RHBA-2024:2646HighCVSS 7.5

Red Hat Bug Fix Advisory: LVMS 4.14.5 Bug Fix Update

Published
May 1, 2024
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

🎯 Affected products17

  • LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:12d2d04ec793b36e031bfe67df77afb815133faa0374999ff1a83d6b8cb1cbf4_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:497a689e898ace0a2e3b7f7a9b6f51e2f81f7fa5b4c45ec4c514e02cf25fa76c_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:7d4fc9165c9803a3216709a0dc53e76a0461d403f8dfb7cd28aa9551d54b6ba2_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:bac397b05c11813f300f1dd97270fcec86c6c6731e7de639c0c537dd0325a3bd_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:22dbd5d21e324f841df4c1f217858f56a4389538b2473f176772b0bf2cac0009_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:597a0a8fb5beaf217cf019c8a60cbc696d2cf22742b2da8d690d40d1c6c6be01_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:995379d05cc39881ab5e9d2bd043617bb20fb85bebf22da3da69fd73ab79563f_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:ef754bda8220ce137caaf7e7ef2851dc3c2de48985af75d62ea61766239889e6_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:5688b13ece8a9d872db73853035b35cd72b6b5c6492012d01620302ee5afe264_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:69a6af5317fdc29919e2f431856fd8219354db5b6d8c2b7e6c8fe20d7b85b1bf_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:72f0fda985bef8badd41dad13b031013b6efa6e4930aa6e8f34a2ecc68d7230b_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:a8ca87c72771ba4c02e027f0da5b3c15f0e29089df90fb66dbc2035574cdaf59_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:10bd442750db361d7854b430b26a21a0908ebdeae9f7ba25cb0802877a454620_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:603cf632d59732b05533b2ae7640fd1543400249fa53378bd7dfac86771adab7_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:98b45141391b5bb2ee0466c780716b2903b4ed16aef1124b588ffa882782f125_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:da81cf0dc341e35a860ccbe49d84eb454fde20b4fc7fe0802ec50957026efad1_amd64 as a component of LVMS 4.14 for RHEL 9

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.

🔗 References (2)