Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1403 - Security Advisory
Issued:
2024-03-19
Updated:
2024-03-19

RHSA-2024:1403 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: fwupd security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for fwupd is now available for Red Hat Enterprise Linux 8.8 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The fwupd packages provide a service that allows session software to update device firmware.

Security Fix(es):

  • fwupd: world readable password in /etc/fwupd/redfish.conf (CVE-2022-3287)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.8 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.8 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 8.8 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.8 aarch64

Fixes

  • BZ - 2129904 - CVE-2022-3287 fwupd: world readable password in /etc/fwupd/redfish.conf

CVEs

  • CVE-2022-3287

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
x86_64
fwupd-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9c0a1adac81b96c5803a4c5d0b98d9f3b85141cd60610fe366933de6d4991130
fwupd-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: f0dff9f4cd07866d230f05ef08808500d42e0e775a81dc2c7f1c8df5093e790a
fwupd-debugsource-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9d9efdf3f357ee69e420f35f8e576a0efd09d2eaf885a6d570bd2aa7a444c150
fwupd-tests-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: d095e1b3aeae98399b6cb08282c7097d3eb41e5611042358f436d1072fa1911b

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
s390x
fwupd-1.7.8-2.el8_8.s390x.rpm SHA-256: b77ff7978b7e40006f6e17883743a22d98b7ca1cb44aad035287cf43526d5159
fwupd-debuginfo-1.7.8-2.el8_8.s390x.rpm SHA-256: 05fbb622bbc5c2c30f9e0e9515e5cda11a43907e1e676de204f9f63e17caf5bb
fwupd-debugsource-1.7.8-2.el8_8.s390x.rpm SHA-256: d383e60d582fd4097520b261d83915edf390dd3d4d261d12c3d5643c279098a0
fwupd-tests-debuginfo-1.7.8-2.el8_8.s390x.rpm SHA-256: 12c8f96fc8957d659f2f3d94a7bd49c8f87c665b8959f93b652d62416c632da2

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
ppc64le
fwupd-1.7.8-2.el8_8.ppc64le.rpm SHA-256: 20320d186734d5efebccf72c8c9480876dadbc0c2961f27f13b18a8581a3293c
fwupd-debuginfo-1.7.8-2.el8_8.ppc64le.rpm SHA-256: 83e35aee588e2d23fe90afb2512c5316342ae141a9d02afbd171b114b062a56f
fwupd-debugsource-1.7.8-2.el8_8.ppc64le.rpm SHA-256: a04c891ded5f68a91bedb2de2056c05ec1039263211764d1af4c8aef322cd42e

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
x86_64
fwupd-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9c0a1adac81b96c5803a4c5d0b98d9f3b85141cd60610fe366933de6d4991130
fwupd-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: f0dff9f4cd07866d230f05ef08808500d42e0e775a81dc2c7f1c8df5093e790a
fwupd-debugsource-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9d9efdf3f357ee69e420f35f8e576a0efd09d2eaf885a6d570bd2aa7a444c150
fwupd-tests-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: d095e1b3aeae98399b6cb08282c7097d3eb41e5611042358f436d1072fa1911b

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
aarch64
fwupd-1.7.8-2.el8_8.aarch64.rpm SHA-256: fcd2b3c33a85fb08791e632cc19d41b7cd5d43f08058543f293f2f47de6bc06b
fwupd-debuginfo-1.7.8-2.el8_8.aarch64.rpm SHA-256: 63b27f6e0a7afb33ff69368ced2fb2c310b6d8e1197cf2c96202c8a5aba760d9
fwupd-debugsource-1.7.8-2.el8_8.aarch64.rpm SHA-256: 3c03be84e760525f2cd2238955821e51e9ac562746072c50b50adb02e4d5c06a
fwupd-tests-debuginfo-1.7.8-2.el8_8.aarch64.rpm SHA-256: 687d40fcfa7e960822e4c48da892aac1dd043e68f4e2192c6f9e37849e483d63

