ALT Vulnerability

This commit is contained in:
Иван Пепеляев 2024-07-10 03:04:08 +00:00
parent 9814cece1b
commit 01df0dfa5a
12 changed files with 5776 additions and 0 deletions

View File

@ -0,0 +1,302 @@
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20249499",
"Version": "oval:org.altlinux.errata:def:20249499",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-9499: package `erlang` update to version 24.3.4.13-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-9499",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-9499",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-01664",
"RefURL": "https://bdu.fstec.ru/vul/2023-01664",
"Source": "BDU"
},
{
"RefID": "BDU:2023-03852",
"RefURL": "https://bdu.fstec.ru/vul/2023-03852",
"Source": "BDU"
},
{
"RefID": "CVE-2016-1000107",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-1000107",
"Source": "CVE"
},
{
"RefID": "CVE-2020-35733",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-35733",
"Source": "CVE"
},
{
"RefID": "CVE-2022-37026",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-37026",
"Source": "CVE"
}
],
"Description": "This update upgrades erlang to version 24.3.4.13-alt1. \nSecurity Fix(es):\n\n * BDU:2023-01664: Уязвимость языка программирования Erlang, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить доступ к конфиденциальным данным\n\n * BDU:2023-03852: Уязвимость компонента OTP языка программирования Erlang, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2016-1000107: inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an \"httpoxy\" issue.\n\n * CVE-2020-35733: An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.\n\n * CVE-2022-37026: In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-07-09"
},
"Updated": {
"Date": "2024-07-09"
},
"BDUs": [
{
"ID": "BDU:2023-01664",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2023-01664",
"Impact": "High",
"Public": "20210115"
},
{
"ID": "BDU:2023-03852",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-287",
"Href": "https://bdu.fstec.ru/vul/2023-03852",
"Impact": "Critical",
"Public": "20220617"
}
],
"CVEs": [
{
"ID": "CVE-2016-1000107",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-601",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-1000107",
"Impact": "Low",
"Public": "20191210"
},
{
"ID": "CVE-2020-35733",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-35733",
"Impact": "High",
"Public": "20210115"
},
{
"ID": "CVE-2022-37026",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-37026",
"Impact": "Critical",
"Public": "20220921"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20249499001",
"Comment": "erlang is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499002",
"Comment": "erlang-common_test is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499003",
"Comment": "erlang-common_test-bin is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499004",
"Comment": "erlang-common_test-common is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499005",
"Comment": "erlang-common_test-debug is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499006",
"Comment": "erlang-common_test-devel is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499007",
"Comment": "erlang-common_test-native is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499008",
"Comment": "erlang-devel is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499009",
"Comment": "erlang-doc is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499010",
"Comment": "erlang-doc-chunks is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499011",
"Comment": "erlang-doc-html is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499012",
"Comment": "erlang-doc-pdf is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499013",
"Comment": "erlang-emacs is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499014",
"Comment": "erlang-examples is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499015",
"Comment": "erlang-full is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499016",
"Comment": "erlang-jinterface is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499017",
"Comment": "erlang-jinterface-debug is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499018",
"Comment": "erlang-jinterface-native is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499019",
"Comment": "erlang-man is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499020",
"Comment": "erlang-megaco is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499021",
"Comment": "erlang-megaco-debug is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499022",
"Comment": "erlang-megaco-devel is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499023",
"Comment": "erlang-megaco-drivers is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499024",
"Comment": "erlang-megaco-native is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499025",
"Comment": "erlang-odbc is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499026",
"Comment": "erlang-odbc-debug is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499027",
"Comment": "erlang-odbc-devel is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499028",
"Comment": "erlang-odbc-native is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499029",
"Comment": "erlang-odbc-server is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499030",
"Comment": "erlang-otp is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499031",
"Comment": "erlang-otp-bin is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499032",
"Comment": "erlang-otp-common is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499033",
"Comment": "erlang-otp-debug is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499034",
"Comment": "erlang-otp-devel is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499035",
"Comment": "erlang-otp-full is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499036",
"Comment": "erlang-otp-native is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499037",
"Comment": "erlang-visual is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499038",
"Comment": "erlang-visual-common is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499039",
"Comment": "erlang-visual-debug is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499040",
"Comment": "erlang-visual-devel is earlier than 1:24.3.4.13-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249499041",
"Comment": "erlang-visual-native is earlier than 1:24.3.4.13-alt1"
}
]
}
]
}
}
]
}

View File

@ -0,0 +1,274 @@
{
"TextFileContent54Objects": [
{
"ID": "oval:org.altlinux.errata:obj:3001",
"Version": "1",
"Comment": "Evaluate `/etc/os-release` file content",
"Path": {
"Datatype": "string",
"Text": "/etc"
},
"Filepath": {
"Datatype": "string",
"Text": "os-release"
},
"Pattern": {
"Datatype": "string",
"Operation": "pattern match",
"Text": "cpe:\\/o:alt:sp(?:server|workstation):(\\d\\.\\d)"
},
"Instance": {
"Datatype": "int",
"Text": "1"
}
}
],
"RPMInfoObjects": [
{
"ID": "oval:org.altlinux.errata:obj:20249499001",
"Version": "1",
"Comment": "erlang is installed",
"Name": "erlang"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499002",
"Version": "1",
"Comment": "erlang-common_test is installed",
"Name": "erlang-common_test"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499003",
"Version": "1",
"Comment": "erlang-common_test-bin is installed",
"Name": "erlang-common_test-bin"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499004",
"Version": "1",
"Comment": "erlang-common_test-common is installed",
"Name": "erlang-common_test-common"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499005",
"Version": "1",
"Comment": "erlang-common_test-debug is installed",
"Name": "erlang-common_test-debug"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499006",
"Version": "1",
"Comment": "erlang-common_test-devel is installed",
"Name": "erlang-common_test-devel"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499007",
"Version": "1",
"Comment": "erlang-common_test-native is installed",
"Name": "erlang-common_test-native"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499008",
"Version": "1",
"Comment": "erlang-devel is installed",
"Name": "erlang-devel"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499009",
"Version": "1",
"Comment": "erlang-doc is installed",
"Name": "erlang-doc"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499010",
"Version": "1",
"Comment": "erlang-doc-chunks is installed",
"Name": "erlang-doc-chunks"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499011",
"Version": "1",
"Comment": "erlang-doc-html is installed",
"Name": "erlang-doc-html"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499012",
"Version": "1",
"Comment": "erlang-doc-pdf is installed",
"Name": "erlang-doc-pdf"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499013",
"Version": "1",
"Comment": "erlang-emacs is installed",
"Name": "erlang-emacs"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499014",
"Version": "1",
"Comment": "erlang-examples is installed",
"Name": "erlang-examples"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499015",
"Version": "1",
"Comment": "erlang-full is installed",
"Name": "erlang-full"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499016",
"Version": "1",
"Comment": "erlang-jinterface is installed",
"Name": "erlang-jinterface"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499017",
"Version": "1",
"Comment": "erlang-jinterface-debug is installed",
"Name": "erlang-jinterface-debug"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499018",
"Version": "1",
"Comment": "erlang-jinterface-native is installed",
"Name": "erlang-jinterface-native"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499019",
"Version": "1",
"Comment": "erlang-man is installed",
"Name": "erlang-man"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499020",
"Version": "1",
"Comment": "erlang-megaco is installed",
"Name": "erlang-megaco"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499021",
"Version": "1",
"Comment": "erlang-megaco-debug is installed",
"Name": "erlang-megaco-debug"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499022",
"Version": "1",
"Comment": "erlang-megaco-devel is installed",
"Name": "erlang-megaco-devel"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499023",
"Version": "1",
"Comment": "erlang-megaco-drivers is installed",
"Name": "erlang-megaco-drivers"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499024",
"Version": "1",
"Comment": "erlang-megaco-native is installed",
"Name": "erlang-megaco-native"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499025",
"Version": "1",
"Comment": "erlang-odbc is installed",
"Name": "erlang-odbc"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499026",
"Version": "1",
"Comment": "erlang-odbc-debug is installed",
"Name": "erlang-odbc-debug"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499027",
"Version": "1",
"Comment": "erlang-odbc-devel is installed",
"Name": "erlang-odbc-devel"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499028",
"Version": "1",
"Comment": "erlang-odbc-native is installed",
"Name": "erlang-odbc-native"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499029",
"Version": "1",
"Comment": "erlang-odbc-server is installed",
"Name": "erlang-odbc-server"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499030",
"Version": "1",
"Comment": "erlang-otp is installed",
"Name": "erlang-otp"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499031",
"Version": "1",
"Comment": "erlang-otp-bin is installed",
"Name": "erlang-otp-bin"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499032",
"Version": "1",
"Comment": "erlang-otp-common is installed",
"Name": "erlang-otp-common"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499033",
"Version": "1",
"Comment": "erlang-otp-debug is installed",
"Name": "erlang-otp-debug"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499034",
"Version": "1",
"Comment": "erlang-otp-devel is installed",
"Name": "erlang-otp-devel"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499035",
"Version": "1",
"Comment": "erlang-otp-full is installed",
"Name": "erlang-otp-full"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499036",
"Version": "1",
"Comment": "erlang-otp-native is installed",
"Name": "erlang-otp-native"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499037",
"Version": "1",
"Comment": "erlang-visual is installed",
"Name": "erlang-visual"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499038",
"Version": "1",
"Comment": "erlang-visual-common is installed",
"Name": "erlang-visual-common"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499039",
"Version": "1",
"Comment": "erlang-visual-debug is installed",
"Name": "erlang-visual-debug"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499040",
"Version": "1",
"Comment": "erlang-visual-devel is installed",
"Name": "erlang-visual-devel"
},
{
"ID": "oval:org.altlinux.errata:obj:20249499041",
"Version": "1",
"Comment": "erlang-visual-native is installed",
"Name": "erlang-visual-native"
}
]
}

