Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.1.12 security fixes and container updates
🔗 CVE IDs covered (7)
📋 Description
CVE-2021-32626 — redis: Lua scripts can overflow the heap-based Lua stack CVE-2021-32627 — redis: Integer overflow issue with Streams CVE-2021-32628 — redis: Integer overflow bug in the ziplist data structure CVE-2021-32672 — redis: Out of bounds read in lua debugger protocol parser CVE-2021-32675 — redis: Denial of service via Redis Standard Protocol (RESP) request CVE-2021-32687 — redis: Integer overflow issue with intsets CVE-2021-41099 — redis: Integer overflow issue with strings
🎯 Affected products2
- Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:382ae2f9e7e8fcca18bb29f29994bc7f30ba24b810ad127a35254ddef7900f62_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. *Important:* This upgrade of Red Hat Advanced Cluster Management for Kubernetes is not supported when you are running Red Hat Advanced Cluster Management on Red Hat OpenShift Container Platform version 4.5. To apply this upgrade, you must upgrade your OpenShift Container Platform version to 4.6, or later. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.1/html/install/installing#upgrading-by-using-the-operator Workaround: Prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands. Please see https://redis.io/topics/acl for more information on how to do this. Workaround: The flaw can be mitigated by disallowing usage of the CONFIG SET command via ACL configuration. This will prevent clients from setting the `proto-max-bulk-len` configuration parameter. Please see https://redis.io/topics/acl for more information on how to do this. Workaround: The flaw can be mitigated by disallowing usage of the CONFIG SET command via ACL configuration. This will prevent clients from setting the above configuration parameters. Please see https://redis.io/topics/acl for more information on how to do this. Workaround: Prevent unauthenticated users from connecting to Redis by using network access control tools (e.g., firewalls) or enabling TLS and requiring users to authenticate using client side certificates. Workaround: The flaw can be mitigated by disallowing usage of the CONFIG SET command via ACL configuration. This will prevent clients from setting the `set-max-intset-entries` configuration parameter. Please see https://redis.io/topics/acl for more information on how to do this.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2021:3949
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010991
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011020
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3949.json