Red Hat Bug Fix Advisory: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog
🔗 CVE IDs covered (9)
📋 Description
CVE-2023-45287 — golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28176 — jose: resource exhaustion CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-30255 — envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-41184 — keepalived: Integer overflow vulnerability in vrrp_ipsets_handler
🎯 Affected products21
- Red Hat Ceph Storage 7.1 Tools
- rhceph/ceph-nvmeof-cli-rhel9@sha256:172cb8cb8dc3484e85b3699febf8f880326e3f6db1df142e003d661064188df2_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/ceph-nvmeof-cli-rhel9@sha256:cf85b6e0a65ae9c8c9bd5fb734328f416dc4403276af382342b907e29fb7a09b_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/grafana-rhel9@sha256:90ac9350bcdfb7ea4c792473cd6daf44ea959b713171948ff7383dbab0b9ab53_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/grafana-rhel9@sha256:b6a68d6ca6f8fd1fa28505cb6b28228c9d59200fa16b9c4424860185f83a7702_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/grafana-rhel9@sha256:c80a162dbd5a0aaa8f09ead2b51e6d757bc9fb37dbac4e83d47ec0a430833770_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/keepalived-rhel9@sha256:5596adad0d53b9c2d7ac2f852054a27c9f6673c86b3e536bc2d1b45c10ac5627_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/keepalived-rhel9@sha256:b058c89bc6ed1fe360d54ce5e1affadd788da2c3ed78dbed20843f42cec8cc91_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/keepalived-rhel9@sha256:e7e799173022e5c0ed3baf2f8d5ee87bb411f658d867c10d97fab795ee3973ac_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-7-rhel9@sha256:10390294e3a42068d65886e392e11d4565b7ed44120933976a000aab358f962e_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-7-rhel9@sha256:665bf2b06022f0d99dce923f3d9901e34f1a4081ba2155a3abb07ae738e77ca2_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-7-rhel9@sha256:9e7f88ea7684c8354d363532bd4769f612aa5fe1175b36c56c760bcd77d9261c_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:780876a9b75f314f4363306ec07258e8e32e45e857698f1f5beb201f16b6a9c3_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:80036eeff471ac2a9d8dde6ce8a252bf8f88ba60f9f41af246ce5250a6cbdf9e_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:c6ede411166431bc5c3c1452c8dc405e864f057e367a61475a251bb0ef81600b_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:592b4f648ece4fc3ca0a2a0cb85103b63c3a53afc3c269a9d3d3796a751541e0_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:5aeae74254653255e8ac397f4c0d426859a3d3882ff555a1734e29269290c04b_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:878773172461a91c2468caf7ec703c87fab854e0bc53c1c9d2f67627a674f977_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:84bc504c6dace7c56113bb2a910f92434f61275ea10dcd4b71e3491945a5ae0e_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:b24534123df33477e97b8efd8aad4770ce9323b0c49eaab84246bea4a84e5819_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:d6b277ae3b9aad91e5a012ebebd9562ed9e6bdfb3875ce6cb169fcc69711862b_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: No current mitigation is available for this vulnerability. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.