- Issued:
- 2021-11-23
- Updated:
- 2021-11-23
RHBA-2021:4781 - Bug Fix Advisory
Synopsis
scap-security-guide bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for scap-security-guide is now available for Red Hat Enterprise
Linux 7.
Description
The scap-security-guide project provides a guide for configuration of the
system from the final system's security point of view. The guidance is
specified in the Security Content Automation Protocol (SCAP) format and
constitutes a catalog of practical hardening advice, linked to government
requirements where applicable. The project bridges the gap between
generalized policy requirements and specific implementation guidelines.
Bug Fix(es) and Enhancement(s):
- xccdf_org.ssgproject.content_rule_package_MFEhiplsm_installed does not
properly check for SELinux (BZ#1944297)
- Insights does not use latest benchmark for CIS compliance (BZ#1953787)
- Ansible remediations of 3 dconf_gnome related rules don't work properly
(BZ#1976123)
- Update rhel7 DISA STIG profile to v3r5 (BZ#1996678)
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Enterprise Linux Server 7 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
- Red Hat Enterprise Linux Workstation 7 x86_64
- Red Hat Enterprise Linux Desktop 7 x86_64
- Red Hat Enterprise Linux for IBM z Systems 7 s390x
- Red Hat Enterprise Linux for Power, big endian 7 ppc64
- Red Hat Enterprise Linux for Scientific Computing 7 x86_64
- Red Hat Enterprise Linux for Power, little endian 7 ppc64le
- Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
- Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
Fixes
- BZ - 1944297 - xccdf_org.ssgproject.content_rule_package_MFEhiplsm_installed does not properly check for SELinux
- BZ - 1953787 - Insights does not use latest benchmark for CIS compliance
- BZ - 1976123 - Ansible remediations of 3 dconf_gnome related rules don't work properly
- BZ - 1996678 - Update rhel7 DISA STIG profile to v3r5
CVEs
(none)
References
(none)
Red Hat Enterprise Linux Server 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
x86_64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
x86_64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux Workstation 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
x86_64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux Desktop 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
x86_64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux for IBM z Systems 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
s390x | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux for Power, big endian 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
ppc64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux for Scientific Computing 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
x86_64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux for Power, little endian 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
ppc64le | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
s390x | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
ppc64 | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7
SRPM | |
---|---|
scap-security-guide-0.1.57-4.el7_9.src.rpm | SHA-256: 2c497812c9d433184b59c3b1f6c272d2162c8d3dc34d5b06ac2a9669f2b08313 |
ppc64le | |
scap-security-guide-0.1.57-4.el7_9.noarch.rpm | SHA-256: dcf1ff24c652d3078146055118cdc058aa2c00cbd7daf7fbd3d1fcfbe0e24117 |
scap-security-guide-doc-0.1.57-4.el7_9.noarch.rpm | SHA-256: df290b81f5d1cd5e7361a55d149722f7c996abb6f7abe2a83de7a6cb72794a2b |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.