Report on Vulnerabilities Fixed in Red Hat Enterprise Linux in 2019

Red Hat Company опубликовала report from risk analysisrelated to the speed of fixing vulnerabilities identified in Red Hat products during 2019. During the year, 1313 vulnerabilities were fixed in Red Hat products and services (3.2% more than in 2018), of which 27 were assigned the status of critical problems. A total of 2019 vulnerabilities were studied by Red Hat Security in 2714, covering all possible problems, including open programs that are not part of RHEL or do not appear in RHEL.

Report on Vulnerabilities Fixed in Red Hat Enterprise Linux in 2019

Updates fixing 98% of the critical issues were released within a week of the vulnerability being made public. 41% of critical issues were resolved within a day.

Report on Vulnerabilities Fixed in Red Hat Enterprise Linux in 2019

The largest number of vulnerabilities were fixed in the Linux kernel and packages with browser components. In particular, 216 problems were fixed in the kernel, 156 in Thunderbird, 152 in Firefox, Chromium - 131, jackson-databind - 123, kernel-rt - 112, MySQL - 95, java-1.8.0-ibm - 69, qemu- kvm - 44, libvirt - 39, ansible - 34, rh-php71-php - 29, exiv2 - 21, rh-php72-php - 20. Of the most significant problems, vulnerabilities were noted in runc, mechanisms for speculative execution of CPU instructions (MDS, SWAPGS, Zombie Load 2.0, Machine Check Error), sack panic, libvirt, vhost net, sudo и Intel i915 driver.

Report on Vulnerabilities Fixed in Red Hat Enterprise Linux in 2019

Source: opennet.ru

Add a comment