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
ppc64le
fwupd-1.7.8-2.el8_8.ppc64le.rpm SHA-256: 20320d186734d5efebccf72c8c9480876dadbc0c2961f27f13b18a8581a3293c
fwupd-debuginfo-1.7.8-2.el8_8.ppc64le.rpm SHA-256: 83e35aee588e2d23fe90afb2512c5316342ae141a9d02afbd171b114b062a56f
fwupd-debugsource-1.7.8-2.el8_8.ppc64le.rpm SHA-256: a04c891ded5f68a91bedb2de2056c05ec1039263211764d1af4c8aef322cd42e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
fwupd-1.7.8-2.el8_8.src.rpm SHA-256: ddddd48848aba2a100b7078f662f1627c4cbd77719f88532e13235a1032a881b
x86_64
fwupd-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9c0a1adac81b96c5803a4c5d0b98d9f3b85141cd60610fe366933de6d4991130
fwupd-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: f0dff9f4cd07866d230f05ef08808500d42e0e775a81dc2c7f1c8df5093e790a
fwupd-debugsource-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9d9efdf3f357ee69e420f35f8e576a0efd09d2eaf885a6d570bd2aa7a444c150
fwupd-tests-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: d095e1b3aeae98399b6cb08282c7097d3eb41e5611042358f436d1072fa1911b

Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.8

SRPM
x86_64
fwupd-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: f0dff9f4cd07866d230f05ef08808500d42e0e775a81dc2c7f1c8df5093e790a
fwupd-debugsource-1.7.8-2.el8_8.x86_64.rpm SHA-256: 9d9efdf3f357ee69e420f35f8e576a0efd09d2eaf885a6d570bd2aa7a444c150
fwupd-devel-1.7.8-2.el8_8.x86_64.rpm SHA-256: e4be2823ab4c2dc51ea2509e0432ecf55f8fe82fa974b1308299fffd7023882b
fwupd-tests-debuginfo-1.7.8-2.el8_8.x86_64.rpm SHA-256: d095e1b3aeae98399b6cb08282c7097d3eb41e5611042358f436d1072fa1911b

Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.8

SRPM
ppc64le
fwupd-debuginfo-1.7.8-2.el8_8.ppc64le.rpm SHA-256: 83e35aee588e2d23fe90afb2512c5316342ae141a9d02afbd171b114b062a56f
fwupd-debugsource-1.7.8-2.el8_8.ppc64le.rpm SHA-256: a04c891ded5f68a91bedb2de2056c05ec1039263211764d1af4c8aef322cd42e
fwupd-devel-1.7.8-2.el8_8.ppc64le.rpm SHA-256: 6cef49b952e938eb756f13f3c0e61a74ecb0f832a67a0e327c8e8128d47bb3f9

Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 8.8

SRPM
s390x
fwupd-debuginfo-1.7.8-2.el8_8.s390x.rpm SHA-256: 05fbb622bbc5c2c30f9e0e9515e5cda11a43907e1e676de204f9f63e17caf5bb
fwupd-debugsource-1.7.8-2.el8_8.s390x.rpm SHA-256: d383e60d582fd4097520b261d83915edf390dd3d4d261d12c3d5643c279098a0
fwupd-devel-1.7.8-2.el8_8.s390x.rpm SHA-256: b7ffa60b78fabd04955f2fa886f46326e801d4c89bea2dea44924ba43afc35d9
fwupd-tests-debuginfo-1.7.8-2.el8_8.s390x.rpm SHA-256: 12c8f96fc8957d659f2f3d94a7bd49c8f87c665b8959f93b652d62416c632da2

Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.8

SRPM
aarch64
fwupd-debuginfo-1.7.8-2.el8_8.aarch64.rpm SHA-256: 63b27f6e0a7afb33ff69368ced2fb2c310b6d8e1197cf2c96202c8a5aba760d9
fwupd-debugsource-1.7.8-2.el8_8.aarch64.rpm SHA-256: 3c03be84e760525f2cd2238955821e51e9ac562746072c50b50adb02e4d5c06a
fwupd-devel-1.7.8-2.el8_8.aarch64.rpm SHA-256: 1eeaaca9a676be62b9672ab052bbab761fefb93acea504de9bcbdd6866d4ef20
fwupd-tests-debuginfo-1.7.8-2.el8_8.aarch64.rpm SHA-256: 687d40fcfa7e960822e4c48da892aac1dd043e68f4e2192c6f9e37849e483d63

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility