# [Critical] Photon OS Security Update ## Summary Advisory ID : PHSA-2019-1.0-0212 Type : Security Severity : {'Critical', 'Low', 'Important', 'Moderate'} Issued on : 2019-03-05 Affected Versions : Photon OS 1.0 ## Details An update of {'linux', 'mysql', 'libsolv', 'rsyslog', 'linux-esx', 'keepalived', 'perl', 'mesos', 'util-linux', 'python3'} packages of Photon OS has been released. ## Affected Packages: ### Critical perl - ['[CVE-2018-18311](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18311)', '[CVE-2018-18313](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18313)'] ### Important linux - ['[CVE-2018-5391](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-5391)'] mysql - ['[CVE-2019-2534](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2534)', '[CVE-2018-3155](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3155)'] rsyslog - ['[CVE-2018-16881](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-16881)'] linux-esx - ['[CVE-2018-5391](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-5391)'] mesos - ['[CVE-2018-1330](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1330)', '[CVE-2018-11793](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11793)'] python3 - ['[CVE-2018-20406](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20406)'] ### Moderate mysql - ['[CVE-2019-2503](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2503)', '[CVE-2018-3145](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3145)', '[CVE-2018-3203](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3203)', '[CVE-2019-2455](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2455)', '[CVE-2018-3133](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3133)', '[CVE-2019-2482](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2482)', '[CVE-2019-2529](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2529)', '[CVE-2018-3156](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3156)', '[CVE-2019-2533](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2533)', '[CVE-2018-3137](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3137)', '[CVE-2018-3251](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3251)', '[CVE-2018-3182](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3182)', '[CVE-2019-2434](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2434)', '[CVE-2018-3143](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3143)'] libsolv - ['[CVE-2018-20533](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20533)', '[CVE-2018-20534](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20534)', '[CVE-2018-20532](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20532)'] ### Low linux - ['[CVE-2018-18690](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18690)', '[CVE-2019-3701](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-3701)', '[CVE-2018-14641](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-14641)'] mysql - ['[CVE-2019-2507](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2507)', '[CVE-2018-3286](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3286)', '[CVE-2019-2530](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2530)', '[CVE-2018-3195](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3195)', '[CVE-2018-3162](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3162)', '[CVE-2019-2531](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2531)', '[CVE-2019-2528](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2528)', '[CVE-2018-3247](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3247)', '[CVE-2018-3161](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3161)', '[CVE-2019-2436](