Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.10.0 RPM security,enhancement&bugfix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-36221 — golang: net/http/httputil: panic due to racy read of persistConn after handler panic CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2021-44716 — golang: net/http: limit growth of header canonicalization cache CVE-2021-44717 — golang: syscall: don't close fd 0 on ForkExec error
🎯 Affected products6
- RHODF 4.10 for RHEL 8
- mcg-0:5.10.0-72.el8.ppc64le as a component of RHODF 4.10 for RHEL 8
- mcg-0:5.10.0-72.el8.s390x as a component of RHODF 4.10 for RHEL 8
- mcg-0:5.10.0-72.el8.src as a component of RHODF 4.10 for RHEL 8
- mcg-0:5.10.0-72.el8.x86_64 as a component of RHODF 4.10 for RHEL 8
- mcg-redistributable-0:5.10.0-72.el8.x86_64 as a component of RHODF 4.10 for RHEL 8
✅ Remediation
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated by disabling HTTP/2. Setting the GODEBUG=http2server=0 environment variable before calling Serve will disable HTTP/2 unless it was manually configured through the golang.org/x/net/http2 package. Workaround: This bug can be mitigated by raising the per-process file descriptor limit.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2022:1361
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2026342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030801
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030806
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1361.json