Red Hat Updates
2599Warning Date
Severity Level
Warning Number
Target Sector
8 July, 2020
● High
2020-1458
All
Description:
Red Hat has released security updates to address vulnerabilities in the following products:
- Red Hat OpenShift Service Mesh 1.0 servicemesh-cni
- Red Hat OpenShift Service Mesh 1.0 servicemesh-proxy
- Red Hat OpenShift Service Mesh 1.0 servicemesh-prometheus
- kernel-alt
- Red Hat Enterprise Linux for IBM System z (Structure A)
- nodejs:12
- Red Hat Enterprise Linux Server – TUS
- Red Hat Enterprise Linux for x86_64 - Extended Update Support
- Kernel
- Red Hat Enterprise Linux Server – TUS
- Red Hat Enterprise Linux Server - Update Services for SAP Solutions
- Red Hat Enterprise Linux Server - AUS
- nghttp2
- Red Hat Enterprise Linux Server - Update Services for SAP Solutions
- nodejs:10
- Red Hat Enterprise Linux for x86_64 - Extended Update Support
- Red Hat Enterprise Linux Server - TUS
- qemu-kvm
- Red Hat Enterprise Linux Server – TUS
- tomcat
- Red Hat Enterprise Linux Server – TUS
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Execute arbitrary code –remotely
- Escalation of privilege
Best practice and Recommendations:
The CERT team encourages users to review Red Hat security advisory and apply the necessary updates:
- https://access.redhat.com/errata/RHSA-2020:2831
- https://access.redhat.com/errata/RHSA-2020:2832
- https://access.redhat.com/errata/RHSA-2020:2840
- https://access.redhat.com/errata/RHSA-2020:2844
- https://access.redhat.com/errata/RHSA-2020:2847
- https://access.redhat.com/errata/RHSA-2020:2848
- https://access.redhat.com/errata/RHSA-2020:2849
- https://access.redhat.com/errata/RHSA-2020:2850
- https://access.redhat.com/errata/RHSA-2020:2851
- https://access.redhat.com/errata/RHSA-2020:2852
- https://access.redhat.com/errata/RHSA-2020:2854
- https://access.redhat.com/errata/RHSA-2020:2863
- https://access.redhat.com/errata/RHSA-2020:2864
- https://access.redhat.com/errata/RHSA-2020:2870