Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.10.0 enhancement, security & bug fix update
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-29923 — golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet CVE-2021-34558 — golang: crypto/tls: certificate of wrong type is causing TLS client to panic CVE-2021-36221 — golang: net/http/httputil: panic due to racy read of persistConn after handler panic CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2021-44716 — golang: net/http: limit growth of header canonicalization cache CVE-2021-44717 — golang: syscall: don't close fd 0 on ForkExec error
🎯 Affected products73
- RHODF 4.10 for RHEL 8
- odf4/cephcsi-rhel8@sha256:9de4f6848556d362dab3fcc534a6e7098649b353139d1b8d796317b8474125c2_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/cephcsi-rhel8@sha256:d828aab4db3bb853a9c2be53ef65e968e7dca8faacb480e9c6802093181a8f16_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/cephcsi-rhel8@sha256:f41411e6c6d65e52a3e3bb6cf3582116646e8ebc4ae9bf8eac77a00433855b20_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-core-rhel8@sha256:4338ea20fce25b664e880066144a5de7769623373cbfde1f46666aace4d9b855_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-core-rhel8@sha256:4ed1db89bdd6150f28721a3c18bcfa7e221b1b621c12ae8830fd35923dea08ca_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-core-rhel8@sha256:f2a35675f04b3852dadbea99fef57dcc85ab5670929f7b0d52981e227047123c_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-operator-bundle@sha256:983c8661518fe3efa01e5d64b389043ac856f013b4ec346d5da252848d8b2252_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-operator-bundle@sha256:e1ae5ed85e17ad3cdbdc5049f5c3064f2616c5a6f445ec9d38e7f915d494776b_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-operator-bundle@sha256:eb454980189ece047c2d97046f77ed67877ff0d6a17ea52621f28d9fba702d28_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:4a4bd7a6b537d75aaa982c308eedc805809c2576f5d75498a432991c7e199534_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:ae593d312597211d35a2d89cefdcf879eb1db1eac9bfdc76c756be78b111b5e7_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:e6162ae89bf73e29c304080e868d47f13c46e389c6f2f6bde856ebeda20306f5_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:09a8a3da7024fbd081caff8cd62c67c898beade0597ff0656d0994daa08b4166_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:3a6619c418c74824b6a69dfce26f2070aae8b7d56b7cea756ab68d5e2c459e07_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:d9332ec67415a78d38ee60b7d15c63475693590160caeb461767683b0dd21751_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-operator-bundle@sha256:7cebd714435a398ade4f686d2943786d8485ea5333f5b16365991ae49303f097_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-operator-bundle@sha256:a640d9395a7dad7c5d2306af3ba60a3430358e705b647ebf272e38e27282ad4c_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-operator-bundle@sha256:a70904f7570095a0721e5fcf7bc4fe1c431112f6ef4437d1b5ed67f8462d7926_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:32a1d52cfc7b91c0186e5423245bd06e525c6890ed77bca7335e56c48e2cd86b_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:9759e45e271ef502e2ed6f7e12dc2ecb10e39fc0cd22e195f7d47edec39ff0fd_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:a3b3a3e9a8332d3b5d5137ff89e1843e6506507c2ebb069c9a7bbfcd03dfdd42_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/odf-console-rhel8@sha256:1d988be397cae4aad67a43534a2875edbee24135ba549549156fb8aa883f22a6_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/odf-console-rhel8@sha256:54f6bca97f44b76c065bbaed5915a97693ce1ea1a3f3a1cf65c610ff81622f3c_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/odf-console-rhel8@sha256:7c89981748d38fafa31c8a8d624381db9c14c07160de7bc13588a0b0e3673b33_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:84407db398089fe2b60b83f4cbd94fd30581d928d6edf614de5d34cec3f21014_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:c7e57040123bc4ef58444a7b2bbf076588876c56f8903e57a3646db0c4c430ca_ppc64le as a component of RHODF 4.10 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:cca6c8289d099a0c6ad92387991089058f344d9fe33c63535898023e182856dc_s390x as a component of RHODF 4.10 for RHEL 8
- odf4/odf-csi-addons-rhel8-operator@sha256:c2a30fc5971995e4c3bf90f7c56733d74a3af9f3e59978d4705a3eee5d0b565a_amd64 as a component of RHODF 4.10 for RHEL 8
- odf4/odf-csi-addons-rhel8-operator@sha256:e7daa827ed079b6f60419beebdf9a5adab484c5617edc6ed51ff4deb8e7ce735_ppc64le as a component of RHODF 4.10 for RHEL 8
- +43 more not shown
✅ Remediation
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated by disabling HTTP/2. Setting the GODEBUG=http2server=0 environment variable before calling Serve will disable HTTP/2 unless it was manually configured through the golang.org/x/net/http2 package. Workaround: This bug can be mitigated by raising the per-process file descriptor limit.
🔗 References (108)
- selfhttps://access.redhat.com/errata/RHSA-2022:1372
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1898988
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1954708
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956418
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1970123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1972190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1974344
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981694
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1983596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1992006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996833
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2003532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005801
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2021313
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2022424
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2022693
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024107
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2026007
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2027666
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2027826
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2028559
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2029413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030602
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030801
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030806
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031023
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031705
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032969
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2033251
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034805
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034904
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2035774
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2035995
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2036018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2036211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037279
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037318
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2038884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041507
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042866
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044823
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2045084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2046186
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2046254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2046677
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2046766
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2046887
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047162
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047562
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047625
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047642
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048107
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048370
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049075
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049081
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049424
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049509
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049718
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2049790
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050142
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050402
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051249
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051599
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052438
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052996
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053156
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2054147
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2054755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061251
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1372.json