Bug 1974761

Summary: Include at OCS 4.6 container images the CVE fix on "polkit" from RHEL8
Product: [Red Hat Storage] Red Hat OpenShift Container Storage Reporter: Rejy M Cyriac <rcyriac>
Component: distributionAssignee: Mudit Agarwal <muagarwa>
Status: CLOSED DUPLICATE QA Contact: Raz Tamir <ratamir>
Severity: high Docs Contact:
Priority: high    
Version: 4.6CC: aeyal, bniver, madam, muagarwa, ocs-bugs, sostapov, ykaul
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-06-22 13:53:33 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Rejy M Cyriac 2021-06-22 13:41:45 UTC
RHEL 8 has shipped "polkit" update with fixes for "Important" CVE


= RHSA-2021:2238 - Security Advisory
  == https://access.redhat.com/errata/RHSA-2021:2238


= CVE-2021-3560
  == https://access.redhat.com/security/cve/CVE-2021-3560


= Updated "polkit" build
  == polkit-0.115-11.el8_4.1


= RHEL8 Errata
  == https://errata.devel.redhat.com/advisory/76777


= Impacted OCS 4.x Container images
  == cephcsi-container
  == rook-ceph-operator-container


The fix to 'Important' CVE on "polkit" is to be included at the impacted OCS container images, through inclusion of the relevant "polkit" update at the updated relevant OCS container images.

Comment 1 Mudit Agarwal 2021-06-22 13:53:33 UTC

*** This bug has been marked as a duplicate of bug 1974766 ***