تنبيه Red Hat
2617تاريخ التحذير
مستوى الخطورة
رقم التحذير
القطاع المستهدف
23 فبراير, 2022
● عالي
2022-4419
الكل
أصدرت Red Hat عدة تحديثات لمعالجة عدد من الثغرات في المنتجات التالية:
- ruby:2.6
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support
- Red Hat Enterprise Linux for x86_64 - Extended Update Support
- Red Hat Enterprise Linux Server - AUS
- Red Hat Enterprise Linux Server - TUS
- Red Hat Enterprise Linux Server - Update Services for SAP Solutions
- Red Hat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions
- Service Telemetry Framework 1.4 (sg-core-container)
- Red Hat OpenStack
- Service Telemetry Framework 1.3 (sg-core-container)
- Red Hat Service Telemetry Framework
- kpatch-patch
- Red Hat Enterprise Linux for Power, little endian
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support
- Red Hat Enterprise Linux for x86_64 - Extended Update Support
- Red Hat Enterprise Linux Server
- Red Hat Enterprise Linux Server - AUS
- Red Hat Enterprise Linux Server - TUS
- Red Hat Enterprise Linux Server - Update Services for SAP Solutions
- Red Hat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions
- Red Hat Advanced Cluster Management 2.3.6
- Red Hat Advanced Cluster Management for Kubernetes
- python-pillow
- Red Hat CodeReady Linux Builder for ARM 64
- Red Hat CodeReady Linux Builder for IBM z Systems
- Red Hat CodeReady Linux Builder for Power, little endian
- Red Hat CodeReady Linux Builder for x86_64
- Red Hat Enterprise Linux Desktop
- Red Hat Enterprise Linux for ARM 64
- Red Hat Enterprise Linux for IBM z Systems
- Red Hat Enterprise Linux for Power, big endian
- Red Hat Enterprise Linux for Power, little endian
- Red Hat Enterprise Linux for Scientific Computing
- Red Hat Enterprise Linux for x86_64
- Red Hat Enterprise Linux Server
- Red Hat Enterprise Linux Workstation
- kernel
- Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
- Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
- Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
- Red Hat Enterprise Linux Desktop
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support
- Red Hat Enterprise Linux for IBM z Systems
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
- Red Hat Enterprise Linux for Power, big endian
- Red Hat Enterprise Linux for Power, little endian
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support
- Red Hat Enterprise Linux for Scientific Computing
- Red Hat Enterprise Linux for x86_64 - Extended Update Support
- Red Hat Enterprise Linux Server
- Red Hat Enterprise Linux Server - AUS
- Red Hat Enterprise Linux Server - TUS
- Red Hat Enterprise Linux Server - Update Services for SAP Solutions
- Red Hat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions
- Red Hat Enterprise Linux Workstation
- Red Hat Virtualization Host
- kernel-rt
- Red Hat Enterprise Linux for Real Time
- Red Hat Enterprise Linux for Real Time - Telecommunications Update Service
- Red Hat Enterprise Linux for Real Time for NFV
- Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service
يمكن للمهاجم استغلال الثغرات وتنفيذ ما يلي:
- رفع الصلاحيات لزيادة قدرته على التعديل في النظام
- الكشف والإفصاح غير المصرح به للمعلومات
يوصي المركز بتحديث النسخ المتأثرة حيث أصدرتRed Hat توضيحًا لهذه التحديثات:
- https://access.redhat.com/errata/RHSA-2022:0581
- https://access.redhat.com/errata/RHSA-2022:0582
- https://access.redhat.com/errata/RHSA-2022:0585
- https://access.redhat.com/errata/RHSA-2022:0587
- https://access.redhat.com/errata/RHSA-2022:0589
- https://access.redhat.com/errata/RHSA-2022:0590
- https://access.redhat.com/errata/RHSA-2022:0592
- https://access.redhat.com/errata/RHSA-2022:0595
- https://access.redhat.com/errata/RHSA-2022:0609
- https://access.redhat.com/errata/RHSA-2022:0620
- https://access.redhat.com/errata/RHSA-2022:0621
- https://access.redhat.com/errata/RHSA-2022:0622
- https://access.redhat.com/errata/RHSA-2022:0628
- https://access.redhat.com/errata/RHSA-2022:0629
- https://access.redhat.com/errata/RHSA-2022:0632
- https://access.redhat.com/errata/RHSA-2022:0633
- https://access.redhat.com/errata/RHSA-2022:0634
- https://access.redhat.com/errata/RHSA-2022:0635
- https://access.redhat.com/errata/RHSA-2022:0636
- https://access.redhat.com/errata/RHSA-2022:0643