6 ms·
The CVEs are for CentOS Stream 9, not the RHEL derived CentOS 7 or Rocky/Alma 8/9. If the RHEL derived distributions were patched but not Stream it would seem
by Shakahs 4y ago
The CVEs are for CentOS Stream 9, not the RHEL derived CentOS 7 or Rocky/Alma 8/9. If the RHEL derived distributions were patched but not Stream it would seem that IBM-RedHat's promises about CentOS Stream being just as good are now provably false.
- fweimer 4y agoI'm not sure if such a promise ever existed. After all, before CentOS Stream, all security fixes went out with RHEL first and were imported into CentOS (non-Stream) only afterwards. And under the Stream development process, the fixes have to be merged into Stream eventually for the next minor RHEL release, otherwise they would be missing from that, too. The CVE tracking pages are here: https://access.redhat.com/security/cve/CVE-2023-0590 https://access.redhat.com/security/cve/CVE-2023-0590 https://access.redhat.com/security/cve/CVE-2023-1249 https://access.redhat.com/security/cve/CVE-2023-1249 https://access.redhat.com/security/cve/CVE-2023-1252 https://access.redhat.com/security/cve/CVE-2023-1252 Based on these data, it seems that the commercially supported versions are still unfixed (if they were impacted in the first place). Bugzilla records show that the corresponding security tracking bugs were filed publicly from the start: https://bugzilla.redhat.com/show_bug.cgi?id=2165741 https://bugzilla.redhat.com/show_bug.cgi?id=2165741 (CVE-2023-0590) https://bugzilla.redhat.com/show_bug.cgi?id=2169719 https://bugzilla.redhat.com/show_bug.cgi?id=2169719 (CVE-2023-1249) https://bugzilla.redhat.com/show_bug.cgi?id=2176140 https://bugzilla.redhat.com/show_bug.cgi?id=2176140 (CVE-2023-1252) So the Neowin headline is a bit misleading because Red Hat disclosed these issues publicly (presumably after consultation with the reporters) even before the 90-day timer expired in the Google bug tracker. (Disclaimer: I work for Red Hat, but are not involved in security anymore.)
- mogwire 4y agoAdditionally these are moderate CVEs and Red Hat, per their lifecycle page, patches them at their will. During the Full Support Phase, Red Hat defined Critical and Important Security errata advisories (RHSAs) and Urgent and Selected (at Red Hat discretion) High Priority Bug Fix errata advisories (RHBAs) may be released as they become available. Other errata advisories may be delivered as appropriate.
- nubinetwork 4y agoReading the article, they seem to be confusing CentOS and Stream... or intentionally trying to confuse the two.
- INTPenis 4y agoDoesn't surprise me really. RHEL has priority for CVE's, always had, there is no reason for them to "test" CVE patches in CentOS Stream. So this really speaks volumes about their commitment to CentOS.
- dralley 4y agoRHEL doesn't have these patches either. Because they're local exploits and not all that important in the grand scheme - they're everywhere and you have to already be pwned for these to benefit an attacker. Typically fixes like these would just be bundled together and wait for a regular release rather than be pushed out immediately.
- locust495 4y agoI think Red Hat only receives priority for embargoed CVEs. Other CVEs are done first on CentOS Stream.
- carlwgeorge 4y agoRocky and Alma are vulnerable to these CVEs too, as is RHEL. As a matter of fact, CentOS Stream 9 already has the fix to one of the CVEs. The rebuilds have to wait for it to show up in RHEL before they can rebuild it.