Moderate: security update - Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874)

Synopsis

Moderate: security update - Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874)

Type/Severity

Security Advisory: Moderate

Topic

Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874)

Description

  • Updated python-psutil version to 5.6.6 inside ansible-runner container
    (CVE-2019-18874)

Solution

For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/index.html

Affected Products

  • Red Hat Ansible Automation Platform 1.0 x86_64

Fixes

  • BZ - 1772014 - CVE-2019-18874 python-psutil: double free because of refcount mishandling

CVEs

References