Lucene search

K
osvGoogleOSV:RLSA-2021:4489
HistoryNov 09, 2021 - 9:32 a.m.

Low: rpm security, bug fix, and enhancement update

2021-11-0909:32:33
Google
osv.dev
8
rpm package manager
security fix
length checks
cve-2021-20266
package management
rocky linux 8.5

AI Score

5.2

Confidence

High

EPSS

0.002

Percentile

54.6%

The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.

Security Fix(es):

  • rpm: missing length checks in hdrblobInit() (CVE-2021-20266)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.