SUSE-SU-2021:0722-1
Dashboard / Vulnerabilities / SUSE-SU-2021:0722-1
SUSE-SU-2021:0722-1
Summary: Security update for crmsh
Details: This update for crmsh fixes the following issues: - Update to version 4.1.0+git.1614156984.f4f5e146: * Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571) * Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571) * Dev: utils: change default file mod as 644 for str2file function * Dev: lock: give more specific error message when raise ClaimLockError * Dev: hb_report: Detect if any ocfs2 partitions exist * Fix: hb_report: run lsof with specific ocfs2 device(bsc#1180688) * Dev: corosync: change the permission of corosync.conf to 644 * Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869) * Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20210722-1/, https://bugzilla.suse.com/1154927, https://bugzilla.suse.com/1178454, https://bugzilla.suse.com/1178869, https://bugzilla.suse.com/1179999, https://bugzilla.suse.com/1180571, https://bugzilla.suse.com/1180688, https://www.suse.com/security/cve/CVE-2020-35459, https://www.suse.com/security/cve/CVE-2021-3020
Affected packages
Package
Name: crmsh
Purl: pkg:rpm/suse/crmsh&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
