RHSA-2022:6318MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.9.48 extras security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS
🎯 Affected products177
- Red Hat OpenShift Container Platform 4.9
- openshift-tech-preview/metallb-rhel8@sha256:0ef2fc630462cb114e0296cf3f8584657381601a2ef410b2c0fc8c1df87a861e_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift-tech-preview/metallb-rhel8@sha256:69d7518340d7a78cfd53005f8bb755d024d96a813fa16d08cddcc0ad31cf5dc9_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift-tech-preview/metallb-rhel8@sha256:b82dd229082a5153e6cbdb4ad9b5094dd00ffde679604d53372e1c240ad9eea7_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift-tech-preview/metallb-rhel8@sha256:cb887bd793fe82a84e75a857752dd91f84e4b631e4b0f635c3fac4c8dc5b3c7e_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/cloud-event-proxy-rhel8@sha256:06169f0cd96f0468bced1f0f61478f6eee4e5fb628e782a981c236ed952edbae_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/cloud-event-proxy-rhel8@sha256:542421646e547e67e8a799148311676e409d10856ed9334c789ee1035011aa47_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/cloud-event-proxy-rhel8@sha256:6d989af2faddea76a7a3e5e565e2548f979c7cd6ff6edf16c92ea7fdecb7dbea_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/cloud-event-proxy-rhel8@sha256:e9cc385a36dcc1c50119b085dd0e97cc38327da2a53930cb32abc9cda08efe22_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:481f7b89cd1bb44dcec07f545e2cf13083dc32194420e22d2d8f6404704a9005_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:6ab49b54e4b5c83b18bf99c1971119b6bf0431f1fd203a97fd41e4a054d14279_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:89ccb55d396902b8c2b5440c75fc7d96fc2271b1cabd9282474af7f39b774fc2_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:dcb7e3bb04ad6a367402dd6b459322df74a8c3e9b296823603b0588e50c86672_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8-operator@sha256:2f851cbc68d1499fcf9208f2203d3755ff58b5aca29920ce4aeabe588fc41dd5_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8-operator@sha256:5736d8e3c2c77010e7ad91f0486fd0b06ec958c73905b226f451f01db341d9ae_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8-operator@sha256:62ff25b246cc1a226361aa7b57ad612f00eb56cb51a60dd6dfd368502bcaff26_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8-operator@sha256:664045fc681f020b65d51b639e8e1df52a805a8f357068bca1b714f3a18b5ec3_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8@sha256:0ef2fc630462cb114e0296cf3f8584657381601a2ef410b2c0fc8c1df87a861e_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8@sha256:69d7518340d7a78cfd53005f8bb755d024d96a813fa16d08cddcc0ad31cf5dc9_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8@sha256:b82dd229082a5153e6cbdb4ad9b5094dd00ffde679604d53372e1c240ad9eea7_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/metallb-rhel8@sha256:cb887bd793fe82a84e75a857752dd91f84e4b631e4b0f635c3fac4c8dc5b3c7e_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-ansible-operator@sha256:4cbac0a0adc55db3020876b723f9d55b9ba098b1f5293edf6c093c49cfbb03d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-ansible-operator@sha256:86e4c43cf4b66eba4b1041818ee8a1047538dc4f5e288fe91d0f5beeea3b4698_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-ansible-operator@sha256:aab2a25350d1d1489a09a77bc15555214e8e3a85fd4763d1858e482fcfccf07c_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-ansible-operator@sha256:e7cd527466d35b1f37b5f57e44e4bf5d03f7c8643ae8ce7aa5547844dc045688_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:9d119cc8ecd12028e5ad2c409ef3c86ac0c01fff82e757c750b3b8382330b41b_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:cbcc17acc38aa8f9b9efbbd8855a91c2afc30a82f5b661ce8fe3a3e56a1a9b37_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:5f6665a77e49df7b6d7b30d040d7fddb118d2677eaad5bc23e3ceccc02a1b8f8_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:6e6fbfa43e2892a7a9dc90984e9c8b0c364f5a0c46c8bc2e8fb8ef84763b10c5_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-cloud-event-proxy-rhel8@sha256:06169f0cd96f0468bced1f0f61478f6eee4e5fb628e782a981c236ed952edbae_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- +147 more not shown
✅ Remediation
For OpenShift Container Platform 4.9 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2022:6318
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100495
- externalhttps://issues.redhat.com/browse/OCPBUGS-831
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6318.json