First published: Tue Nov 15 2022(Updated: )
Ignition is a utility used to manipulate systems during the initramfs. This includes partitioning disks, formatting partitions, writing files (regular files, systemd units, etc.), and configuring users. On first boot, Ignition reads its configuration from a source of truth (remote URL, network metadata service, hypervisor bridge, etc.) and applies the configuration.<br>The following packages have been upgraded to a later upstream version: ignition (2.14.0). (BZ#2090647)<br>Security Fix(es):<br><li> ignition: configs are accessible from unprivileged containers in VMs running on VMware products (CVE-2022-1706)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ignition | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-debuginfo | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-debugsource | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-validate-debuginfo | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-debuginfo | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-debugsource | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-validate-debuginfo | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-debuginfo | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-debugsource | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition-validate-debuginfo | <2.14.0-1.el9 | 2.14.0-1.el9 |
redhat/ignition | <2.14.0-1.el9.aa | 2.14.0-1.el9.aa |
redhat/ignition-debuginfo | <2.14.0-1.el9.aa | 2.14.0-1.el9.aa |
redhat/ignition-debugsource | <2.14.0-1.el9.aa | 2.14.0-1.el9.aa |
redhat/ignition-validate-debuginfo | <2.14.0-1.el9.aa | 2.14.0-1.el9.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:8126 is classified based on the impact of the vulnerability, typically impacting the secure functionality of system configurations.
To fix RHSA-2022:8126, upgrade the Ignition package to version 2.14.0-1.el9 or later as specified in the advisory.
RHSA-2022:8126 affects systems running the Ignition packages with specific versions outlined in the Red Hat advisory.
Ignition manipulates critical system components such as disk partitions, file writes, and user configurations which are affected by RHSA-2022:8126.
There might be potential exploits related to RHSA-2022:8126 that target vulnerabilities in the impacted versions of the Ignition package.