RHSA-2019:4273HighCVSS 7.5
Red Hat Security Advisory: container-tools:1.0 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth
🎯 Affected products125
- Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.src (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-6.gite94b4f9.module+el8.1.0+4908+72a45cef.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- container-selinux-2:2.94-1.git1e99f1d.module+el8.1.0+3468+011f0ab0.noarch (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- container-selinux-2:2.94-1.git1e99f1d.module+el8.1.0+3468+011f0ab0.src (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.src (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-4.git9ebe139.module+el8.1.0+4908+72a45cef.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containers-common-1:0.1.32-6.git1715c90.module+el8.1.0+4903+9bde5d6c.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +95 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2019:4273
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4273.json