Hide Forgot
A flaw was found in cloud-init. SSH host keys are not regenerated when new VM instances are created in combination with hashicorp packer and cloud-init. This could lead to the Man In The Middle (MITM) attack. References: https://bugzilla.redhat.com/show_bug.cgi?id=1574338
Created cloud-init tracking bugs for this issue: Affects: epel-6 [bug 1598833] Affects: fedora-all [bug 1598832]
Reported upstream: https://bugs.launchpad.net/cloud-init/+bug/1781094
Upstream commit now merged to master: https://git.launchpad.net/cloud-init/commit/?id=e218c597
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:3050 https://access.redhat.com/errata/RHSA-2020:3050
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-10896
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2020:3644 https://access.redhat.com/errata/RHSA-2020:3644
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:3898 https://access.redhat.com/errata/RHSA-2020:3898