BookmarkSubscribeRSS Feed
Viraaj
Calcite | Level 5

Our all SAS servers deployed on RHEL 7.7 platform and now our IT is patching the below OS updates on the SAS Servers and anyone can help me with these updates will affect our SAS 9.4 M6 Servers (SAS App, Meta, and middle-tier).

  •  
  • RHEL 7 Baseline update – 7.x -> 7.7. Servers will receive the latest patches.
    • Includes:
      • RHEL 7.7 (kernel-3.10.0-1062.18.1)
        • kernel: Count overflow in FUSE request leading to use-after-free issues. (CVE-2019-11487).
        • kernel: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666).
        • Kernel: KVM: export MSR_IA32_TSX_CTRL to guest – incomplete fix for TAA (CVE-2019-11135) (CVE-2019-19338).
      • New kernel notes: https://access.redhat.com/errata/RHSA-2020:0834
      • JAVA Security Update (OpenJDK)
        • OpenJDK: Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601).
        • OpenJDK: Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604).
        • OpenJDK: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590).
        • OpenJDK: Incorrect isBuiltinStreamHandler causing URL normalization issues (Networking, 8228548) (CVE-2020-2593).
        • OpenJDK: Excessive memory usage in OID processing in X.509 certificate parsing (Libraries, 8234037) (CVE-2020-2654).
        • OpenJDK: Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909) (CVE-2020-2583).
        • OpenJDK: Incomplete enforcement of maxDatagramSockets limit in DatagramChannelImpl (Networking, 8231795) (CVE-2020-2659).

Java notes: https://access.redhat.com/errata/RHSA-2020:0196

1 REPLY 1
alexal
SAS Employee

@Viraaj ,

 

No, they shouldn't affect your SAS installation. 

suga badge.PNGThe SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment. 

Join SUGA 

Get Started with SAS Information Catalog in SAS Viya

SAS technical trainer Erin Winters shows you how to explore assets, create new data discovery agents, schedule data discovery agents, and much more.

Find more tutorials on the SAS Users YouTube channel.

Discussion stats
  • 1 reply
  • 408 views
  • 0 likes
  • 2 in conversation