ELSA-2023-2487

ELSA-2023-2487 - fwupd security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2023-05-15

Description


[1.8.10-2.0.1]
- Drop pesign.service restart in postun [Orabug: 34760075]
- Update signing certificate [JIRA: OLDIS-16371]
- Rebuild for SecureBoot signatures [Orabug: 33801813]
- Build with the updated Oracle certificate
- Use oraclesecureboot301 as certdir [Orabug: 29881368]
- Use new signing certificate (Alex Burmashev)
- Update SBAT data to include Oracle [Oracle: 33072886]

[1.8.10-2]
- Rebuild because distrobaker did entirely the wrong thing.
- Resolves: rhbz#2128384, needed for rhbz#2119436 and rhbz#2128384

[1.8.10-1]
- Rebase to latest upstream release to fix multiple ESP detection problems
- Resolves: rhbz#2128384, needed for rhbz#2119436 and rhbz#2128384

[1.7.10-1]
- New upstream release
- Resolves: rhbz#2129280

[1.7.9-2]
- Include the new dbx updates on the filesystem; clients typically do not have LVFS enabled.
- Resolves: rhbz#2120708

[1.7.8-1]
- New upstream release
- Resolves: rhbz#2059075

[1.7.4-3]
- Disable the Logitech bulkcontroller plugin to avoid adding a dep to protobuf-c
which lives in AppStream, not BaseOS.
- Use the efi_vendor variable from EFI-RPM
- Resolves: rhbz#2064904

[1.7.4-1]
- New upstream release
- Backport Fedora 34 changes
- Include support for Lenovo TBT4 Docking stations
- Do not cause systemd-modules-load failures
- Build against a new enough pesign
- Resolves: rhbz#2007520

[1.7.1-1]
- New upstream release
- Backport Fedora 34 changes
- Include support for Dell TBT4 Docking stations
- Resolves: rhbz#1974347
- Resolves: rhbz#1991426

[1.5.9-4]
- Rebuilt to use redhatsecureboot503 signatures
- Undo last Fedora sync to use the RHEL-specific patches
- Resolves: rhbz#2007520

[1.5.9-3]
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688

[1.5.9-2]
- Rebuilt for RHEL 9 BETA for openssl 3.0
Related: rhbz#1971065

[1.5.9-1]
- Rebase to include the SBAT metadata section to allow fixing BootHole
- Resolves: rhbz#1951030

[1.5.5-4]
- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[1.5.5-3]
- Backport a patch from master to drop the python3-pillow dep
- Resolves: rhbz#1935838


Related CVEs


CVE-2022-34301
CVE-2022-34302
CVE-2022-3287
CVE-2022-34303

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 9 (aarch64) fwupd-1.8.10-2.0.1.el9.src.rpmdf3acae9d6408b2aba78a842ef78bf44-
fwupd-1.8.10-2.0.1.el9.aarch64.rpm59050e1f61f46e05d6fed91ad87041ca-
fwupd-devel-1.8.10-2.0.1.el9.aarch64.rpm945d38da3422b4cb5b7ab32fe78a62b6-
fwupd-plugin-flashrom-1.8.10-2.0.1.el9.aarch64.rpm99a3afd3f7facf020f16075d6275e260-
Oracle Linux 9 (x86_64) fwupd-1.8.10-2.0.1.el9.src.rpmdf3acae9d6408b2aba78a842ef78bf44-
fwupd-1.8.10-2.0.1.el9.x86_64.rpm2a0886d60dd41a2db105483441fbea7b-
fwupd-devel-1.8.10-2.0.1.el9.x86_64.rpm29ec0eea04d5c38f2153092fb0ccb534-
fwupd-plugin-flashrom-1.8.10-2.0.1.el9.x86_64.rpmaa6f7eb62e6b25952aeafc2b10c23532-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete