Low: Satellite 6.10.3 Async Bug Fix Update

Related Vulnerabilities: CVE-2021-4142  

Synopsis

Low: Satellite 6.10.3 Async Bug Fix Update

Type/Severity

Security Advisory: Low

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated Satellite 6.10 packages that fix several bugs are now available for Red Hat Satellite.

Description

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments.

Security Fix(es):
2043714 - CVE-2021-4142 candlepin: Satellite: Allow unintended SCA certificate to authenticate Candlepin [rhn_satellite_6-default]

This update fixes the following bugs:

2043702 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror on Sync' is enabled
2043710 - Syncing tens of repos to capsule can cause deadlock: while updating tuple (...) in relation "core_content"
2048306 - Satellite 6.10 may fail to sync content to capsule still in version 6.9
2049760 - No longer be able to import content into disconnected Satellite for existing content views
2053723 - Large repo sync failed with "Katello::Errors::Pulp3Error: Response payload is not completed"
2053726 - After upgrading to 6.10, Satellite fails to sync some repositories with large files with timeout error
2055660 - organization context fails to change in web UI
2055662 - Incremental CV update fails with 400 HTTP error
2027367 - Satellite doesn't forward the "If-Modified-Since" header for /accessible_content endpoint to Candlepin
2027786 - Satellite schedules one recurring InventorySync::Async::InventoryScheduledSync per org but each task syncs all orgs, resulting in harmless but unnecessary tasks
2043697 - null value in column "manifest_id" violates not-null constraint error while syncing RHOSP container images
2043698 - Remote Execution fails to honor remote_execution_connect_by_ip override on host
2043699 - Content view export failed with undefined method `first' for nil:NilClass
2043700 - webhook event "build_exited" never gets triggered
2043701 - Ansible roles are not starting automatically after provisioning
2043704 - Syncing sha-checksummed KS repository fails with: " Artifact() got an unexpected keyword argument 'sha' "
2043705 - db:seed can fail when there are host mismatches
2043706 - New OS created due to facts mismatch for operatingsystem for RHSM, Puppet and Ansible
2043707 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra package dependency errors
2043712 - pulpcore-workers grow very large when repositories have many changelog entries
2043715 - Limited CV docker tags cannot be pulled after syncing library repo with "limit sync tags"
2043716 - 406 error appears when running insights-client --compliance
2043719 - Incremental publish content view doesn't copy any contents
2043720 - ERROR: at least one Erratum record has migrated_pulp3_href NULL value
2047345 - New version of Candlepin now has org in entitlement certificate and causes authorization issues

Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.10/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts

Affected Products

  • Red Hat Satellite 6.10 x86_64
  • Red Hat Satellite Capsule 6.10 x86_64

Fixes

  • BZ - 2027367 - Satellite doesn't forward the "If-Modified-Since" header for /accessible_content endpoint to Candlepin
  • BZ - 2027786 - Satellite schedules one recurring InventorySync::Async::InventoryScheduledSync per org but each task syncs all orgs, resulting in harmless but unnecessary tasks
  • BZ - 2034346 - CVE-2021-4142 Satellite: Allow unintended SCA certificate to authenticate Candlepin
  • BZ - 2043697 - null value in column "manifest_id" violates not-null constraint error while syncing RHOSP container images
  • BZ - 2043698 - Remote Execution fails to honor remote_execution_connect_by_ip override on host
  • BZ - 2043699 - Content view export failed with undefined method `first' for nil:NilClass
  • BZ - 2043700 - webhook event "build_exited" never gets triggered
  • BZ - 2043701 - Ansible roles are not starting automatically after provisioning
  • BZ - 2043702 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror on Sync' is enabled
  • BZ - 2043704 - Syncing sha-checksummed KS repository fails with: " Artifact() got an unexpected keyword argument 'sha' "
  • BZ - 2043705 - db:seed can fail when there are host mismatches
  • BZ - 2043706 - New OS created due to facts mismatch for operatingsystem for RHSM, Puppet and Ansible
  • BZ - 2043707 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra package dependency errors
  • BZ - 2043710 - syncing tens of repos to capsule can cause deadlock: while updating tuple (...) in relation "core_content"
  • BZ - 2043712 - pulpcore-workers grow very large when repositories have many changelog entries
  • BZ - 2043715 - Limited CV docker tags cannot be pulled after syncing library repo with "limit sync tags"
  • BZ - 2043716 - 406 error appears when running insights-client --compliance
  • BZ - 2043719 - Incremental publish content view doesn't copy any contents
  • BZ - 2043720 - ERROR: at least one Erratum record has migrated_pulp3_href NULL value
  • BZ - 2047345 - New version of Candlepin now has org in entitlement certificate and causes authorization issues
  • BZ - 2048306 - Satellite 6.10 may fail to sync content to capsule still in version 6.9
  • BZ - 2049760 - No longer be able to import content into disconnected Satellite for existing content views
  • BZ - 2053723 - Large repo sync failed with "Katello::Errors::Pulp3Error: Response payload is not completed"
  • BZ - 2053726 - After upgrading to 6.10, Satellite fails to sync some repositories with large files with timeout error
  • BZ - 2055660 - organization context fails to change in web UI
  • BZ - 2055662 - Incremental CV update fails with 400 HTTP error