This is such a poorly written article.
There is an enormous difference between a vulnerability in CentOS Stream, and RHEL. The article title is about CentOS, but the body says RHEL is affected too.
There is an enormous difference between a vulnerability in CentOS Stream, and RHEL. The article title is about CentOS, but the body says RHEL is affected too.
Soo…… Red Hat isn’t patching their live, currently supported distributions? That seems bigger news than their approach to CentOS, which they are clearly trying to kill.
I don't quite agree though. Sure, RH can decide when to patch, but a researcher isn't wrong just because they say "Hey, RHEL isn't patched".
Should RHEL be patching sooner? Maybe. Though I get patches can have unintended consequences. However, I like the idea of a third part scrutinizing this stuff. Otherwise companies will do the wrong thing and claim their security posture is perfect.