Exactly, I followed the CVE link through, and all affected RHEL8/9.
Soo…… Red Hat isn’t patching their live, currently supported distributions? That seems bigger news than their approach to CentOS, which they are clearly trying to kill.
Soo…… Red Hat isn’t patching their live, currently supported distributions? That seems bigger news than their approach to CentOS, which they are clearly trying to kill.
I don't quite agree though. Sure, RH can decide when to patch, but a researcher isn't wrong just because they say "Hey, RHEL isn't patched".
Should RHEL be patching sooner? Maybe. Though I get patches can have unintended consequences. However, I like the idea of a third part scrutinizing this stuff. Otherwise companies will do the wrong thing and claim their security posture is perfect.