I have an issue with some servers at work where I have been unable to determine the best course of action to address it based on pre-existing knowledge within my team or web searches. Does anyone have suggestions for the best place to ask RHEL-specific questions? I don’t want to presume that it’s OK to post such nitty-gritty technical questions here.

You are viewing a single thread.
View all comments View context
3 points

old versions of modules that come from the Ceph package got flagged by our security scan.

RHEL uses a practice called backporting, where older versions of software in packages get fixes from newer versions of the software without changing the version. This means that scanners that only check the version number can give you false positives for CVEs that are actually fixed. Is there a specific CVE that your scanner mentions? If so, you can look it up in the Red Hat CVE database and check if the fix has been backported, and which release of the package includes said fix.

permalink
report
parent
reply
1 point

Oh, I was not aware of this. This is very useful! I will check it out and post an update later. Thank you!

permalink
report
parent
reply
1 point

I checked, and the versions of those modules that are currently installed are way behind what’s provided in the listed Red Hat patch, so it does seem that the updates for this just haven’t been installed. I will try to double-check with Red Hat support to be sure that enabling the Ceph repository is the correct course of action to take. Thank you once again for your help.

permalink
report
parent
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 7.9K

    Monthly active users

  • 6.3K

    Posts

  • 175K

    Comments