RHBA-2024:2648HighCVSS 7.5

Red Hat Bug Fix Advisory: LVMS 4.13.6 Bug Fix Update

Published
May 1, 2024
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

🎯 Affected products17

  • LVMS 4.13 for RHEL 8
  • lvms4/lvms-must-gather-rhel8@sha256:49925f850770c4ccba59dbceb9ffe0d7c59e5acf7d0b54baf7b2dc7f1e9494de_ppc64le as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-must-gather-rhel8@sha256:878e2f7b4af26196d30faf110a667238addb4c67d039ccaa9196a45e45af127a_amd64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-must-gather-rhel8@sha256:ad023433c7b4ce0ecd159db915236de9a3273b0bc24edfb31dbbafd8b9706bb1_s390x as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-must-gather-rhel8@sha256:ef2c80336249bf864d4ccab747f7097766f368a575e2e45645fa92bd19acfd60_arm64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-operator-bundle@sha256:2ce17ffcaa145ab476d367862c017a55e9cd4898c3f389906e6705ef992c1e1f_arm64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-operator-bundle@sha256:6698ed0920b36f2581438ab6000db8118c7be63407d644f64c644549f8ef019d_ppc64le as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-operator-bundle@sha256:75039a8f5bd901b241105bd167f5bfcda4bf93046d44d407a0c4e0c3bc436680_amd64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-operator-bundle@sha256:af8e0eec77f039c81d68853d126042cf1d0d61db762f019ccc8a8f3145282435_s390x as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-rhel8-operator@sha256:1e572fe0d7b1aa06b315ce506b7342429fa13c3b76676fd77246ff153e3edd7a_arm64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-rhel8-operator@sha256:395cdb02c412081da754cb3a54756da746e90296536caa8e9e560d2c461cd047_ppc64le as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-rhel8-operator@sha256:d5ac2b9aed11bfa60b02deb83f83f28702a9c5b8081003f05dbe47619e037a44_s390x as a component of LVMS 4.13 for RHEL 8
  • lvms4/lvms-rhel8-operator@sha256:eae7d1853ab166c25f0af60543de5ad5c9a7b4ac48dba6b672a24451eeb1ac6f_amd64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/topolvm-rhel8@sha256:462297cea11fb99476264faa8fef27b8f75045961080159550d5c88c5d1af7a4_arm64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/topolvm-rhel8@sha256:6fff57b8fc3b932576742da3647c204b0b850f369ac38dc49c6b4785536d90dc_amd64 as a component of LVMS 4.13 for RHEL 8
  • lvms4/topolvm-rhel8@sha256:90def498de78fc8c8904ec48530389628c20f51a51fb62a8652dd2c2721de3e4_ppc64le as a component of LVMS 4.13 for RHEL 8
  • lvms4/topolvm-rhel8@sha256:c43dd964a36d9b7c75aaf28cc19fdea81b0e85a802538d1fc146b29f23dd4240_s390x as a component of LVMS 4.13 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.

🔗 References (2)