Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

RedHat Satellite: RHSA-2023-1630-01 Important Async Security Fix

red hat
Calendar Grey April 4, 2023
Dist Redhat Esm H88
Critical Update 4.7.1 enhances core performance and addresses vulnerabilities, guaranteeing operational stability and security.
Updated Satellite 6.12 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments.
Security fix(es):
* Candlepin: PreparedStatement.setText(int, InputStream) will create a temporary file if the InputStream is larger than 2k (CVE-2022-41946)
This update fixes the following bugs:
2163538 - Pages Blank 2174984 - Getting 'null value in column \"image_manifest_id\" violates not-null constraint' when syncing openstack container repos 2174987 - (Regression of 2033940) Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions 2174994 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching 2174997 - Package and Errata actions on content hosts selected using the "select all hosts" option fails. 2174998 - Subscription can't be blank, A Pool and its Subscription cannot belong to different organizations 2175002 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io 2175005 - New kickstart_kernel_options snippet breaks UEFI (Grub2) PXE provisioning when boot_mode is static 2175008 - RHEL 9 as Guest OS is not available on Satellite 6.11 2174995 - Health check should use hostname -f 2175007 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans 2176272 - new wait task introduced by rh_cloud 6.0.44 is not recognized by maintain as OK to interrupt 2175010 - Some custom repositories are failing to synchorize with error "This field may not be blank" after upgrading to Red Hat Satellite 6.11 2176922 - [RFE] Need syncable yum-format repository imports 2175003 - Can't perform incremental content exports in syncable format
Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs.

References

https://access.redhat.com/security/cve/CVE-2022-41946 https://access.redhat.com/security/updates/classification#important

Package List

Red Hat Satellite 6.12 for RHEL 8:
Source: candlepin-4.1.20-1.el8sat.src.rpm foreman-3.3.0.21-2.el8sat.src.rpm python-django-3.2.16-1.el8pc.src.rpm python-pulp-container-2.10.12-1.el8pc.src.rpm python-pulpcore-3.18.16-1.el8pc.src.rpm rubygem-fog-vsphere-3.6.0-1.el8sat.src.rpm rubygem-foreman_maintain-1.1.12-1.el8sat.src.rpm rubygem-hammer_cli_katello-1.6.0.2-1.el8sat.src.rpm rubygem-katello-4.5.0.32-1.el8sat.src.rpm rubygem-optimist-3.0.1-1.el8sat.src.rpm rubygem-rbvmomi2-3.6.0-2.el8sat.src.rpm satellite-6.12.3-1.el8sat.src.rpm
noarch: candlepin-4.1.20-1.el8sat.noarch.rpm candlepin-selinux-4.1.20-1.el8sat.noarch.rpm foreman-3.3.0.21-2.el8sat.noarch.rpm foreman-cli-3.3.0.21-2.el8sat.noarch.rpm foreman-debug-3.3.0.21-2.el8sat.noarch.rpm foreman-dynflow-sidekiq-3.3.0.21-2.el8sat.noarch.rpm foreman-ec2-3.3.0.21-2.el8sat.noarch.rpm foreman-gce-3.3.0.21-2.el8sat.noarch.rpm foreman-journald-3.3.0.21-2.el8sat.noarch.rpm foreman-libvirt-3.3.0.21-2.el8sat.noarch.rpm foreman-openstack-3.3.0.21-2.el8sat.noarch.rpm foreman-ovirt-3.3.0.21-2.el8sat.noarch.rpm foreman-postgresql-3.3.0.21-2.el8sat.noarch.rpm foreman-service-3.3.0.21-2.el8sat.noarch.rpm foreman-telemetry-3.3.0.21-2.el8sat.noarch.rpm foreman-vmware-3.3.0.21-2.el8sat.noarch.rpm python39-django-3.2.16-1.el8pc.noarch.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:1630-01
Product: Red Hat Satellite 6
Issue date: 2023-04-04

Topic

Updated Satellite 6.12 packages that fixes important security bugs andseveralregular bugs are now available for Red Hat Satellite.

Relevant Releases Architectures

Red Hat Satellite 6.12 for RHEL 8 - noarch

Bugs Fixed

2153399 - CVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions

2163538 - Pages Blank

2174984 - Getting 'null value in column \"image_manifest_id\" violates not-null constraint' when syncing openstack container repos

2174987 - (Regression of 2033940) Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions

2174994 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching

2174995 - Health check should use hostname -f

2174997 - Package and Errata actions on content hosts selected using the "select all hosts" option fails.

2174998 - Subscription can't be blank, A Pool and its Subscription cannot belong to different organizations

2175002 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io

2175003 - Can't perform incremental content exports in syncable format

2175005 - New kickstart_kernel_options snippet breaks UEFI (Grub2) PXE provisioning when boot_mode is static

2175007 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans

2175008 - RHEL 9 as Guest OS is not available on Satellite 6.11

2175010 - Some custom repositories are failing to synchorize with error "This field may not be blank" after upgrading to Red Hat Satellite 6.11

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here