RHSA-2021:3653HighCVSS 8.1

Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.1.11 security fix and container updates

Published
September 23, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2021-23017 — nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name

🎯 Affected products2

  • Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
  • rhacm2/acm-must-gather-rhel8@sha256:19f9e374bbf3621b51a37ec23aaf88651c68321644984e27ea277e364d8a7712_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. *Important:* This upgrade of Red Hat Advanced Cluster Management for Kubernetes is not supported when you are running Red Hat Advanced Cluster Management on Red Hat OpenShift Container Platform version 4.5. To apply this upgrade, you must upgrade your OpenShift Container Platform version to 4.6, or later. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.1/html/install/installing#upgrading-by-using-the-operator

🔗 References (5)