Re: [Linux-PowerEdge] CVE-2020-5344

2020-04-09 Thread Yannick PALANQUE

[EXTERNAL EMAIL] 

Hello,

Le 09/04/2020 22:12, miguel.cha...@dell.com a écrit :
> Is there a solution?


I think maybe running the DUP from a chrooted installation of CentOS 7 
could work? (you should copy a big tar.gz or something like that)

But it must be like a using a truck to move a cup of tea one meter away...
___
Linux-PowerEdge mailing list
Linux-PowerEdge@dell.com
https://lists.us.dell.com/mailman/listinfo/linux-poweredge


Re: [Linux-PowerEdge] CVE-2020-5344

2020-04-09 Thread Miguel_Chavez
Dell Customer Communication - Confidential

Good afternoon, 

A quick note on this  is that feedback was forwarded to our engineering team.  
It looks like at least for this DRAC generation, tentatively they are looking 
to add back support for RHEL 6 on  FW 4.20.20

For now, the currrent work arounds are what you mentioned  in your email. 

There was also feedback provided for the display filter for the update package. 

If additional information is needed, please reach out to our Dell Support 
department. 

Thanks! 

Regards,
Miguel Chavez

-Original Message-
From: linux-poweredge-bounces-Lists  
On Behalf Of isdtor
Sent: Thursday, April 9, 2020 11:49 AM
To: linux-poweredge-Lists
Subject: [Linux-PowerEdge] CVE-2020-5344


[EXTERNAL EMAIL] 


Hi list,

Can someone from Dell please explain how we can deploy security updates to 
machines where the OS is no longer supported, such as RHEL/CentOS 6? The 
upgrade below was downloaded from Dell's support web site, "Operating system" 
selected is "Red Hat(R) Enterprise Linux 6". And quite obviously, this doesn't 
work on RHEL 6 because glibc is version 2.12.

[root@host tmp]# 
./iDRAC-with-Lifecycle-Controller_Firmware_KTC95_LN_4.10.10.10_A00.BIN -q 
Collecting inventory...
./bmcfwul: /lib64/libc.so.6: version `GLIBC_2.14' not found (required by 
./bmcfwul) .
Inventory collection failed.
[root@host tmp]# 

I am aware I can extract the payload and upload to the iDRAC directly, but this 
is not practical when hundreds of servers need upgrading. Equally, the install 
from update CD method is also unworkable as it requires reboots, often in 
remote locations.

Is there a solution?

___
Linux-PowerEdge mailing list
Linux-PowerEdge@dell.com
https://lists.us.dell.com/mailman/listinfo/linux-poweredge

___
Linux-PowerEdge mailing list
Linux-PowerEdge@dell.com
https://lists.us.dell.com/mailman/listinfo/linux-poweredge


[Linux-PowerEdge] CVE-2020-5344

2020-04-09 Thread isdtor


[EXTERNAL EMAIL] 


Hi list,

Can someone from Dell please explain how we can deploy security updates to 
machines where the OS is no longer supported, such as RHEL/CentOS 6? The 
upgrade below was downloaded from Dell's support web site, "Operating system" 
selected is "Red Hat(R) Enterprise Linux 6". And quite obviously, this doesn't 
work on RHEL 6 because glibc is version 2.12.

[root@host tmp]# 
./iDRAC-with-Lifecycle-Controller_Firmware_KTC95_LN_4.10.10.10_A00.BIN -q
Collecting inventory...
./bmcfwul: /lib64/libc.so.6: version `GLIBC_2.14' not found (required by 
./bmcfwul)
.
Inventory collection failed.
[root@host tmp]# 

I am aware I can extract the payload and upload to the iDRAC directly, but this 
is not practical when hundreds of servers need upgrading. Equally, the install 
from update CD method is also unworkable as it requires reboots, often in 
remote locations.

Is there a solution?

___
Linux-PowerEdge mailing list
Linux-PowerEdge@dell.com
https://lists.us.dell.com/mailman/listinfo/linux-poweredge