# Rocky Security Advisories CVE Library

**URL:** <https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450>\
**Category:** Rocky Linux Help & Support\
**Created:** [November 11, 2024, 12:42pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450 "2024-11-11T12:42:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![GaryTheHat](https://avatars.discourse-cdn.com/v4/letter/g/87869e/32.png) [@GaryTheHat](https://forums.rockylinux.org/u/GaryTheHat)\
**Post date:** [November 11, 2024, 12:42pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/1 "2024-11-11T12:42:08Z")

</div>

Hi,

Can you provide any details if Rocky will be releasing a CVE Library where you can easily search a CVE to discover the Product Errata? As well as ensuring that the Product Errata addresses all corrected packages for vulnerability remediation?

At this time I can only find the Product Errata, where you are unable to search by CVE which makes quite a process for easily obtaining security related information for vulnerability remediation.

Also, I have noticed that the remediated package description within Errata generally misses information.

As an example,

CVE-2019-10082  
RLSA-2020:4751

Described Remediation Package Versions

SRPMs

```
mod_md-1:2.0.8-8.module+el8.5.0+695+1fa8055e.src.rpm
mod_md-1:2.0.8-8.module+el8.4.0+553+7a69454b.src.rpm

```

RPMs

```
mod_md-1:2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm
mod_md-1:2.0.8-8.module+el8.4.0+553+7a69454b.aarch64.rpm
mod_md-1:2.0.8-8.module+el8.5.0+695+1fa8055e.x86_64.rpm
mod_md-1:2.0.8-8.module+el8.4.0+553+7a69454b.x86_64.rpm
mod_md-debuginfo-1:2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm
mod_md-debuginfo-1:2.0.8-8.module+el8.4.0+553+7a69454b.aarch64.rpm
mod_md-debuginfo-1:2.0.8-8.module+el8.5.0+695+1fa8055e.x86_64.rpm
mod_md-debuginfo-1:2.0.8-8.module+el8.4.0+553+7a69454b.x86_64.rpm
mod_md-debugsource-1:2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm
mod_md-debugsource-1:2.0.8-8.module+el8.4.0+553+7a69454b.aarch64.rpm
mod_md-debugsource-1:2.0.8-8.module+el8.5.0+695+1fa8055e.x86_64.rpm
mod_md-debugsource-1:2.0.8-8.module+el8.4.0+553+7a69454b.x86_64.rpm

```

If we compare to the RedHat 8 Errata there are far more updated packages described RHSA-2020:4751. I’m sure since Rocky 8 is a 121 with RedHat8, the updated package details should be exactly the same.

With a lot of important information missing from your Errata this makes it a lot harder for accurate vulnerability analysis than other Linux Vendors. Thinking that OVAL definitions will be written with the use of Updated Package details.

Thanks

---

<div class="post-metadata">

**Author:** ![GaryTheHat](https://avatars.discourse-cdn.com/v4/letter/g/87869e/32.png) [@GaryTheHat](https://forums.rockylinux.org/u/GaryTheHat)\
**Post date:** [November 14, 2024, 1:06pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/2 "2024-11-14T13:06:56Z")

</div>

To follow up:

Can you please confirm that the following CVE’s are associated to RLSA-2020:4751?

CVE-2020-9490  
CVE-2019-0217  
CVE-2019-0215  
CVE-2019-0211  
CVE-2019-10097  
CVE-2020-9490  
CVE-2019-0217  
CVE-2019-10082  
CVE-2019-0211  
CVE-2019-0215  
CVE-2019-10082  
CVE-2024-38474  
CVE-2019-10097

I am unable to see these described within the CVE’s within the errata, but seeing that some Vulnerability Scanning solutions are mapping to the errata.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [November 14, 2024, 2:40pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/3 "2024-11-14T14:40:16Z")

</div>

Since Rocky 8 is based on RHEL8, and since it’s been fixed in RHEL8 as shown here: [https://access.redhat.com/errata/RHSA-2020:4751](https://access.redhat.com/errata/RHSA-2020:4751) then it’s fixed in Rocky 8 as well - since the package versions are identical. Therefore any of the RHEL resources for errata can confirm for the entire CVE list that you posted on whether they have been fixed or not - feel free to check/verify that.

As for the errata not being as up-to-date as you would like, see various posts on the forum, for example:

> [@Rocky Linux 8 Errata not updated since 5th of April](https://forums.rockylinux.org/t/rocky-linux-8-errata-not-updated-since-5th-of-april/13891/2):
>
> We are aware of the deficiencies in our errata. A lot of the reasons why it’s not consistently up to date is: Constant upstream changes make it difficult to piece everything together (and recently even red hat announced a change in how their errata is going to work) - This requires constant code changes that is hard to keep up with. We have day jobs (and families), so combine that with maintaining the distribution, working on peridot v2, SIG activities, and other open source activities plus mo…

which explains why since the team are busy with a lot of things, including their day jobs and families. Feel free to volunteer if you would like to help out in that area.

