You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Jun 27, 2025. It is now read-only.
<criteria operator="OR">
<criterion comment="Red Hat Enterprise Linux must be installed" test_ref="oval:com.redhat.rhba:tst:20223893008"/>
<criteria operator="AND">
<criterion comment="Red Hat Enterprise Linux 9 is installed" test_ref="oval:com.redhat.rhba:tst:20223893007"/>
<criterion comment="gzip is earlier than 0:1.10-9.el9_0" test_ref="oval:com.redhat.rhsa:tst:20224582001"/>
<criterion comment="gzip is signed with Red Hat redhatrelease2 key" test_ref="oval:com.redhat.rhsa:tst:20224582002"/>
</criteria>
</criteria>
The one generated by this python code results in:
<criteria operator="OR">
<criterion comment="Rocky Linux must be installed"
test_ref="oval:org.rockylinux.rlsa:tst:20250426001"/>
<criteria operator="AND">
<criterion comment="gzip is earlier than 0:1.10-9.el9_0"
test_ref="oval:org.rockylinux.rlsa:tst:202245829690"/>
<criterion comment="gzip is signed with Rocky Linux rockyrelease2 key"
test_ref="oval:org.rockylinux.rlsa:tst:202245829691"/>
</criteria>
<criteria operator="AND">
<criterion comment="gzip-debuginfo is earlier than 0:1.10-9.el9_0"
test_ref="oval:org.rockylinux.rlsa:tst:202245829692"/>
<criterion comment="gzip-debuginfo is signed with Rocky Linux rockyrelease2 key"
test_ref="oval:org.rockylinux.rlsa:tst:202245829693"/>
</criteria>
<criteria operator="AND">
<criterion comment="gzip-debugsource is earlier than 0:1.10-9.el9_0"
test_ref="oval:org.rockylinux.rlsa:tst:202245829694"/>
<criterion comment="gzip-debugsource is signed with Rocky Linux rockyrelease2 key"
test_ref="oval:org.rockylinux.rlsa:tst:202245829695"/>
</criteria>
**<criteria operator="OR">
<criterion comment="Rocky Linux 9 must be installed"**
test_ref="oval:org.rockylinux.rlsa:tst:20250426002"/>
</criteria>
</criteria>
I suspect that last "OR" for Rocky Linux 9 should be AND. The last criteria always results in a 'true'.
So, I have a fully patched system with gzip 1.12 - Looking at the results, everything is 'false' except Rocky Linux 9 = true.
All,
I am trying to figure out why OpenSCAP fails every CVE test. In looking at the RHEL9 oval file:
https://security.access.redhat.com/data/oval/v2/RHEL9/rhel-9.oval.xml.bz2
I see gzip issue has the following criteria
The one generated by this python code results in:
I suspect that last "OR" for Rocky Linux 9 should be AND. The last criteria always results in a 'true'.
So, I have a fully patched system with gzip 1.12 - Looking at the results, everything is 'false' except Rocky Linux 9 = true.