Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat Ansible Tower 3.6 Advisory RHSA-2020:4255-01 CVE-2019-18874

red hat
Calendar Grey October 14, 2020
Dist Redhat Esm H88
Keep up to date with the recent security patch for Red Hat Ansible Tower 3.6 that deals with CVE-2019-18874 and additional vulnerabilities.
Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874) 2

Solution

For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html

Summary

* Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)

References

https://access.redhat.com/security/cve/CVE-2017-12652 https://access.redhat.com/security/cve/CVE-2018-20843 https://access.redhat.com/security/cve/CVE-2019-5094 https://access.redhat.com/security/cve/CVE-2019-5188 https://access.redhat.com/security/cve/CVE-2019-5482 https://access.redhat.com/security/cve/CVE-2019-11719 https://access.redhat.com/security/cve/CVE-2019-11727 https://access.redhat.com/security/cve/CVE-2019-11756 https://access.redhat.com/security/cve/CVE-2019-12450 https://access.redhat.com/security/cve/CVE-2019-12749 https://access.redhat.com/security/cve/CVE-2019-14822 https://access.redhat.com/security/cve/CVE-2019-14866 https://access.redhat.com/security/cve/CVE-2019-14973 https://access.redhat.com/security/cve/CVE-2019-15903 https://access.redhat.com/security/cve/CVE-2019-16935 https://access.redhat.com/security/cve/CVE-2019-17006 https://access.redhat.com/security/cve/CVE-2019-17023 https://access.redhat.com/security/cve/CVE-2019-17498 https://access.redhat.com/security/cve/CVE-2019-17546 https://access.redhat.com/security/cve/CVE-2019-18874 https://access.redhat.com/security/cve/CVE-2019-19126 https://access.redhat.com/security/cve/CVE-2019-19956 https://access.redhat.com/security/cve/CVE-2019-20386 Read the Full Advisory

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:4255-01
Product: Red Hat Ansible Tower
Issue date: 2020-10-14

Topic

Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874)

Relevant Releases Architectures

Bugs Fixed

1772014 - CVE-2019-18874 python-psutil: double free because of refcount mishandling

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here