RHSA-2022:0577MediumCVSS 8.6

Red Hat Security Advisory: Windows Container Support for Red Hat OpenShift 5.0.0 [security update]

Published
March 28, 2022
Last Modified
August 15, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2020-28851 — golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension CVE-2020-28852 — golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-29923 — golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet CVE-2021-31525 — golang: net/http: panic in ReadRequest and ReadResponse when reading a very large header CVE-2021-33195 — golang: net: lookup functions may return invalid host names CVE-2021-33197 — golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty CVE-2021-33198 — golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents CVE-2021-34558 — golang: crypto/tls: certificate of wrong type is causing TLS client to panic CVE-2021-36221 — golang: net/http/httputil: panic due to racy read of persistConn after handler panic

🎯 Affected products3

  • Red Hat OpenShift Container Platform 4.10
  • openshift4-wincw/windows-machine-config-operator-bundle@sha256:e6ad3e6e043aeeebc84da2071ca26bb1e89c071598b5088a8a7f237626491072_amd64 as a component of Red Hat OpenShift Container Platform 4.10
  • openshift4-wincw/windows-machine-config-rhel8-operator@sha256:31af4d44c7cc4e00219a99451ce2e3523cdba90d575d58979ae1355c4350b6fe_amd64 as a component of Red Hat OpenShift Container Platform 4.10

✅ Remediation

For Windows Machine Config Operator upgrades, see the following documentation: https://docs.openshift.com/container-platform/latest/windows_containers/windows-node-upgrades.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (24)