RHSA-2024:0254MediumCVSS 7.0
Red Hat Security Advisory: rsync security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-37434 — zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra field
🎯 Affected products15
- Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-0:3.1.3-14.el8_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-0:3.1.3-14.el8_6.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-0:3.1.3-14.el8_6.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-0:3.1.3-14.el8_6.5.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-0:3.1.3-14.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-daemon-0:3.1.3-14.el8_6.5.noarch as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debuginfo-0:3.1.3-14.el8_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debuginfo-0:3.1.3-14.el8_6.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debuginfo-0:3.1.3-14.el8_6.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debuginfo-0:3.1.3-14.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debugsource-0:3.1.3-14.el8_6.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debugsource-0:3.1.3-14.el8_6.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debugsource-0:3.1.3-14.el8_6.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
- rsync-debugsource-0:3.1.3-14.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.6)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258