View File

@ -0,0 +1,23 @@
{
"TextFileContent54State": [
{
"ID": "oval:org.altlinux.errata:ste:3001",
"Version": "1",
"Text": {}
}
],
"RPMInfoStates": [
{
"ID": "oval:org.altlinux.errata:ste:20249499001",
"Version": "1",
"Comment": "package EVR is earlier than 1:24.3.4.13-alt1",
"Arch": {},
"EVR": {
"Text": "1:24.3.4.13-alt1",
"Datatype": "evr_string",
"Operation": "less than"
},
"Subexpression": {}
}
]
}

View File

@ -0,0 +1,510 @@
{
"TextFileContent54Tests": [
{
"ID": "oval:org.altlinux.errata:tst:3001",
"Version": "1",
"Check": "all",
"Comment": "ALT Linux based on branch 'c9f2' must be installed",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:3001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:3001"
}
}
],
"RPMInfoTests": [
{
"ID": "oval:org.altlinux.errata:tst:20249499001",
"Version": "1",
"Check": "all",
"Comment": "erlang is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499002",
"Version": "1",
"Check": "all",
"Comment": "erlang-common_test is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499002"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499003",
"Version": "1",
"Check": "all",
"Comment": "erlang-common_test-bin is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499003"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499004",
"Version": "1",
"Check": "all",
"Comment": "erlang-common_test-common is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499004"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499005",
"Version": "1",
"Check": "all",
"Comment": "erlang-common_test-debug is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499005"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499006",
"Version": "1",
"Check": "all",
"Comment": "erlang-common_test-devel is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499006"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499007",
"Version": "1",
"Check": "all",
"Comment": "erlang-common_test-native is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499007"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499008",
"Version": "1",
"Check": "all",
"Comment": "erlang-devel is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499008"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499009",
"Version": "1",
"Check": "all",
"Comment": "erlang-doc is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499009"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499010",
"Version": "1",
"Check": "all",
"Comment": "erlang-doc-chunks is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499010"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499011",
"Version": "1",
"Check": "all",
"Comment": "erlang-doc-html is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499011"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499012",
"Version": "1",
"Check": "all",
"Comment": "erlang-doc-pdf is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499012"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499013",
"Version": "1",
"Check": "all",
"Comment": "erlang-emacs is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499013"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499014",
"Version": "1",
"Check": "all",
"Comment": "erlang-examples is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499014"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499015",
"Version": "1",
"Check": "all",
"Comment": "erlang-full is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499015"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499016",
"Version": "1",
"Check": "all",
"Comment": "erlang-jinterface is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499016"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499017",
"Version": "1",
"Check": "all",
"Comment": "erlang-jinterface-debug is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499017"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499018",
"Version": "1",
"Check": "all",
"Comment": "erlang-jinterface-native is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499018"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499019",
"Version": "1",
"Check": "all",
"Comment": "erlang-man is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499019"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499020",
"Version": "1",
"Check": "all",
"Comment": "erlang-megaco is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499020"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499021",
"Version": "1",
"Check": "all",
"Comment": "erlang-megaco-debug is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499021"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499022",
"Version": "1",
"Check": "all",
"Comment": "erlang-megaco-devel is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499022"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499023",
"Version": "1",
"Check": "all",
"Comment": "erlang-megaco-drivers is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499023"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499024",
"Version": "1",
"Check": "all",
"Comment": "erlang-megaco-native is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499024"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499025",
"Version": "1",
"Check": "all",
"Comment": "erlang-odbc is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499025"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499026",
"Version": "1",
"Check": "all",
"Comment": "erlang-odbc-debug is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499026"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499027",
"Version": "1",
"Check": "all",
"Comment": "erlang-odbc-devel is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499027"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499028",
"Version": "1",
"Check": "all",
"Comment": "erlang-odbc-native is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499028"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499029",
"Version": "1",
"Check": "all",
"Comment": "erlang-odbc-server is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499029"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499030",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499030"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499031",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp-bin is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499031"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499032",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp-common is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499032"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499033",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp-debug is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499033"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499034",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp-devel is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499034"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499035",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp-full is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499035"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499036",
"Version": "1",
"Check": "all",
"Comment": "erlang-otp-native is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499036"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499037",
"Version": "1",
"Check": "all",
"Comment": "erlang-visual is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499037"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499038",
"Version": "1",
"Check": "all",
"Comment": "erlang-visual-common is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499038"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499039",
"Version": "1",
"Check": "all",
"Comment": "erlang-visual-debug is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499039"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499040",
"Version": "1",
"Check": "all",
"Comment": "erlang-visual-devel is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499040"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249499041",
"Version": "1",
"Check": "all",
"Comment": "erlang-visual-native is earlier than 1:24.3.4.13-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249499041"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249499001"
}
}
]
}

