RHSA-2024:3401: Moderate: rpm-ostree security update
Moderate: rpm-ostree security update
Other sources
The rpm-ostree tool binds together the RPM packaging model with the OSTree model of bootable file system trees. It provides commands that can be used both on client systems and on server-side composes. The rpm-ostree-client package provides commands for client systems to perform upgrades and rollbacks.Security Fix(es): rpm-ostree: world-readable /etc/shadow file (CVE-2024-2905) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3401?
The severity of RHSA-2024:3401 is categorized as moderate.
How do I fix RHSA-2024:3401?
To fix RHSA-2024:3401, you should update the rpm-ostree package to version 2023.3-2.el9_2.
Which systems are affected by RHSA-2024:3401?
RHSA-2024:3401 affects various versions of Red Hat Enterprise Linux for Power, x86_64, and ARM architectures.
What component is affected by RHSA-2024:3401?
The component affected by RHSA-2024:3401 is the rpm-ostree tool.
Is there a specific update package for RHSA-2024:3401?
Yes, the update package for RHSA-2024:3401 is rpm-ostree version 2023.3-2.el9_2.