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2436)', '[CVE-2018-3283](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3283)', '[CVE-2018-3186](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3186)', '[CVE-2018-3284](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3284)', '[CVE-2018-3212](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3212)', '[CVE-2018-3144](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3144)', '[CVE-2019-2494](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2494)', '[CVE-2018-3282](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3282)', '[CVE-2019-2481](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2481)', '[CVE-2018-3277](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3277)', '[CVE-2018-3279](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3279)', '[CVE-2018-3285](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3285)', '[CVE-2019-2486](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2486)', '[CVE-2018-3187](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3187)', '[CVE-2019-2535](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2535)', '[CVE-2019-2420](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2420)', '[CVE-2019-2536](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2536)', '[CVE-2018-3171](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3171)', '[CVE-2018-3173](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3173)', '[CVE-2018-3276](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3276)', '[CVE-2018-3123](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3123)', '[CVE-2019-2495](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2495)', '[CVE-2018-3280](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3280)', '[CVE-2019-2502](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2502)', '[CVE-2018-3170](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3170)', '[CVE-2018-3185](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3185)', '[CVE-2019-2539](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2539)', '[CVE-2019-2537](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2537)', '[CVE-2018-3200](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3200)', '[CVE-2018-3278](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3278)', '[CVE-2019-2510](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2510)', '[CVE-2018-3082](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3082)', '[CVE-2018-3174](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3174)', '[CVE-2019-2532](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2532)'] linux-esx - ['[CVE-2018-18690](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18690)', '[CVE-2019-3701](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-3701)', '[CVE-2018-14641](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-14641)'] util-linux - ['[CVE-2017-2616](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-2616)'] keepalived - ['[CVE-2018-19044](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-19044)'] ## Solution Update the affected packages (tdnf update _package_) Note: For packages ['linux', 'linux-esx'] after updating, a reboot is required for taking effect. ## Updated Packages Information linux-api-headers-4.4.174-1.ph1.noarch.rpm , sha256 : ef79142098ebd637bed8f2c32732f2ca25183ee11488cf907687f90c886e85c4 , size : 1.1M , build_date : Fri, 01 Mar 2019 13:00:05 UTC linux-sound-4.4.174-1.ph1.x86_64.rpm , sha256 : e6b5fa03a2a1f83f61f60ba63177e98b6bbf0bea3b224e950731f5317d148099 , size : 259K , build_date : Fri, 01 Mar 2019 13:25:38 UTC util-linux-debuginfo-2.27.1-4.ph1.x86_64.rpm , sha256 : 