View File

@ -0,0 +1,897 @@
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20249452",
"Version": "oval:org.altlinux.errata:def:20249452",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-9452: package `qemu` update to version 8.2.4-alt0.p10.1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-9452",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-9452",
"Source": "ALTPU"
},
{
"RefID": "BDU:2024-03304",
"RefURL": "https://bdu.fstec.ru/vul/2024-03304",
"Source": "BDU"
},
{
"RefID": "BDU:2024-03819",
"RefURL": "https://bdu.fstec.ru/vul/2024-03819",
"Source": "BDU"
},
{
"RefID": "BDU:2024-04887",
"RefURL": "https://bdu.fstec.ru/vul/2024-04887",
"Source": "BDU"
},
{
"RefID": "CVE-2024-3446",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-3446",
"Source": "CVE"
},
{
"RefID": "CVE-2024-3447",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-3447",
"Source": "CVE"
},
{
"RefID": "CVE-2024-3567",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-3567",
"Source": "CVE"
}
],
"Description": "This update upgrades qemu to version 8.2.4-alt0.p10.1. \nSecurity Fix(es):\n\n * BDU:2024-03304: Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2024-03819: Уязвимость функции sdhci_write_dataport эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2024-04887: Уязвимость функции update_sctp_checksum() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2024-3446: A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.\n\n * CVE-2024-3447: description unavailable\n\n * CVE-2024-3567: A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-07-10"
},
"Updated": {
"Date": "2024-07-10"
},
"BDUs": [
{
"ID": "BDU:2024-03304",
"CVSS": "AV:L/AC:L/Au:M/C:C/I:C/A:C",
"CVSS3": "AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"CWE": "CWE-415",
"Href": "https://bdu.fstec.ru/vul/2024-03304",
"Impact": "High",
"Public": "20240409"
},
{
"ID": "BDU:2024-03819",
"CVSS": "AV:L/AC:L/Au:M/C:N/I:N/A:C",
"CVSS3": "AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
"CWE": "CWE-122",
"Href": "https://bdu.fstec.ru/vul/2024-03819",
"Impact": "Low",
"Public": "20240404"
},
{
"ID": "BDU:2024-04887",
"CVSS": "AV:L/AC:L/Au:S/C:N/I:N/A:C",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-617",
"Href": "https://bdu.fstec.ru/vul/2024-04887",
"Impact": "Low",
"Public": "20240410"
}
],
"CVEs": [
{
"ID": "CVE-2024-3446",
"CWE": "CWE-415",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-3446",
"Impact": "None",
"Public": "20240409"
},
{
"ID": "CVE-2024-3567",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-617",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-3567",
"Impact": "Low",
"Public": "20240410"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20249452001",
"Comment": "qemu is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452002",
"Comment": "qemu-audio-alsa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452003",
"Comment": "qemu-audio-dbus is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452004",
"Comment": "qemu-audio-oss is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452005",
"Comment": "qemu-audio-pa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452006",
"Comment": "qemu-audio-pipewire is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452007",
"Comment": "qemu-audio-sdl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452008",
"Comment": "qemu-audio-spice is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452009",
"Comment": "qemu-aux is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452010",
"Comment": "qemu-block-blkio is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452011",
"Comment": "qemu-block-curl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452012",
"Comment": "qemu-block-dmg is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452013",
"Comment": "qemu-block-gluster is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452014",
"Comment": "qemu-block-iscsi is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452015",
"Comment": "qemu-block-nfs is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452016",
"Comment": "qemu-block-rbd is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452017",
"Comment": "qemu-block-ssh is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452018",
"Comment": "qemu-block-vitastor is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452019",
"Comment": "qemu-char-spice is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452020",
"Comment": "qemu-common is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452021",
"Comment": "qemu-device-display-qxl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452022",
"Comment": "qemu-device-display-vhost-user-gpu is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452023",
"Comment": "qemu-device-display-virtio-gpu is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452024",
"Comment": "qemu-device-display-virtio-gpu-ccw is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452025",
"Comment": "qemu-device-display-virtio-gpu-gl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452026",
"Comment": "qemu-device-display-virtio-gpu-pci is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452027",
"Comment": "qemu-device-display-virtio-gpu-pci-gl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452028",
"Comment": "qemu-device-display-virtio-vga is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452029",
"Comment": "qemu-device-display-virtio-vga-gl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452030",
"Comment": "qemu-device-usb-host is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452031",
"Comment": "qemu-device-usb-redirect is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452032",
"Comment": "qemu-device-usb-smartcard is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452033",
"Comment": "qemu-doc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452034",
"Comment": "qemu-guest-agent is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452035",
"Comment": "qemu-img is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452036",
"Comment": "qemu-kvm is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452037",
"Comment": "qemu-kvm-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452038",
"Comment": "qemu-pr-helper is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452039",
"Comment": "qemu-system is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452040",
"Comment": "qemu-system-aarch64 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452041",
"Comment": "qemu-system-aarch64-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452042",
"Comment": "qemu-system-alpha is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452043",
"Comment": "qemu-system-alpha-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452044",
"Comment": "qemu-system-arm is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452045",
"Comment": "qemu-system-arm-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452046",
"Comment": "qemu-system-avr is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452047",
"Comment": "qemu-system-avr-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452048",
"Comment": "qemu-system-cris is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452049",
"Comment": "qemu-system-cris-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452050",
"Comment": "qemu-system-hppa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452051",
"Comment": "qemu-system-hppa-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452052",
"Comment": "qemu-system-loongarch is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452053",
"Comment": "qemu-system-loongarch-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452054",
"Comment": "qemu-system-m68k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452055",
"Comment": "qemu-system-m68k-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452056",
"Comment": "qemu-system-microblaze is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452057",
"Comment": "qemu-system-microblaze-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452058",
"Comment": "qemu-system-mips is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452059",
"Comment": "qemu-system-mips-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452060",
"Comment": "qemu-system-nios2 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452061",
"Comment": "qemu-system-nios2-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452062",
"Comment": "qemu-system-or1k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452063",
"Comment": "qemu-system-or1k-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452064",
"Comment": "qemu-system-ppc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452065",
"Comment": "qemu-system-ppc-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452066",
"Comment": "qemu-system-riscv is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452067",
"Comment": "qemu-system-riscv-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452068",
"Comment": "qemu-system-rx is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452069",
"Comment": "qemu-system-rx-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452070",
"Comment": "qemu-system-s390x is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452071",
"Comment": "qemu-system-s390x-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452072",
"Comment": "qemu-system-sh4 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452073",
"Comment": "qemu-system-sh4-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452074",
"Comment": "qemu-system-sparc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452075",
"Comment": "qemu-system-sparc-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452076",
"Comment": "qemu-system-tricore is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452077",
"Comment": "qemu-system-tricore-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452078",
"Comment": "qemu-system-x86 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452079",
"Comment": "qemu-system-x86-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452080",
"Comment": "qemu-system-xtensa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452081",
"Comment": "qemu-system-xtensa-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452082",
"Comment": "qemu-tests is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452083",
"Comment": "qemu-tools is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452084",
"Comment": "qemu-ui-curses is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452085",
"Comment": "qemu-ui-dbus is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452086",
"Comment": "qemu-ui-egl-headless is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452087",
"Comment": "qemu-ui-gtk is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452088",
"Comment": "qemu-ui-opengl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452089",
"Comment": "qemu-ui-sdl is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452090",
"Comment": "qemu-ui-spice-app is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452091",
"Comment": "qemu-ui-spice-core is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452092",
"Comment": "qemu-user is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452093",
"Comment": "qemu-user-aarch64 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452094",
"Comment": "qemu-user-alpha is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452095",
"Comment": "qemu-user-arm is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452096",
"Comment": "qemu-user-avr is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452097",
"Comment": "qemu-user-binfmt is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452098",
"Comment": "qemu-user-binfmt-aarch64 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452099",
"Comment": "qemu-user-binfmt-alpha is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452100",
"Comment": "qemu-user-binfmt-arm is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452101",
"Comment": "qemu-user-binfmt-avr is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452102",
"Comment": "qemu-user-binfmt-cris is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452103",
"Comment": "qemu-user-binfmt-hexagon is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452104",
"Comment": "qemu-user-binfmt-hppa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452105",
"Comment": "qemu-user-binfmt-loongarch is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452106",
"Comment": "qemu-user-binfmt-m68k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452107",
"Comment": "qemu-user-binfmt-microblaze is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452108",
"Comment": "qemu-user-binfmt-mips is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452109",
"Comment": "qemu-user-binfmt-nios2 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452110",
"Comment": "qemu-user-binfmt-or1k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452111",
"Comment": "qemu-user-binfmt-ppc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452112",
"Comment": "qemu-user-binfmt-riscv is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452113",
"Comment": "qemu-user-binfmt-rx is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452114",
"Comment": "qemu-user-binfmt-s390x is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452115",
"Comment": "qemu-user-binfmt-sh4 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452116",
