[CentOS-announce] CESA-2022:0274 Important CentOS 7 polkit Security Update

2022-01-26 Thread Johnny Hughes
CentOS Errata and Security Advisory 2022:0274 Important Upstream details at : https://access.redhat.com/errata/RHSA-2022:0274 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64:

[CentOS] Polkit patch for CVE-2021-4034 for CentOS 6

2022-01-26 Thread Simon Matter
Hi, For those still running CentOS 6 somewhere, the patch below can be added to the source RPM. Verified to fix the issue on CentOS 6.10 x86_64 with this exploit: https://packetstormsecurity.com/files/165728/Polkit-pkexec-CVE-2021-4034-Proof-Of-Concept.html Regards, Simon PS: Sure, I know

Re: [CentOS] CentOS 7 polkit update

2022-01-26 Thread Ranbir
On Wed, 2022-01-26 at 10:42 -0600, Johnny Hughes wrote: > That has been pushed to the master server and is syncing to the > mirror > network.  It will be announce shortly. Thank you for the update. :) I also noticed (obviously _after_ I emailed the list) my local mirror hadn't done a sync yet

Re: [CentOS] CentOS 7 polkit update

2022-01-26 Thread Johnny Hughes
On 1/26/22 10:35, Ranbir wrote: Hi All, I was looking for an update to polkit in CentOS 7 to fix CVE-2021-4034, but I don't see one yet. I'm assuming it's coming soon-ish. Is there any word on roughly when that will be? Here's the RHEL 7 advisory:

[CentOS] CentOS 7 polkit update

2022-01-26 Thread Ranbir
Hi All, I was looking for an update to polkit in CentOS 7 to fix CVE-2021-4034, but I don't see one yet. I'm assuming it's coming soon-ish. Is there any word on roughly when that will be? Here's the RHEL 7 advisory: https://access.redhat.com/errata/RHSA-2022:0274 -- Ranbir

[CentOS-docs] [centos/centos.org] branch master updated (d87760a -> c3e6a8e)

2022-01-26 Thread git
This is an automated email from the git hooks/post-receive script. rbowen pushed a change to branch master in repository centos/centos.org. from d87760a Fix Automotive SIG record add c3e6a8e Update cloud SIG meeting details No new revisions were added by this update. Summary of

[CentOS] CentOS-announce Digest, Vol 201, Issue 3

2022-01-26 Thread centos-announce-request
Send CentOS-announce mailing list submissions to centos-annou...@centos.org To subscribe or unsubscribe via the World Wide Web, visit https://lists.centos.org/mailman/listinfo/centos-announce or, via email, send a message with subject or body 'help' to