Security vulnerabilities related to NTP addressed in rhel6, why rhel7 still in affected?

Latest response

Hi
Regarding CVE-2015-7852, cve-2015-7691, cve-2015-7692, CVE-2015-7701, cve-2015-7702, cve-2015-7703
these issues have been addressed in Red Hat Enterprise Linux 6, why not merge these patches in Red Hat Enterprise Linux 7?

eg:
https://access.redhat.com/security/cve/cve-2015-7852

Thanks.

Responses

Hi Baochuan,

The issue isn't so severe to justify an async erratum for RHEL 7. The fix will be released later. Please hold on.

Regards, Radek

Radek,

This answer doesn't add up. Why did it justify an immediate fix in RHEL 6, but not RHEL 7? can you please give some more context around the decision. It's 3 months since the RHEL 6 update was released.

Are Red Hat rebasing NTP in RHEL 7.3?

The listed vulnerabilities were fixed in the RHEL 6.8 update, it wasn't an asynchronous errata. They just happened to fit better in the release schedule. They were too late for RHEL 7.2, so they will be in RHEL 7.3.

Thanks. Hope it will be released ASAP.

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.