"Comment": "qemu-user-binfmt-sparc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452117",
"Comment": "qemu-user-binfmt-tricore is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452118",
"Comment": "qemu-user-binfmt-x86 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452119",
"Comment": "qemu-user-binfmt-xtensa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452120",
"Comment": "qemu-user-cris is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452121",
"Comment": "qemu-user-hexagon is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452122",
"Comment": "qemu-user-hppa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452123",
"Comment": "qemu-user-loongarch is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452124",
"Comment": "qemu-user-m68k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452125",
"Comment": "qemu-user-microblaze is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452126",
"Comment": "qemu-user-mips is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452127",
"Comment": "qemu-user-nios2 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452128",
"Comment": "qemu-user-or1k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452129",
"Comment": "qemu-user-ppc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452130",
"Comment": "qemu-user-riscv is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452131",
"Comment": "qemu-user-rx is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452132",
"Comment": "qemu-user-s390x is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452133",
"Comment": "qemu-user-sh4 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452134",
"Comment": "qemu-user-sparc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452135",
"Comment": "qemu-user-static is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452136",
"Comment": "qemu-user-static-aarch64 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452137",
"Comment": "qemu-user-static-alpha is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452138",
"Comment": "qemu-user-static-arm is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452139",
"Comment": "qemu-user-static-avr is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452140",
"Comment": "qemu-user-static-binfmt is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452141",
"Comment": "qemu-user-static-binfmt-aarch64 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452142",
"Comment": "qemu-user-static-binfmt-alpha is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452143",
"Comment": "qemu-user-static-binfmt-arm is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452144",
"Comment": "qemu-user-static-binfmt-avr is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452145",
"Comment": "qemu-user-static-binfmt-cris is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452146",
"Comment": "qemu-user-static-binfmt-hexagon is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452147",
"Comment": "qemu-user-static-binfmt-hppa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452148",
"Comment": "qemu-user-static-binfmt-loongarch is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452149",
"Comment": "qemu-user-static-binfmt-m68k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452150",
"Comment": "qemu-user-static-binfmt-microblaze is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452151",
"Comment": "qemu-user-static-binfmt-mips is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452152",
"Comment": "qemu-user-static-binfmt-nios2 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452153",
"Comment": "qemu-user-static-binfmt-or1k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452154",
"Comment": "qemu-user-static-binfmt-ppc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452155",
"Comment": "qemu-user-static-binfmt-riscv is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452156",
"Comment": "qemu-user-static-binfmt-rx is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452157",
"Comment": "qemu-user-static-binfmt-s390x is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452158",
"Comment": "qemu-user-static-binfmt-sh4 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452159",
"Comment": "qemu-user-static-binfmt-sparc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452160",
"Comment": "qemu-user-static-binfmt-tricore is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452161",
"Comment": "qemu-user-static-binfmt-x86 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452162",
"Comment": "qemu-user-static-binfmt-xtensa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452163",
"Comment": "qemu-user-static-cris is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452164",
"Comment": "qemu-user-static-hexagon is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452165",
"Comment": "qemu-user-static-hppa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452166",
"Comment": "qemu-user-static-loongarch is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452167",
"Comment": "qemu-user-static-m68k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452168",
"Comment": "qemu-user-static-microblaze is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452169",
"Comment": "qemu-user-static-mips is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452170",
"Comment": "qemu-user-static-nios2 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452171",
"Comment": "qemu-user-static-or1k is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452172",
"Comment": "qemu-user-static-ppc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452173",
"Comment": "qemu-user-static-riscv is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452174",
"Comment": "qemu-user-static-rx is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452175",
"Comment": "qemu-user-static-s390x is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452176",
"Comment": "qemu-user-static-sh4 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452177",
"Comment": "qemu-user-static-sparc is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452178",
"Comment": "qemu-user-static-tricore is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452179",
"Comment": "qemu-user-static-x86 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452180",
"Comment": "qemu-user-static-xtensa is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452181",
"Comment": "qemu-user-tricore is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452182",
"Comment": "qemu-user-x86 is earlier than 0:8.2.4-alt0.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249452183",
"Comment": "qemu-user-xtensa is earlier than 0:8.2.4-alt0.p10.1"
}
]
}
]
}
}
]
}

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,23 @@
{
"TextFileContent54State": [
{
"ID": "oval:org.altlinux.errata:ste:2001",
"Version": "1",
"Text": {}
}
],
"RPMInfoStates": [
{
"ID": "oval:org.altlinux.errata:ste:20249452001",
"Version": "1",
"Comment": "package EVR is earlier than 0:8.2.4-alt0.p10.1",
"Arch": {},
"EVR": {
"Text": "0:8.2.4-alt0.p10.1",
"Datatype": "evr_string",
"Operation": "less than"
},
"Subexpression": {}
}
]
}

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,158 @@
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20249776",
"Version": "oval:org.altlinux.errata:def:20249776",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-9776: package `kernel-image-un-def` update to version 6.1.96-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-9776",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-9776",
"Source": "ALTPU"
},
{
"RefID": "CVE-2024-39474",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-39474",
"Source": "CVE"
},
{
"RefID": "CVE-2024-39484",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-39484",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-image-un-def to version 6.1.96-alt1. \nSecurity Fix(es):\n\n * CVE-2024-39474: In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL\n\ncommit a421ef303008 (\"mm: allow !GFP_KERNEL allocations for kvmalloc\")\nincludes support for __GFP_NOFAIL, but it presents a conflict with commit\ndd544141b9eb (\"vmalloc: back off when the current task is OOM-killed\"). A\npossible scenario is as follows:\n\nprocess-a\n__vmalloc_node_range(GFP_KERNEL | __GFP_NOFAIL)\n __vmalloc_area_node()\n vm_area_alloc_pages()\n\t\t--\u003e oom-killer send SIGKILL to process-a\n if (fatal_signal_pending(current)) break;\n--\u003e return NULL;\n\nTo fix this, do not check fatal_signal_pending() in vm_area_alloc_pages()\nif __GFP_NOFAIL set.\n\nThis issue occurred during OPLUS KASAN TEST. Below is part of the log\n-\u003e oom-killer sends signal to process\n[65731.222840] [ T1308] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=/,mems_allowed=0,global_oom,task_memcg=/apps/uid_10198,task=gs.intelligence,pid=32454,uid=10198\n\n[65731.259685] [T32454] Call trace:\n[65731.259698] [T32454] dump_backtrace+0xf4/0x118\n[65731.259734] [T32454] show_stack+0x18/0x24\n[65731.259756] [T32454] dump_stack_lvl+0x60/0x7c\n[65731.259781] [T32454] dump_stack+0x18/0x38\n[65731.259800] [T32454] mrdump_common_die+0x250/0x39c [mrdump]\n[65731.259936] [T32454] ipanic_die+0x20/0x34 [mrdump]\n[65731.260019] [T32454] atomic_notifier_call_chain+0xb4/0xfc\n[65731.260047] [T32454] notify_die+0x114/0x198\n[65731.260073] [T32454] die+0xf4/0x5b4\n[65731.260098] [T32454] die_kernel_fault+0x80/0x98\n[65731.260124] [T32454] __do_kernel_fault+0x160/0x2a8\n[65731.260146] [T32454] do_bad_area+0x68/0x148\n[65731.260174] [T32454] do_mem_abort+0x151c/0x1b34\n[65731.260204] [T32454] el1_abort+0x3c/0x5c\n[65731.260227] [T32454] el1h_64_sync_handler+0x54/0x90\n[65731.260248] [T32454] el1h_64_sync+0x68/0x6c\n\n[65731.260269] [T32454] z_erofs_decompress_queue+0x7f0/0x2258\n--\u003e be-\u003edecompressed_pages = kvcalloc(be-\u003enr_pages, sizeof(struct page *), GFP_KERNEL | __GFP_NOFAIL);\n\tkernel panic by NULL pointer dereference.\n\terofs assume kvmalloc with __GFP_NOFAIL never return NULL.\n[65731.260293] [T32454] z_erofs_runqueue+0xf30/0x104c\n[65731.260314] [T32454] z_erofs_readahead+0x4f0/0x968\n[65731.260339] [T32454] read_pages+0x170/0xadc\n[65731.260364] [T32454] page_cache_ra_unbounded+0x874/0xf30\n[65731.260388] [T32454] page_cache_ra_order+0x24c/0x714\n[65731.260411] [T32454] filemap_fault+0xbf0/0x1a74\n[65731.260437] [T32454] __do_fault+0xd0/0x33c\n[65731.260462] [T32454] handle_mm_fault+0xf74/0x3fe0\n[65731.260486] [T32454] do_mem_abort+0x54c/0x1b34\n[65731.260509] [T32454] el0_da+0x44/0x94\n[65731.260531] [T32454] el0t_64_sync_handler+0x98/0xb4\n[65731.260553] [T32454] el0t_64_sync+0x198/0x19c\n\n * CVE-2024-39484: In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: davinci: Don't strip remove function when driver is builtin\n\nUsing __exit for the remove function results in the remove callback being\ndiscarded with CONFIG_MMC_DAVINCI=y. When such a device gets unbound (e.g.\nusing sysfs or hotplug), the driver is just removed without the cleanup\nbeing performed. This results in resource leaks. Fix it by compiling in the\nremove callback unconditionally.\n\nThis also fixes a W=1 modpost warning:\n\nWARNING: modpost: drivers/mmc/host/davinci_mmc: section mismatch in\nreference: davinci_mmcsd_driver+0x10 (section: .data) -\u003e\ndavinci_mmcsd_remove (section: .exit.text)",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-07-09"
},
"Updated": {
"Date": "2024-07-09"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2024-39474",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-770",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-39474",
"Impact": "Low",
"Public": "20240705"
},
{
"ID": "CVE-2024-39484",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-770",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-39484",
"Impact": "Low",
"Public": "20240705"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20249776001",
"Comment": "kernel-doc-un is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776002",
"Comment": "kernel-headers-modules-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776003",
"Comment": "kernel-headers-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776004",
"Comment": "kernel-image-domU-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776005",
"Comment": "kernel-image-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776006",
"Comment": "kernel-image-un-def-checkinstall is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776007",
"Comment": "kernel-modules-drm-ancient-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776008",
"Comment": "kernel-modules-drm-nouveau-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776009",
"Comment": "kernel-modules-drm-un-def is earlier than 1:6.1.96-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20249776010",
"Comment": "kernel-modules-staging-un-def is earlier than 1:6.1.96-alt1"
}
]
}
]
}
}
]
}

