-
Notifications
You must be signed in to change notification settings - Fork 887
RHEL kernels not reporting vulnerabilities #33990
Copy link
Copy link
Closed
Labels
#g-security-complianceSecurity & Compliance product groupSecurity & Compliance product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.bugSomething isn't working as documentedSomething isn't working as documentedcustomer-rialto~aging bugBug has been open more than 90 daysBug has been open more than 90 days~assisting qaThis issue can be QA'd by anyone outside the QA team when capacity allowsThis issue can be QA'd by anyone outside the QA team when capacity allows~software-ingestionIssue regarding ingesting software inventory from a host into Fleet.Issue regarding ingesting software inventory from a host into Fleet.
Milestone
Metadata
Metadata
Assignees
Labels
#g-security-complianceSecurity & Compliance product groupSecurity & Compliance product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.bugSomething isn't working as documentedSomething isn't working as documentedcustomer-rialto~aging bugBug has been open more than 90 daysBug has been open more than 90 days~assisting qaThis issue can be QA'd by anyone outside the QA team when capacity allowsThis issue can be QA'd by anyone outside the QA team when capacity allows~software-ingestionIssue regarding ingesting software inventory from a host into Fleet.Issue regarding ingesting software inventory from a host into Fleet.
Type
Projects
Status
Done
Fleet version:
Web browser and operating system:
💥 Actual behavior
Vulns that should show up for RHEL (CentOS and Fedora) OS' Linux kernels are not shown in Fleet.
🛠️ To fix
Update goval-dictionary to add arch support for RHEL (in progress)
Publish RHEL goval-dictionary sqlite to vulnerabilities repo (see amazon linux)
Update fleet to use sqlite for kernel scanning (not all package scanning to keep test scope lower)
@noahtalerman: Remove "coming soon" sentence from the vulnerability processing guide:
🧑💻 Steps to reproduce
🕯️ More info (optional)
N/A