Bug 1984488

Summary: systemd: CVE-2021-33910 patch missing in CentOS Stream 8
Product: Red Hat Enterprise Linux 8 Reporter: Carl George 🤠 <carl>
Component: systemdAssignee: systemd-maint
Status: CLOSED DUPLICATE QA Contact: Frantisek Sumsal <fsumsal>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: CentOS StreamCC: bstinson, jwboyer, ngompa13, systemd-maint-list
Target Milestone: beta   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-07-21 16:24:16 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Carl George 🤠 2021-07-21 14:43:23 UTC
Description of problem:
systemd was recently patched for CVE-2021-33910 in RHEL 8.  That patch does not appear to be part of systemd in CentOS Stream 8.


Version-Release number of selected component (if applicable):
systemd-239-48.el8


Additional info:
CentOS Stream 8 can build the update once it's exported to git.centos.org.  To trigger that, please update systemd in the rhel-8.5.0 branch and attach the resulting build to 8.5 errata.

Comment 1 Josh Boyer 2021-07-21 16:24:16 UTC

*** This bug has been marked as a duplicate of bug 1974700 ***

Comment 2 Neal Gompa 2021-07-21 17:22:13 UTC
(In reply to Josh Boyer from comment #1)
> 
> *** This bug has been marked as a duplicate of bug 1974700 ***

Please don't close tickets in favor of private ones. It makes it look like you're hiding something. I would hope that is not the intent. Either close the private ticket in favor of this one or make bug 1974700 public.

Comment 3 Josh Boyer 2021-07-21 17:59:09 UTC
(In reply to Neal Gompa from comment #2)
> (In reply to Josh Boyer from comment #1)
> > 
> > *** This bug has been marked as a duplicate of bug 1974700 ***
> 
> Please don't close tickets in favor of private ones. It makes it look like
> you're hiding something. I would hope that is not the intent. Either close
> the private ticket in favor of this one or make bug 1974700 public.

No intention to hide anything.  The work is being done against 1974700 per our process.  Creating this bug isn't going to make it go faster or provide more information and just creates busywork for the team that's already trying to get fixes out across all RHEL releases.  I'll leave it to the team owning the issue to determine if 1974700 can be opened.