<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle VM Server for x86 Bulletin - January 2022 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle VM Server for x86 Bulletin Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>OVMBulletinJan2022</ID>
      </Identification>
      <Status>Final</Status>
      <Version>2.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2022-01-14T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
         <Revision>
            <Number>2.0</Number>
            <Date>2022-02-15T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
      </RevisionHistory>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle VM Server for x86 security vulnerabilities which have had security patches released for all supported versions and platforms.</Note>
   </DocumentNotes>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/ovmbulletinjan2022.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle VM Server for x86" Type="Product Family">
            <Branch Name="Oracle VM Server for x86" Type="Product Name">
               <Branch Name="3.2" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.2">Oracle VM Server for x86 3.2</FullProductName>
               </Branch>
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.3">Oracle VM Server for x86 3.3</FullProductName>
               </Branch>
               <Branch Name="3.4" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.4">Oracle VM Server for x86 3.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
     </Branch>
  </ProductTree>
<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1048</Title>
         <Notes>
               <Note Audience="All" Ordinal="1" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1048</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0007.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-4034</Title>
         <Notes>
               <Note Audience="All" Ordinal="2" Title="Details" Type="Details">This is a vulnerability in  polkit  in Oracle VM Server for x86.       A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-4034</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0006.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3752</Title>
         <Notes>
               <Note Audience="All" Ordinal="3" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3752</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0007.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-0129</Title>
         <Notes>
               <Note Audience="All" Ordinal="4" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. CVSS Base Score: 5.7 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-0129</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.7</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0007.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20321</Title>
         <Notes>
               <Note Audience="All" Ordinal="5" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20321</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0007.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-4155</Title>
         <Notes>
               <Note Audience="All" Ordinal="6" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-4155</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0007.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3753</Title>
         <Notes>
               <Note Audience="All" Ordinal="7" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3753</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/OVMSA-2022-0007.html</URL>
                  <ProductID>P-4455V-3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
</cvrf:cvrfdoc>
