ELSA-2019-4593

ELSA-2019-4593 - kubernetes kubeadm-upgrade kubeadm-ha-setup security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2019-04-13

Description


kubernetes
[1.12.7-1.1.2]
- [OLCNE-257] fix coredns issue and minor upgrade issue

[1.12.7-1.1.1]
- [OLCNE-235] [CVE-2019-9946] portmap inserts rules at the front of the iptables nat chains

[1.12.7-1.0.1]
- Add Oracle Build Files For Version v1.12.7

kubeadm-upgrade
[0.0.1-1.0.22]
-- Bump up 1.12.7 version for coredns fix

[0.0.1-1.0.21]
-- CVE-2019-9946

[0.0.1-1.0.20]
-- CVE-2019-1002101

[0.0.1-1.0.19]
-- Bump up 1.12.6 version

[0.0.1-1.0.18]
-- OLCNE-201 upgrade from 1.9 to 1.12 fails

[0.0.1-1.0.17]
-- Update the Kubernetes version to include the conntrack fix

[0.0.1-1.0.16]
-- CVE-2019-1002100

kubeadm-ha-setup
[0.0.2-1.0.24]
- Return stdout and stderr from Run function to allow the caller decided what to display

[0.0.2-1.0.23]
- [OLCNE-170] proxy variable is inherited in remote master

[0.0.2-1.0.22]
- The Trim function doesn't work for replacing strings
- Upgrade should use the pause container instead of pause-amd64

[0.0.2-1.0.21]
- Include 1.12.7 image and update 1.13 and metric servers info

[0.0.2-1.0.20]
- Support new registries and allow for password to have a colon

[0.0.2-1.0.19]
- --force flag for full restore

[0.0.2-1.0.18]
- Change update help message

[0.0.2-1.0.17]
- Change update message, add ha install command and ask for confirmation

[0.0.2-1.0.16]
- Change upgrade command name to update

[0.0.2-1.0.15]
- Fix upgrade for point release

[0.0.2-1.0.14]
- OLCNE-79 Move file.go to config.go

[0.0.2-1.0.13]
- OLCNE-144 Feature Flag 1.13 code

[0.0.2-1.0.12]
- Add support of upgrading HA master nodes

[0.0.2-1.0.11]
- Support deploying Kubernetes version 1.13.2

[0.0.2-1.0.10]
- CVE-2018-16875

[0.0.2-1.0.9]
- Add timeout to Run() (gitlab issues #3)
- Rename path to linux-git.us.oracle.com/Kubernetes

[0.0.2-1.0.8]
- Remove releases.json dependency

[0.0.2-1.0.7]
- Pin dependent kubernetes packages

[0.0.2-1.0.6]
- Update deps for kube 1.13

[0.0.2-1.0.5]
- Add test runner in makefile and execute it in CI/CD

[0.0.2-1.0.4]
- Fix backup path issue again found by Tom Cocozzello

[0.0.2-1.0.3]
- [Orabug 29152516] Backup and restore /var/lib/kubelet/kubeadm-flags.env too
- Cleanup kube-ipvs0 interface too
- More code cleanup
- Use map for checking kernel module
- Fix client joining errors
- Addressing Tom Cocozzello's review
- Enabling IPVS in HA

[0.0.2-1.0.2]
- Update dashboard image (CVE-2018-18264)

[0.0.2-1.0.1]
- Allow Oracle certified addons to be installed via cli

kubernetes-cni
[0.6.0-2.2.1]
- [OLCNE-235] [CVE-2019-9946] portmap inserts rules at the front of the iptables nat chains

kubernetes-cni-plugins
[0.7.5-1.0.1.dev]
- Update to v0.7.5


Related CVEs


CVE-2019-9946
CVE-2019-1002101

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) kubeadm-ha-setup-0.0.2-1.0.24.el7.src.rpm0b51ab282acbb99ffefbb071562abe9bf043c9014d5d3865968a886b077b4f65ELSA-2020-5825ol7_x86_64_addons
kubeadm-upgrade-0.0.1-1.0.22.el7.src.rpm0332e8f3e6a76c6f3f188dcfda18f0bd0f6c5392757f096710162f4f42d688bfELSA-2020-5654ol7_x86_64_addons
kubernetes-1.12.7-1.1.2.el7.src.rpm315ba74a629f88badfa99003431f53d4e623dac4851d48733bb7cf0a8da169e7ELSA-2024-12329ol7_x86_64_addons
kubernetes-cni-0.6.0-2.2.1.el7.src.rpm4534e4ffadd5bbd724ed3b2afd67f31f28d600e47c075a8d05a28dadbd8de3d2ELSA-2024-12189ol7_x86_64_addons
kubernetes-cni-plugins-0.7.5-1.0.1.el7.src.rpmbc16567356ef86a767e46496d9f19ee1ff6d21b0b13ad821b5f1d38cab969b7eELBA-2024-18618ol7_x86_64_addons
kubeadm-1.12.7-1.1.2.el7.x86_64.rpmb0ff6e5d2569ecb7263ee1e291ab6da991ee04d5ed0b3b20d5ed261d0b9319ccELSA-2024-12329ol7_x86_64_addons
kubeadm-ha-setup-0.0.2-1.0.24.el7.x86_64.rpm47e665f559d1b98f0d0b882e940290f2506d521b6417e51cd0a720fbd723f9bdELSA-2020-5825ol7_x86_64_addons
kubeadm-upgrade-0.0.1-1.0.22.el7.x86_64.rpm3b1de609c2fdff0c1530a7deb5c1647afda0f70b39cc0f5869ce88c250370c00ELSA-2020-5654ol7_x86_64_addons
kubectl-1.12.7-1.1.2.el7.x86_64.rpm9789b69ef22588266aac95c848a588be6826d0a730a34dae6af65dc826db1599ELSA-2024-12329ol7_x86_64_addons
kubelet-1.12.7-1.1.2.el7.x86_64.rpmaf81d6a1104e0c4725ff6ee85b1abdd44e392d7cceb13dd917f8529bde6402caELSA-2024-12329ol7_x86_64_addons
kubernetes-cni-0.6.0-2.2.1.el7.x86_64.rpmf4944eca17235a1c0c0566ed03b88c74318da2c5321fcb2b6a77cd610637ac4bELSA-2024-12189ol7_x86_64_addons
kubernetes-cni-plugins-0.7.5-1.0.1.el7.x86_64.rpm11d2b9e50b028cf0d614ebe8ad0c925b2e03e1fe04e5cf2db0d114ae2bea0397ELBA-2024-18618ol7_x86_64_addons



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete