-
Bug
-
Resolution: Done
-
Major
-
None
-
Important
-
5
-
-
** Note that this is a public ticket, please refrain from adding any sensitive data. **
Description of Problem
When working on a fully updated RHEL 7.9 ELS system, insights show no CVEs with advisories. But as soon as kernel-doc package would be installed, Then 150 CVEs pop-up from nowhere.
How reproducible
Always
Steps to Reproduce and Actual Behavior:
- Install a RHEL 7.9 and register with redhat portal
- Enable rhel7-server-els-rpms repo and update all packages + reboot with latest kernel
- Install insights-client and register with insights
- Open the system from https://console.redhat.com/insights/inventory, Check the Vulnerability tab and and notice no CVEs with Advisories present
- Install kernel-doc package and re-run insights-client command
- Repeat step 4 and now notice, 150 CVEs out of no where.
Expected Behavior
False-Positive CVE detection needs to be minimized as much as possible.
Business Impact / Additional info
It seems RHEL 8.8 EUS also suffers from a similar issue but not for RHEL 9.4 EUS. [ as tested by the end-user ]
- is duplicated by
-
RHINENG-15013 Incorrect Advisory mapping on the CVE in the Insights
-
- Closed
-