4 ms·
Red Hat doesn’t fix moderate CVEs immediately. Per there RHEL Lifecycle web page: “During the Full Support Phase, Red Hat defined Critical and Important Securi
by mogwire 4y ago
Red Hat doesn’t fix moderate CVEs immediately. Per there RHEL Lifecycle web page:
“During the Full Support Phase, Red Hat defined Critical and Important Security errata advisories (RHSAs) and Urgent and Selected (at Red Hat discretion) High Priority Bug Fix errata advisories (RHBAs) may be released as they become available. Other errata advisories may be delivered as appropriate.”
Seeing how all of these CVEs are considered Moderate they fall under the “delivered as appropriate”.
As usual people over react and try to make companies look like they don’t care about security, back ports, etc when all Red Hat is doing is following its own policy.
- carlwgeorge 4y agoAbsolutely agree, but one small point of clarification. One of the referenced CVEs (CVE-2023-1249) is rated low. The other two (CVE-2023-0590 and CVE-2023-1252) are rated moderate.