Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Red Hat 8 RHSA-2020-4508-01 Moderate: libsolv Security Issue

red hat
Calendar Grey November 4, 2020
Dist Redhat Esm H88
An important libsolv security patch has been released for Red Hat Enterprise Linux 8. This update addresses various issues and improves security functionalities.
An update for libsolv is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm.
The following packages have been upgraded to a later upstream version: libsolv (0.7.11). (BZ#1809106)
Security Fix(es):
* libsolv: out-of-bounds read in repodata_schema2id in repodata.c (CVE-2019-20387)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2019-20387 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/

Package List

Red Hat Enterprise Linux BaseOS (v. 8):
Source: libsolv-0.7.11-1.el8.src.rpm
aarch64: libsolv-0.7.11-1.el8.aarch64.rpm libsolv-debuginfo-0.7.11-1.el8.aarch64.rpm libsolv-debugsource-0.7.11-1.el8.aarch64.rpm libsolv-demo-debuginfo-0.7.11-1.el8.aarch64.rpm libsolv-tools-debuginfo-0.7.11-1.el8.aarch64.rpm perl-solv-debuginfo-0.7.11-1.el8.aarch64.rpm python3-solv-0.7.11-1.el8.aarch64.rpm python3-solv-debuginfo-0.7.11-1.el8.aarch64.rpm ruby-solv-debuginfo-0.7.11-1.el8.aarch64.rpm
ppc64le: libsolv-0.7.11-1.el8.ppc64le.rpm libsolv-debuginfo-0.7.11-1.el8.ppc64le.rpm libsolv-debugsource-0.7.11-1.el8.ppc64le.rpm libsolv-demo-debuginfo-0.7.11-1.el8.ppc64le.rpm libsolv-tools-debuginfo-0.7.11-1.el8.ppc64le.rpm perl-solv-debuginfo-0.7.11-1.el8.ppc64le.rpm python3-solv-0.7.11-1.el8.ppc64le.rpm python3-solv-debuginfo-0.7.11-1.el8.ppc64le.rpm ruby-solv-debuginfo-0.7.11-1.el8.ppc64le.rpm
s390x: libsolv-0.7.11-1.el8.s390x.rpm libsolv-debuginfo-0.7.11-1.el8.s390x.rpm libsolv-debugsource-0.7.11-1.el8.s390x.rpm libsolv-demo-debuginfo-0.7.11-1.el8.s390x.rpm libsolv-tools-debuginfo-0.7.11-1.el8.s390x.rpm perl-solv-debuginfo-0.7.11-1.el8.s390x.rpm python3-solv-0.7.11-1.el8.s390x.rpm python3-solv-debuginfo-0.7.11-1.el8.s390x.rpm ruby-solv-debuginfo-0.7.11-1.el8.s390x.rpm
x86_64:

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:4508-01
Product: Red Hat Enterprise Linux
Issue date: 2020-11-03

Topic

An update for libsolv is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64

Bugs Fixed

1796536 - No Python 3 bindings for libsolv in RHEL8

1797072 - CVE-2019-20387 libsolv: out-of-bounds read in repodata_schema2id in repodata.c

1809106 - Rebase libsolv to >= 0.7.11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here