RHSA-2022:2183MediumCVSS 8.8

Red Hat Security Advisory: Release of containers for OSP 16.2.z director operator tech preview

Published
May 11, 2022
Last Modified
August 15, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2019-11253 — kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service CVE-2019-19794 — golang-github-miekg-dns: predictable TXID can lead to response forgeries CVE-2020-15257 — containerd: unrestricted access to abstract Unix domain socket can lead to privileges escalation CVE-2021-29482 — ulikunitz/xz: Infinite loop in readUvarint allows for denial of service CVE-2021-32760 — containerd: pulling and extracting crafted container image may result in Unix file permission changes

🎯 Affected products4

  • Red Hat OpenStack Platform 16.2
  • rhosp-rhel8-tech-preview/osp-director-downloader@sha256:d3915d621da43f74f177a3dd416fb89e3bb66dd58d2d915243fcf6102ffc9fdb_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8-tech-preview/osp-director-operator-bundle@sha256:dcf25f95c2a758e097d1e344d6f46b43b6050b6f4a70587eacee34430823595d_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8-tech-preview/osp-director-operator@sha256:95957e8ab5c45d5bcf35f8c59d5748e3ed8d5ab2db0d46fce46b376217e23d56_amd64 as a component of Red Hat OpenStack Platform 16.2

✅ Remediation

OSP 16.2 Release - OSP Director Operator Containers tech preview

🔗 References (9)