RHSA-2022:6517HighCVSS 7.5
Red Hat Security Advisory: Release of containers for OSP 16.2.z director operator tech preview
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-41103 — containerd: insufficiently restricted permissions on container root and plugin directories CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read
🎯 Affected products3
- Red Hat OpenStack Platform 16.2
- rhosp-rhel8-tech-preview/osp-director-operator-bundle@sha256:58abd2a556d744489724497ede17fe15bdcf8bfbe526a58754c431e7ace7e7a2_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8-tech-preview/osp-director-operator@sha256:f60730cb02cea67835ba63c86e0c0d159714a1e6fdc12364680ea59fb816f7bd_amd64 as a component of Red Hat OpenStack Platform 16.2
✅ Remediation
OSP 16.2.z Release - OSP Director Operator Containers
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2022:6517
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011007
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107342
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6517.json