Some additional links relating to errata can be found here: [Rocky Linux Errata - Rocky Linux Wiki](https://wiki.rockylinux.org/rocky/errata/)

---

<div class="post-metadata">

**Author:** ![GaryTheHat](https://avatars.discourse-cdn.com/v4/letter/g/87869e/32.png) [@GaryTheHat](https://forums.rockylinux.org/u/GaryTheHat)\
**Post date:** [November 14, 2024, 3:04pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/4 "2024-11-14T15:04:58Z")

</div>

Thanks for the response! Yeah I have been using the RH Errata for the package details. I am currently trying to work out how to suppress false positives where CPE has been used, usually we would map directly to the vendor advisory.

With regards to volunteering, I could be up that! I have a couple of large project’s I am working on which need to be completed by the end of the year, but this is deffo something I would be interested in for 2025. Any chance you could PM details of how we can discuss this further please?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [November 14, 2024, 4:38pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/5 "2024-11-14T16:38:12Z")

</div>

Hey! Thank you for your interest in trying to improve the tool… We really appreciate it. I do apologize for things not working to yours (and others) expectations when it comes to errata…

The tool that helps with our errata is here: [distro-tools/apollo at main · resf/distro-tools · GitHub](https://github.com/resf/distro-tools/tree/main/apollo)

I like to say just fork it and do a PR of your changes to the repo… I find that to be a good starting point. Though I believe it would be better if someone provided mentoring or better guidance to get you started, especially on the tool itself. I think @neil or @mustafa can provide further guidance and I can see if they’d be willing to reach out to you in regards to the tool.

For more real time direct communication, I always recommend our [mattermost](https://chat.rockylinux.org) and joining our `Development` and `Security` channels in regards to this tool (and others).

---

<div class="post-metadata">

**Author:** ![GaryTheHat](https://avatars.discourse-cdn.com/v4/letter/g/87869e/32.png) [@GaryTheHat](https://forums.rockylinux.org/u/GaryTheHat)\
**Post date:** [November 14, 2024, 4:57pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/6 "2024-11-14T16:57:07Z")

</div>

Not a problem, will cool to help out! My contract in work states ‘No Moonlighting’, so I have messaged my boss to ensure I dont break my contract terms, but I cant see it being a conflict of interest since you are not a competitor of my company.

I will check the tool over, I was thinking maybe a DB would be a good approach. Ingress the RH Errata to a table and a new field for the Rocky Errata ID, can just use a DB query to extract all of the data associated to the update.

---

<div class="post-metadata">

**Author:** ![GaryTheHat](https://avatars.discourse-cdn.com/v4/letter/g/87869e/32.png) [@GaryTheHat](https://forums.rockylinux.org/u/GaryTheHat)\
**Post date:** [November 18, 2024, 11:08am UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/7 "2024-11-18T11:08:25Z")

</div>

I have installed ‘mattermost’, but it is requiring ‘Enter Server URL’, could you provide the information to join please?

I think I have also came up with a work around for the time being whilst I review the Apollo tool.

Thanks

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [November 18, 2024, 11:43am UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/8 "2024-11-18T11:43:05Z")

</div>

It can be found on [rockylinux.org](http://rockylinux.org) website by going to the menu and choosing the option as shown below:

 ![Screenshot from 2024-11-18 12-42-15](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/3/35d0f3fe38f2c84d0d8871eba3d056c929a36c5e.png)

that gives you the url to use.

---

<div class="post-metadata">

**Author:** ![neil](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/neil/32/34_2.png) [@neil](https://forums.rockylinux.org/u/neil)\
**Post date:** [February 12, 2025, 10:57pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/10 "2025-02-12T22:57:25Z")

</div>

hey @GaryTheHat I wanted to circle back on this… I’ve had this tab open in my browser(s) for months, literally…

If you’re interested, I think there’s going to be some more organized effort around gathering errata and integrating it into the rocky setup… wanted to drop a note here in case you wanted to join. I’ll make sure to tag you in any post/communications we have talking about it 🙂

---

<div class="post-metadata">

**Author:** ![neil](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/neil/32/34_2.png) [@neil](https://forums.rockylinux.org/u/neil)\
**Post date:** [April 3, 2025, 3:58pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/12 "2025-04-03T15:58:36Z")

</div>

@GaryTheHat as promised!

There is now some active request for comments and wants regarding the Errata system. Please check it out: [Apollo, Errata, & You: a CIQ OSPO request for comment](https://forums.rockylinux.org/t/apollo-errata-you-a-ciq-ospo-request-for-comment/18102)

Thanks!

---

<div class="post-metadata">

**Author:** ![sthornton](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/sthornton/32/5320_2.png) [@sthornton](https://forums.rockylinux.org/u/sthornton)\
**Post date:** [April 21, 2025, 6:55pm UTC](https://forums.rockylinux.org/t/rocky-security-advisories-cve-library/16450/13 "2025-04-21T18:55:49Z")

</div>

@GaryTheHat I’ve submitted a PR which i believe will address the issues you saw with missing module artifacts in the Rocky errata: [Advisory module handling by rockythorn · Pull Request #39 · resf/distro-tools · GitHub](https://github.com/resf/distro-tools/pull/39)

I’ve also submitted an initial guide for getting started with development on this project: [distro-tools/apollo/README.md at main · resf/distro-tools · GitHub](https://github.com/resf/distro-tools/blob/main/apollo/README.md)
