[Apollo] Advisories Statistics light light Login

RLSA-2024:0647

Security Mirrored from RHSA-2024:0647
Issued at: 2024-02-12
Updated at: 2024-02-12

Synopsis

Moderate: rpm security update



Description

The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.

Security Fix(es):

* rpm: TOCTOU race in checks for unsafe symlinks (CVE-2021-35937)

* rpm: races with chown/chmod/capabilities calls during installation (CVE-2021-35938)

* rpm: checks for unsafe symlinks are not performed for intermediary directories (CVE-2021-35939)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64

Fixes

1964114 1964125 1964129

CVEs

CVE-2021-35937 CVE-2021-35938 CVE-2021-35939

Affected packages

Rocky Linux 8 aarch64 - BaseOS

python3-rpm-0:4.14.3-28.el8_9.aarch64.rpm python3-rpm-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-0:4.14.3-28.el8_9.aarch64.rpm rpm-0:4.14.3-28.el8_9.src.rpm rpm-apidocs-0:4.14.3-28.el8_9.noarch.rpm rpm-build-libs-0:4.14.3-28.el8_9.aarch64.rpm rpm-build-libs-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-cron-0:4.14.3-28.el8_9.noarch.rpm rpm-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-debugsource-0:4.14.3-28.el8_9.aarch64.rpm rpm-devel-0:4.14.3-28.el8_9.aarch64.rpm rpm-devel-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-libs-0:4.14.3-28.el8_9.aarch64.rpm rpm-libs-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-ima-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-ima-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-prioreset-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-prioreset-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-selinux-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-selinux-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-syslog-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-syslog-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-systemd-inhibit-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-systemd-inhibit-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-sign-0:4.14.3-28.el8_9.aarch64.rpm rpm-sign-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm

Rocky Linux 8 aarch64 - AppStream

rpm-build-0:4.14.3-28.el8_9.aarch64.rpm rpm-build-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-fapolicyd-0:4.14.3-28.el8_9.aarch64.rpm rpm-plugin-fapolicyd-debuginfo-0:4.14.3-28.el8_9.aarch64.rpm