Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.1.11 security fix and container updates
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-23017 — nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name
🎯 Affected products2
- Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:19f9e374bbf3621b51a37ec23aaf88651c68321644984e27ea277e364d8a7712_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. *Important:* This upgrade of Red Hat Advanced Cluster Management for Kubernetes is not supported when you are running Red Hat Advanced Cluster Management on Red Hat OpenShift Container Platform version 4.5. To apply this upgrade, you must upgrade your OpenShift Container Platform version to 4.6, or later. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.1/html/install/installing#upgrading-by-using-the-operator
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2021:3653
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1963121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999375
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3653.json