8f00bef82d546a6f1d87e107ce0068ed8196d45cb2663153def2c6a96fb36416 , size : 4.8M , build_date : Fri, 01 Mar 2019 13:01:34 UTC linux-esx-debuginfo-4.4.174-1.ph1.x86_64.rpm , sha256 : 64886a2b5f4ac6caa36f9c0bfd9d535e3085019829c262ced837c2d74e37b547 , size : 191M , build_date : Fri, 01 Mar 2019 13:22:31 UTC linux-dev-4.4.174-1.ph1.x86_64.rpm , sha256 : 087e99f6a64cb8a594b82ce2cbdde2534c3447abc1ea755317768b08ae439c3c , size : 10M , build_date : Fri, 01 Mar 2019 13:25:38 UTC linux-esx-devel-4.4.174-1.ph1.x86_64.rpm , sha256 : 024b0c02fe6cb5f679165fe4b1bee4132dd7e50873b300ee9194220c502fd255 , size : 9.8M , build_date : Fri, 01 Mar 2019 13:22:31 UTC util-linux-lang-2.27.1-4.ph1.x86_64.rpm , sha256 : 4f61ac31c66232f7d1517fbf80f6946f0442ae0184fbb0ad0eb0185972760ddc , size : 1.8M , build_date : Fri, 01 Mar 2019 13:01:34 UTC util-linux-devel-2.27.1-4.ph1.x86_64.rpm , sha256 : ec74597f3269f469c79157f38dd97b0c6c660634d58ac3fe39b9a10080909710 , size : 26K , build_date : Fri, 01 Mar 2019 13:01:34 UTC linux-tools-4.4.174-1.ph1.x86_64.rpm , sha256 : 78f085a148638d3e16cc1599af2ff40d5a361958d6af4893aa69345bc2eb5841 , size : 826K , build_date : Fri, 01 Mar 2019 13:25:38 UTC linux-debuginfo-4.4.174-1.ph1.x86_64.rpm , sha256 : f121de67f69fbc24a4ce4252114b5ecaa4cca68fc8167445a163fad81a64eaec , size : 426M , build_date : Fri, 01 Mar 2019 13:25:38 UTC linux-esx-docs-4.4.174-1.ph1.x86_64.rpm , sha256 : 120b20f517265cf691080089eb30fb655afe925cf5bb431b15210f264eb3eed6 , size : 6.6M , build_date : Fri, 01 Mar 2019 13:22:31 UTC linux-drivers-gpu-4.4.174-1.ph1.x86_64.rpm , sha256 : 439e4d637991f4ab61b1322131257f874cd516a8a3388bc61955784da0d9a15b , size : 1.5M , build_date : Fri, 01 Mar 2019 13:25:38 UTC linux-docs-4.4.174-1.ph1.x86_64.rpm , sha256 : 1dfe42bfe4c49202fec9d99523c919f79d404f1cc7c6a01b271edd5f1ec7efb0 , size : 6.6M , build_date : Fri, 01 Mar 2019 13:25:38 UTC linux-4.4.174-1.ph1.x86_64.rpm , sha256 : 2c79716b863f7513e8d503028e6b21dd33d701065ca687a0ce15d0c15dcc3b1f , size : 19M , build_date : Fri, 01 Mar 2019 13:25:38 UTC util-linux-2.27.1-4.ph1.x86_64.rpm , sha256 : 19ef49ee6c8f503f8ba444c3cfc458fcd5af623762cd00d6a4466368204e08b8 , size : 2.2M , build_date : Fri, 01 Mar 2019 13:01:34 UTC linux-oprofile-4.4.174-1.ph1.x86_64.rpm , sha256 : 35af4d4a882074425cc5c9c794431fe3456de02f32164630cc99b92f90f96c7a , size : 45K , build_date : Fri, 01 Mar 2019 13:25:38 UTC linux-esx-4.4.174-1.ph1.x86_64.rpm , sha256 : c74a3d530ce520fb0d4d3e2fa6c2cc959068cd58e9ae5e34abcfde1c5dc51346 , size : 7.6M , build_date : Fri, 01 Mar 2019 13:22:31 UTC mysql-5.7.25-1.ph1.x86_64.rpm , sha256 : b8f0865d103ba85a652a4eca5bcfb73026e4131e0708da1efa53de0117572e3b , size : 51M , build_date : Fri, 01 Mar 2019 13:21:41 UTC mysql-debuginfo-5.7.25-1.ph1.x86_64.rpm , sha256 : 23c4a6c4769020b99e27ef56e9687aedffe383020c6af7b54cc72cd7e90caa48 , size : 3.0M , build_date : Fri, 01 Mar 2019 13:21:41 UTC mysql-devel-5.7.25-1.ph1.x86_64.rpm , sha256 : cf2a61517fc3b13a1ed98ee22fa193b0097d62f5510c93345a9a73bbd58e6158 , size : 1.9M , build_date : Fri, 01 Mar 2019 13:21:41 UTC libsolv-0.6.19-6.ph1.x86_64.rpm , sha256 : c82e153bbd813ffc25c811d87a24d3006e15a96ef965a699e0f958a8db90fce4 , size : 425K , build_date : Fri, 01 Mar 2019 13:08:47 UTC libsolv-debuginfo-0.6.19-6.ph1.x86_64.rpm , sha256 : ddb4e337f7e8d5b842b062b68ad53ca38335b7e6b4dc7748655a0b5c7ef20f07 , size : 44K , build_date : Fri, 01 Mar 2019 13:08:47 UTC rsyslog-8.15.0-9.ph1.x86_64.rpm , sha256 : 941711f0b446e6f17c2a46c11d0a3cf919e7d521a9aabc4638d8e8f4bb8b43e9 , size : 694K , build_date : Fri, 01 Mar 2019 13:12:48 UTC rsyslog-debuginfo-8.15.0-9.ph1.x86_64.rpm , sha256 : 9a7d7239b63efdaf2aca944710418cb5ccb349fa28f0c107b8dc9139f3f6c669 , size : 2.8M , build_date : Fri, 01 Mar 2019 13:12:48 UTC linux-esx-debuginfo-4.4.174-1.ph1.x86_64.rpm , sha256 : 64886a2b5f4ac6caa36f9c0bfd9d535e3085019829c262ced837c2d74e37b547 , size : 191M , build_date : Fri, 01 Mar 2019 13:22:31 UTC linux-esx-devel-4.4.174-1.ph1.x86_64.rpm , sha256 : 024b0c02fe6cb5f679165fe4b1bee4132dd7e50873b300ee9194220c502fd255 , size : 9.8M , build_date : Fri, 01 Mar 2019 13:22:31 UTC linux-esx-docs-4.4.174-1.ph1.x86_64.rpm , sha256 : 120b20f517265cf691080089eb30fb655afe925cf5bb431b15210f264eb3eed6 , size : 6.6M , build_date : Fri, 01 Mar 2019 13:22:31 UTC linux-esx-4.4.174-1.ph1.x86_64.rpm , sha256 : c74a3d530ce520fb0d4d3e2fa6c2cc959068cd58e9ae5e34abcfde1c5dc51346 , size : 7.6M , build_date : Fri, 01 Mar 2019 13:22:31 UTC keepalived-debuginfo-1.3.5-2.ph1.x86_64.rpm , sha256 : 09b797733ce435394f278395a32f104be81d60edac8c0343d108edfd11f3a2c1 , size : 970K , build_date : Fri, 01 Mar 2019 13:09:38 UTC keepalived-1.3.5-2.ph1.x86_64.rpm , sha256 : 7f822bf48964d9d2c71b8c7058c104ff775a08b7cc049af9eff84ca067ef2142 , size : 276K , build_date : Fri, 01 Mar 2019 13:09:38 UTC perl-5.24.1-3.ph1.x86_64.rpm , sha256 : b838a0770420842d7c59d6870ef72cde56eff656c260f8578f6842b08baeb25a , size : 18M , build_date : Fri, 01 Mar 2019 13:03:03 UTC perl-debuginfo-5.24.1-3.ph1.x86_64.rpm , sha256 : 890ccf71c3f3883a8f6c7fdfb46e69330d87b25f34b9001f6b4c23e1b8a55eae , size : 254K , build_date : Fri, 01 Mar 2019 13:03:03 UTC mesos-python-1.5.2-1.ph1.x86_64.rpm , sha256 : 79a46298fdf81f4bf0a87ffdb493ba7bd3e5d74bad9873db82031504142668a3 , size : 16M , build_date : Fri, 01 Mar 2019 15:01:25 UTC mesos-debuginfo-1.5.2-1.ph1.x86_64.rpm , sha256 : 2ce1c104f43883a132938fb3d9efc26ad2a1491a4b8edec07a62fd78fbab2bca , size : 470M , build_date : Fri, 01 Mar 2019 15:01:25 UTC mesos-devel-1.5.2-1.ph1.x86_64.rpm , sha256 : 9a1fc29cf013a78a0737669f9d23f90cafd359f9141431a0b6135f8a99d9fb6e , size : 1.3M , build_date : Fri, 01 Mar 2019 15:01:25 UTC mesos-1.5.2-1.ph1.x86_64.rpm , sha256 : 7bddef5d0bbffb43e1e55c55a62ffa1d2e6a937e0ddf73d1325a9d14a4922473 , size : 16M , build_date : Fri, 01 Mar 2019 15:01:25 UTC util-linux-debuginfo-2.27.1-4.ph1.x86_64.rpm , sha256 : 8f00bef82d546a6f1d87e107ce0068ed8196d45cb2663153def2c6a96fb36416 , size : 4.8M , build_date : Fri, 01 Mar 2019 13:01:34 UTC util-linux-lang-2.27.1-4.ph1.x86_64.rpm , sha256 : 4f61ac31c66232f7d1517fbf80f6946f0442ae0184fbb0ad0eb0185972760ddc , size : 1.8M , build_date : Fri, 01 Mar 2019 13:01:34 UTC util-linux-devel-2.27.1-4.ph1.x86_64.rpm , sha256 : ec74597f3269f469c79157f38dd97b0c6c660634d58ac3fe39b9a10080909710 , size : 26K , build_date : Fri, 01 Mar 2019 13:01:34 UTC util-linux-2.27.1-4.ph1.x86_64.rpm , sha256 : 19ef49ee6c8f503f8ba444c3cfc458fcd5af623762cd00d6a4466368204e08b8 , size : 2.2M , build_date : Fri, 01 Mar 2019 13:01:34 UTC python3-3.5.6-3.ph1.x86_64.rpm , sha256 : 40022a0cbac2d4e21cc994411ccda03751a1b041b30c1153bf9649ba3bb71630 , size : 1.1M , build_date : Fri, 01 Mar 2019 13:05:25 UTC python3-tools-3.5.6-3.ph1.x86_64.rpm , sha256 : 655771e5b5ef95fc16510e2c283582d8d58d5397c3ffb15da4a77a0f0f1fc6ea , size : 166K , build_date : Fri, 01 Mar 2019 13:05:25 UTC python3-libs-3.5.6-3.ph1.x86_64.rpm , sha256 : fb3bcbc1f478b8aefb78c49035f15cdcd7db27bf107510da8b582bf35010cc01 , size : 9.8M , build_date : Fri, 01 Mar 2019 13:05:25 UTC python3-debuginfo-3.5.6-3.ph1.x86_64.rpm , sha256 : 36a93979f2aff2c2a66651edb28e2dc6e44c5c902bc1e7abc8e33ded75d455c7 , size : 7.2M , build_date : Fri, 01 Mar 2019 13:05:25 UTC python3-devel-3.5.6-3.ph1.x86_64.rpm , sha256 : c4db3a057a06a2409618a8fa69dc05a1a0a1f57aaf569cb99629194269ac250d , size : 156K , build_date : Fri, 01 Mar 2019 13:05:25 UTC