Important: Satellite 6.12.3 Async Security Update

Related Vulnerabilities: CVE-2022-41946  

Synopsis

Important: Satellite 6.12.3 Async Security Update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated Satellite 6.12 packages that fixes important security bugs and several
regular bugs are now available for Red Hat Satellite.

Description

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments.

Security fix(es):

  • Candlepin: PreparedStatement.setText(int, InputStream) will create a temporary file if the InputStream is larger than 2k (CVE-2022-41946)

This update fixes the following bugs:

2163538 - Pages Blank
2174984 - Getting 'null value in column \"image_manifest_id\" violates not-null constraint' when syncing openstack container repos
2174987 - (Regression of 2033940) Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions
2174994 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching <IP>
2174997 - Package and Errata actions on content hosts selected using the "select all hosts" option fails.
2174998 - Subscription can't be blank, A Pool and its Subscription cannot belong to different organizations
2175002 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io
2175005 - New kickstart_kernel_options snippet breaks UEFI (Grub2) PXE provisioning when boot_mode is static
2175008 - RHEL 9 as Guest OS is not available on Satellite 6.11
2174995 - Health check should use hostname -f
2175007 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans
2176272 - new wait task introduced by rh_cloud 6.0.44 is not recognized by maintain as OK to interrupt
2175010 - Some custom repositories are failing to synchorize with error "This field may not be blank" after upgrading to Red Hat Satellite 6.11
2176922 - [RFE] Need syncable yum-format repository imports
2175003 - Can't perform incremental content exports in syncable format

Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Satellite 6.12 x86_64
  • Red Hat Satellite Capsule 6.12 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64

Fixes

  • BZ - 2153399 - CVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions
  • BZ - 2163538 - Pages Blank
  • BZ - 2174984 - Getting 'null value in column \"image_manifest_id\" violates not-null constraint' when syncing openstack container repos
  • BZ - 2174987 - (Regression of 2033940) Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions
  • BZ - 2174994 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching <IP>
  • BZ - 2174995 - Health check should use hostname -f
  • BZ - 2174997 - Package and Errata actions on content hosts selected using the "select all hosts" option fails.
  • BZ - 2174998 - Subscription can't be blank, A Pool and its Subscription cannot belong to different organizations
  • BZ - 2175002 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io
  • BZ - 2175003 - Can't perform incremental content exports in syncable format
  • BZ - 2175005 - New kickstart_kernel_options snippet breaks UEFI (Grub2) PXE provisioning when boot_mode is static
  • BZ - 2175007 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans
  • BZ - 2175008 - RHEL 9 as Guest OS is not available on Satellite 6.11
  • BZ - 2175010 - Some custom repositories are failing to synchorize with error "This field may not be blank" after upgrading to Red Hat Satellite 6.11
  • BZ - 2176272 - new wait task introduced by rh_cloud 6.0.44 is not recognized by maintain as OK to interrupt
  • BZ - 2176922 - [RFE] Need syncable yum-format repository imports