Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

RedHat: RHSA-2020-4254-01 Moderate: Ansible Tower 3.7 Security Update

red hat
Calendar Grey October 14, 2020
Dist Redhat Esm H88
Important security patch for Red Hat Ansible Tower 3.7 runner version tackling CVE-2019-18874 via python-psutil enhancement.
Red Hat Ansible Tower 3.7 runner release (CVE-2019-18874) 2

Solution

For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html

Summary

* Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)

References

https://access.redhat.com/security/cve/CVE-2017-12652 https://access.redhat.com/security/cve/CVE-2018-20843 https://access.redhat.com/security/cve/CVE-2019-5094 https://access.redhat.com/security/cve/CVE-2019-5188 https://access.redhat.com/security/cve/CVE-2019-5482 https://access.redhat.com/security/cve/CVE-2019-11719 https://access.redhat.com/security/cve/CVE-2019-11727 https://access.redhat.com/security/cve/CVE-2019-11756 https://access.redhat.com/security/cve/CVE-2019-12450 https://access.redhat.com/security/cve/CVE-2019-12749 https://access.redhat.com/security/cve/CVE-2019-14822 https://access.redhat.com/security/cve/CVE-2019-14866 https://access.redhat.com/security/cve/CVE-2019-14973 https://access.redhat.com/security/cve/CVE-2019-15903 https://access.redhat.com/security/cve/CVE-2019-16935 https://access.redhat.com/security/cve/CVE-2019-17006 https://access.redhat.com/security/cve/CVE-2019-17023 https://access.redhat.com/security/cve/CVE-2019-17498 https://access.redhat.com/security/cve/CVE-2019-17546 https://access.redhat.com/security/cve/CVE-2019-18874 https://access.redhat.com/security/cve/CVE-2019-19126 https://access.redhat.com/security/cve/CVE-2019-19956 https://access.redhat.com/security/cve/CVE-2019-20386 Read the Full Advisory

Package List


Advisory ID: RHSA-2020:4254-01
Product: Red Hat Ansible Tower
Issue date: 2020-10-14

Topic

Red Hat Ansible Tower 3.7 runner release (CVE-2019-18874)

Relevant Releases Architectures

Bugs Fixed

1772014 - CVE-2019-18874 python-psutil: double free because of refcount mishandling

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here