RHEA-2023:3352MediumCVSS 5.3
Red Hat Enhancement Advisory: OpenShift Virtualization 4.11.4 Images
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products15
- CNV 4.11 for RHEL 8
- container-native-virtualization/checkup-framework@sha256:2bcd239de1b16eb64ea314dbfe4c965ed2ff6681b092423146ce1f9fba5dbd8d_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hostpath-csi-driver-rhel8@sha256:5eca89e6ac055a448b2e2150698c5fa2e66f8026a0a5da28defcea6c4376ecaa_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hostpath-csi-driver@sha256:5eca89e6ac055a448b2e2150698c5fa2e66f8026a0a5da28defcea6c4376ecaa_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-console-plugin@sha256:83bf9af49dc07256b50e13ad0ecc7cd9880b7c40e2b2061bbe125c0e9d9e2e6e_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:90ecca3593937aff5be9df15281bc785db64389268fbe38f6740c0dfbc53dc23_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:bb438a4542cbfed7e678dac1572ec5638b9b37fb0e5e2c95da975991dd4f05e6_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:1c5393262a8eb9d449f2e803ba992429ca28d35d82813c43f1e2ae9cb62e11d7_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:7f287881ac2622d448495589ce866afa23e8938af5a62c0a055076275b8a6361_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:48b8fe110deab5d921ac15dd554aee80cc971205c6fdd09169e64572fa6f4b50_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:0253e34b988af03f387c5531646996e94c6d3c06ad8bdc03ade5343570254337_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:e99341b0b59811648d4e4ae44a47359cc3c588a2f8da0bfa75d68f3e8568ede1_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:ffd5c41704e6dbdf7ba4dc5128f0f9896f31ab41994924b7db957d211113aef5_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:471824fc8548ce1530b1490df4c51bda7228b10bd9f63ac1b596e9a8a565479e_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/vm-network-latency-checkup@sha256:3730fa5da224ed4ebaa44e7e1fa694a15c8469e6b318a6d9136f17d9158252a5_amd64 as a component of CNV 4.11 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHEA-2023:3352
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2078545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2152534
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167509
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169272
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176032
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189460
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhea-2023_3352.json