false positiv on CVE-2021-33621 red hat 8 und 9

43 views
Skip to first unread message

No Data

unread,
Oct 6, 2026, 5:54:09 AM (5 days ago) Oct 6
to Wazuh | Mailing List
CVE-2021-33621 on Red Hat Enterprise Linux 8/9 is a false positive. 




Red Hat Enterprise Linux 8.10 (Ootpa)        

 ruby     

 Installed 2.5.9-115.module+el8.10.0+24408+7ffaaa88   Fixed       2.5.9-111.module+el8.9.0+19193+435404ae   

 

ruby     

 Installed 3.0.7-167.el9_8             Fixed     3.0.7-162.el9_4 


-----------

rpm -q perl-DBI --qf '%{NAME}-%{EPOCHNUM}:%{VERSION}-%{RELEASE}.%{ARCH}\nModule: %{MODULARITYLABEL}\n'

RHEL 8

 ruby-0:2.5.9-115.module+el8.10.0+24408+7ffaaa88.x86_64

 Module: ruby:2.5:8100020260615131019:489197e6

   

RHEL 9

 ruby-0:3.0.7-167.el9_8.x86_64

 Module: (none)


with Best regards

Md. Nazmur Sakib

unread,
Oct 6, 2026, 6:51:29 AM (5 days ago) Oct 6
to Wazuh | Mailing List
Hello!

It seems like a false-positive detection on my end as well.

Before escalating this further to fix the CTI feed, it will be very helpful if you can share some further information.
Go to your Vulnerability Dashboard > Inventory

Search for this vulnerability.

Click on the details, copy the JSON from both agents, and share it with me. 

I am sharing a screenshot for reference.
image (3).png


I look forward to your update.

No Data

unread,
Oct 6, 2026, 6:59:02 AM (5 days ago) Oct 6
to Wazuh | Mailing List
Sorry, I can’t share the entire output. Which fields are you interested in?

Md. Nazmur Sakib

unread,
Oct 6, 2026, 7:24:35 AM (5 days ago) Oct 6
to Wazuh | Mailing List

Share these information from the Vulnerability Dashboard > Inventory

package.name

package.version
host.os.name

host.os.platform

host.os.version



It will help me verify that the issue is not related to the package version not updating correctly by syscollector. It's okay if you are not comfortable sharing any of the information I have asked for.

No Data

unread,
Oct 6, 2026, 10:11:33 AM (5 days ago) Oct 6
to Wazuh | Mailing List
I can do that tomorrow. However, all of this information is already included in my first email.

Md. Nazmur Sakib

unread,
Oct 7, 2026, 12:24:49 AM (4 days ago) Oct 7
to Wazuh | Mailing List
If you have the same information that you have shared in the Inventory section, I do not need that information further.

I just wanted to make sure that the syscollector and the indexer-connector are updating the package information correctly in the state vulnerability index.

Md. Nazmur Sakib

unread,
Oct 7, 2026, 12:45:00 AM (4 days ago) Oct 7
to Wazuh | Mailing List
I have escalated this to the team responsible for updating the feed. They will review this further and will make any necessary changes. I am sharing the GitHub link if you want to add any additional information and keep track of the progress.
https://github.com/wazuh/wazuh/issues/40108
Reply all
Reply to author
Forward
0 new messages