2017-13672 Oracle VM Server for x86 qemu-kvm No 2.1 Local Low None None None Partial 3.4
CVE-2018-5683 Oracle VM Server for x86 qemu-kvm No 2.1 Local Low None None None Partial 3.4
CVE-2018-7858 Oracle VM Server for x86 qemu-kvm No 2.1 Local Low None None None Partial 3.4
CVE-2017-18203 Oracle VM Server for x86 Unbreakable Enterprise kernel No 1.9 Local Medium None None None Partial 3.3