Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20250124000602.GA22935@openwall.com>
Date: Fri, 24 Jan 2025 01:06:02 +0100
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Oracle January 2025 Critical Patch Update

On Thu, Jan 23, 2025 at 09:24:14AM -0800, Alan Coopersmith wrote:
> The open source packages delivered in Oracle Linux & Oracle Solaris are
> listed separately, but these are downstreams, so I've always thought they'd
> be off topic here, since we normally only cover upstream issues, and don't
> publish every distro's notices that they've applied the latest fixes to
> rsync, openssl, glibc, or whatever upstream was fixed this week.
> 
> For those who want to see such downstream notices, you can find them at:
> 
> Oracle Linux:
>    https://linux.oracle.com/security/
>    https://oss.oracle.com/mailman/listinfo/el-errata
>    https://www.oracle.com/security-alerts/#OLBulletin
> 
> Oracle Solaris:
>    https://www.oracle.com/security-alerts/#SolarisThirdPartyBulletin

You're correct, these would generally be off-topic here.

So in this thread I am not talking about Oracle's OS distros, but about
Oracle's upstream Open Source projects.  Looking at the Critical Patch
Update, I don't know which projects fit such criteria.  Like I wrote, I
think it's MySQL and VirtualBox, but probably not only these two.
Perhaps also Java?  I'm not familiar with most of Oracle's products and
their licensing.

Also, in some cases we make exceptions for projects closely related to
or enabling Open Source ones e.g. as in the recent AMD microcode thread.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.