Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
DescriptionChristophe Besson
2019-12-17 14:31:18 UTC
Description of problem:
`yum updateinfo list cves` doesn't provide information about this specific kernel (the first released with RHEL 7.6):
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
CVE-2015-8830 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2016-4913 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-0861 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-10661 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-17805 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-18208 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-18232 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-18344 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2017-18360 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-1092 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-1094 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-1118 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-1120 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-1130 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-5344 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-5391 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-5803 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-5848 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-7740 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-7757 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-8781 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10322 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10878 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10879 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10881 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10883 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10902 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-10940 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-13405 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-18690 Important/Sec. kernel-3.10.0-957.el7.x86_64
CVE-2018-1000026 Important/Sec. kernel-3.10.0-957.el7.x86_64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The issue seems to be indirectly related to yum, this information is missing from updateinfo.xml after updating the kernel > kernel-3.10.0-957.el7
Version-Release number of selected component (if applicable):
yum-3.4.3-161.el7.noarch
Steps to Reproduce:
1. Install a base RHEL 7.6
2. Run the following command and notice the output.
# yum updateinfo list cves | grep -i CVE-2017-0861
3. Update the kernel to any 7.6 EUS version (> kernel-3.10.0-957.el7) and notice that the CVE isn't echoed anymore.
Actual results:
# yum updateinfo list cves | grep -i CVE-2017-0861
<empty>
Expected results:
# yum updateinfo list cves | grep -i CVE-2017-0861CVE-2017-0861 Important/Sec. kernel-3.10.0-957.el7.x86_64
Additional information:
The CVE-2017-0861 can be seen on a RHEL 7.7 kernel.
This BZ is over 3 years old, and we are on 7.9.z. I recommend we close this as Won't Fix.
Comment 36RHEL Program Management
2023-11-11 07:28:44 UTC
After evaluating this issue, there are no plans to address it further or fix it in an upcoming release. Therefore, it is being closed. If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened.
Comment 37Red Hat Bugzilla
2024-03-11 04:25:02 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days