RHBA-2024:3776MediumCVSS 5.9

Red Hat Bug Fix Advisory: LVMS 4.14.6 Bug Fix Update

Published
June 10, 2024
Last Modified
August 12, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-24783 — golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

🎯 Affected products17

  • LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:31b4449bad1e87203473227e439209f82368a98b8374b23b297610d63b0d6322_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:71855fe56b4b5d0d5d72f170124d4313b731b036186372d5bdab2cd448054ad2_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:d2664dd60aa6ed6e577aede1b6c75e0fa342baff33d34ff7f81df2473cb116aa_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-must-gather-rhel9@sha256:fdc2bbb1d267438b89dfea972d359fd889ba37e243a3124c4f30ee67ba2f3fb1_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:8fcc797130633dc1f7cde49e6a26fe9ed512ad31ad7d3926139037818eed3b4c_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:d761307b7013d4e82aa8a3219ed48964574466bc5aa2936d12c14a7826977936_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:e4e09f39ab69c0d0b8ae3febe599f61ec2c18fd51982d70e8e12218a27d8d67e_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-operator-bundle@sha256:f6e1dafbff82547d118eea721e197a89b94d838f4ec7a100b643dacc36327828_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:35b79bd23e4b826e7435f8d0d6ab00fa153bb12d5d6cc025f1c6885898547008_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:585c86932e27e05635041deda8e594cbd42dc7f6cfae6a5e821ff74300cfe988_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:5ff014f2ac5325d144510db4e841de9dfd6ef6852273af95a3f2eb634531435e_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/lvms-rhel9-operator@sha256:e7331d87b408f4d35780ad92b07e878bcefbd38a0572a6fc42d3cbda92cc0c02_ppc64le as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:25db92ac006601341f71d9f8b04f868ad53384a87cc10b682e7759f5f342b7f3_s390x as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:3c9e04d3970551d7158ce20d3be0f6be73ed837c2419184461ff03d5e9011f91_arm64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:a21b811411a475a3ad2b6f64873cee2f579abdf540e66b66450d1c29bb507ad6_amd64 as a component of LVMS 4.14 for RHEL 9
  • lvms4/topolvm-rhel9@sha256:ea8c15ea24bc7cb1ceebed9aaeb4ccea0b0411cc81c7fd3a6197ed38d5671403_ppc64le as a component of LVMS 4.14 for RHEL 9

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (3)