-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: redis security update
Advisory ID:       RHSA-2019:2621-01
Product:           Red Hat Enterprise Linux OpenStack Platform
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:2621
Issue date:        2019-09-03
CVE Names:         CVE-2019-10192 
====================================================================
1. Summary:

An update for redis is now available for Red Hat OpenStack Platform 14.0
(Rocky).

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat OpenStack Platform 14.0 - ppc64le, x86_64

3. Description:

Redis is an advanced key-value store. It is often referred to as a
data-structure server since keys can contain strings, hashes, lists, sets,
and sorted sets. For performance, Redis works with an in-memory data set.
You can persist it either by dumping the data set to disk every once in a
while, or by appending each command to a log.

Security Fix(es):

* redis: Heap buffer overflow in HyperLogLog triggered by malicious client
(CVE-2019-10192)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1723918 - CVE-2019-10192 redis: Heap buffer overflow in HyperLogLog triggered by malicious client

6. Package List:

Red Hat OpenStack Platform 14.0:

Source:
redis-3.2.8-4.el7ost.src.rpm

ppc64le:
redis-3.2.8-4.el7ost.ppc64le.rpm
redis-debuginfo-3.2.8-4.el7ost.ppc64le.rpm

x86_64:
redis-3.2.8-4.el7ost.x86_64.rpm
redis-debuginfo-3.2.8-4.el7ost.x86_64.rpm

Red Hat OpenStack Platform 14.0:

Source:
redis-3.2.8-4.el7ost.src.rpm

ppc64le:
redis-3.2.8-4.el7ost.ppc64le.rpm
redis-debuginfo-3.2.8-4.el7ost.ppc64le.rpm

x86_64:
redis-3.2.8-4.el7ost.x86_64.rpm
redis-debuginfo-3.2.8-4.el7ost.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2019-10192
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXW6IKtzjgjWX9erEAQjZhRAAgTkFv/vuEObZUeFFbGj6Aq9wAaf0qlYn
YzXr5cYKMQhJ2jhnIzwPA0OOg4G0lbBskKn/QocB/GxmxG3e7Jpx27uKYWjGnEKE
0U3lAA/pJLLYfO25CO7GmPB2v9LlsWnWeKTTEwDbbaR6gTSUvrIo1Y0KN6EMVF6U
Qhi5b9rJbFyk4TgUt7Acfj0OvdjHBm38GHn/EKY9p/d3B8vnfCghPbrRQFfSJ9MJ
bEXoqpjt6rTaaaPqYgeugvAL1EiVx81HFifGZHb5prPvdeyUGLehoSMUfupCfE8h
lKw8H0f+wwdln6XSJCUI8mmIH4o10ClPxdF7Z5bURHkLxuk04vzYq/3V+y581CM4
GSVDQu58CX2f1bzVxh7/6RbpkRppYOxfDva+mX+CElAHmVDTr7vKQx533LnSzFlo
GV0xREEAb2KomnLSMm7E/+CIp9n1Hv+JWxvFLqb5Gv95X3HEEBwB7v0G4TPdYrUP
Uk0YL67BjML6cWWkA7dB3RifUcVgaWecGWg0TVJxInah3fRMuzjlebK+DxvOmDgU
G9IvjQwFU4PINXdXCoptjrb8Wc5iQT6PLFILeefB3vtbetjgFX5Iyp6Kv1Kbo2MS
pwmMIuFbfNJZjU+ykoPy27cblPVwUnEj2yEvrHV7gXTqId6tJmfsR3Xqk4Nx9GqO
WosAhhVWgyo=WhcC
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2019-2621:01 Important: redis security update

An update for redis is now available for Red Hat OpenStack Platform 14.0 (Rocky)

Summary

Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.
Security Fix(es):
* redis: Heap buffer overflow in HyperLogLog triggered by malicious client (CVE-2019-10192)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2019-10192 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat OpenStack Platform 14.0:
Source: redis-3.2.8-4.el7ost.src.rpm
ppc64le: redis-3.2.8-4.el7ost.ppc64le.rpm redis-debuginfo-3.2.8-4.el7ost.ppc64le.rpm
x86_64: redis-3.2.8-4.el7ost.x86_64.rpm redis-debuginfo-3.2.8-4.el7ost.x86_64.rpm
Red Hat OpenStack Platform 14.0:
Source: redis-3.2.8-4.el7ost.src.rpm
ppc64le: redis-3.2.8-4.el7ost.ppc64le.rpm redis-debuginfo-3.2.8-4.el7ost.ppc64le.rpm
x86_64: redis-3.2.8-4.el7ost.x86_64.rpm redis-debuginfo-3.2.8-4.el7ost.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2019:2621-01
Product: Red Hat Enterprise Linux OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2019:2621
Issued Date: : 2019-09-03
CVE Names: CVE-2019-10192

Topic

An update for redis is now available for Red Hat OpenStack Platform 14.0(Rocky).Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat OpenStack Platform 14.0 - ppc64le, x86_64


Bugs Fixed

1723918 - CVE-2019-10192 redis: Heap buffer overflow in HyperLogLog triggered by malicious client


Related News