View File

@ -0,0 +1,88 @@
{
"TextFileContent54Objects": [
{
"ID": "oval:org.altlinux.errata:obj:2001",
"Version": "1",
"Comment": "Evaluate `/etc/os-release` file content",
"Path": {
"Datatype": "string",
"Text": "/etc"
},
"Filepath": {
"Datatype": "string",
"Text": "os-release"
},
"Pattern": {
"Datatype": "string",
"Operation": "pattern match",
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
},
"Instance": {
"Datatype": "int",
"Text": "1"
}
}
],
"RPMInfoObjects": [
{
"ID": "oval:org.altlinux.errata:obj:20249776001",
"Version": "1",
"Comment": "kernel-doc-un is installed",
"Name": "kernel-doc-un"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776002",
"Version": "1",
"Comment": "kernel-headers-modules-un-def is installed",
"Name": "kernel-headers-modules-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776003",
"Version": "1",
"Comment": "kernel-headers-un-def is installed",
"Name": "kernel-headers-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776004",
"Version": "1",
"Comment": "kernel-image-domU-un-def is installed",
"Name": "kernel-image-domU-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776005",
"Version": "1",
"Comment": "kernel-image-un-def is installed",
"Name": "kernel-image-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776006",
"Version": "1",
"Comment": "kernel-image-un-def-checkinstall is installed",
"Name": "kernel-image-un-def-checkinstall"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776007",
"Version": "1",
"Comment": "kernel-modules-drm-ancient-un-def is installed",
"Name": "kernel-modules-drm-ancient-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776008",
"Version": "1",
"Comment": "kernel-modules-drm-nouveau-un-def is installed",
"Name": "kernel-modules-drm-nouveau-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776009",
"Version": "1",
"Comment": "kernel-modules-drm-un-def is installed",
"Name": "kernel-modules-drm-un-def"
},
{
"ID": "oval:org.altlinux.errata:obj:20249776010",
"Version": "1",
"Comment": "kernel-modules-staging-un-def is installed",
"Name": "kernel-modules-staging-un-def"
}
]
}

View File

@ -0,0 +1,23 @@
{
"TextFileContent54State": [
{
"ID": "oval:org.altlinux.errata:ste:2001",
"Version": "1",
"Text": {}
}
],
"RPMInfoStates": [
{
"ID": "oval:org.altlinux.errata:ste:20249776001",
"Version": "1",
"Comment": "package EVR is earlier than 1:6.1.96-alt1",
"Arch": {},
"EVR": {
"Text": "1:6.1.96-alt1",
"Datatype": "evr_string",
"Operation": "less than"
},
"Subexpression": {}
}
]
}

View File

@ -0,0 +1,138 @@
{
"TextFileContent54Tests": [
{
"ID": "oval:org.altlinux.errata:tst:2001",
"Version": "1",
"Check": "all",
"Comment": "ALT Linux based on branch 'p10' must be installed",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:2001"
}
}
],
"RPMInfoTests": [
{
"ID": "oval:org.altlinux.errata:tst:20249776001",
"Version": "1",
"Check": "all",
"Comment": "kernel-doc-un is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776002",
"Version": "1",
"Check": "all",
"Comment": "kernel-headers-modules-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776002"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776003",
"Version": "1",
"Check": "all",
"Comment": "kernel-headers-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776003"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776004",
"Version": "1",
"Check": "all",
"Comment": "kernel-image-domU-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776004"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776005",
"Version": "1",
"Check": "all",
"Comment": "kernel-image-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776005"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776006",
"Version": "1",
"Check": "all",
"Comment": "kernel-image-un-def-checkinstall is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776006"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776007",
"Version": "1",
"Check": "all",
"Comment": "kernel-modules-drm-ancient-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776007"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776008",
"Version": "1",
"Check": "all",
"Comment": "kernel-modules-drm-nouveau-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776008"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776009",
"Version": "1",
"Check": "all",
"Comment": "kernel-modules-drm-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776009"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20249776010",
"Version": "1",
"Check": "all",
"Comment": "kernel-modules-staging-un-def is earlier than 1:6.1.96-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20249776010"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20249776001"
}
}
]
}