RHBA-2024:3778MediumCVSS 5.9
Red Hat Bug Fix Advisory: LVMS 4.13.7 Bug Fix Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-24783 — golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm
🎯 Affected products17
- LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:7729e2a6e0200218d398c81328a909575b32eb7ddc05f28db19d108bcf7f1dae_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:7f550aabc5045192f2a376cea542a3f7af4f91ae38ec92cc88087424c969e79a_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:b48d244af8d297034cd369bd5030ffce1337c773843faf96a33e08216191afb1_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:c267a14958a453fe560fda80e513a45e317b1f659e9a95e2806a02352a8146a0_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:16956b691a4962411aa3ba9994c8cc5de7b25c9209801f36b64df5fce6f1c4b2_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:1cab118b2306a363ec45619b32a104475307b49f6c85f28ca2755193bb33f27f_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:a9da6a7fc468692a0e88927661d04bf0387f502ecdce3142687a2512c80fb26a_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:b5654e5f8135060d40949758bd115941087f8944ee6db208c401b83913f2c9c3_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:3e9350e4929af4869fc1ad2d8a86de45b17d65dc2908b86bc35e4b8fff2620a3_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:5fa67415c5a9c2cb0738c8f675de18bc9af66b99d37f3c9a748f579af89b4e89_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:6519363c9c198eab1ed7cae058235441f026628daac0c11db33850fcbf020e6c_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:e613632e80317068727cc0a0307ef13dfe2ceccf9d2526bbe8d192ddecf53ca1_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:22aed966d91e2f76c1f5b25edabbc87a1ea9b00fb6f0c5cb23873c5cd992b15a_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:28da801bfedbfdc14b8bbac0990361308f79c0982c8650e9e8d79937c4bab169_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:8ea239033fc9ae277687b2fd536b64969e77fd4424d61abdab253f9e3c920d9f_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:938bdf0178f4bcadc6d7f2c483c5f472746212e88248445c6ceb53aa9341be47_amd64 as a component of LVMS 4.13 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.