Red Hat Security Advisory: Service Telemetry Framework 1.5 security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-23772 — golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString CVE-2022-23773 — golang: cmd/go: misinterpretation of branch names can lead to incorrect access control CVE-2022-23806 — golang: crypto/elliptic: IsOnCurve returns true for invalid field elements CVE-2022-24675 — golang: encoding/pem: fix stack overflow in Decode CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar CVE-2022-29526 — golang: syscall: faccessat checks wrong group CVE-2022-30629 — golang: crypto/tls: session tickets lack random ticket_age_add CVE-2022-30630 — golang: io/fs: stack exhaustion in Glob CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-30632 — golang: path/filepath: stack exhaustion in Glob CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products8
- Service Telemetry Framework 1.5 for RHEL 8
- stf/prometheus-webhook-snmp-rhel8@sha256:a53c3dc5955a72913788a3eeda32f725b2f5ef6e893022cc358f20414eb5074f_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/service-telemetry-operator-bundle@sha256:617009676fbc385e222f144f79819b2cdcdafb28ae8674a53cdf8676f69d3717_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/service-telemetry-rhel8-operator@sha256:f71352691d5e680eb09a67ef2e7208a40a10a0b781b451150ced7408dfc603d0_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/sg-bridge-rhel8@sha256:d42174e8f6fbc91666ee2d78483f362f4de3f0ea551ea6d2bf310dadb1b5ba28_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/sg-core-rhel8@sha256:f3ac213d5ff7470ad8a9175fa699033c5c2ee7cd6cf5eb5f4e081de00e94cd37_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/smart-gateway-operator-bundle@sha256:08209b33986a186c90ec84140c833fdd892358583d3a7cb8c73f4732fe210546_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/smart-gateway-rhel8-operator@sha256:9ea6481e460623bd551f5facb1d8cee105103ad380a32cb3efcc0714b60db471_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
✅ Remediation
The Service Telemetry Framework container image provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References). Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2023:1529
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077688
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107371
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176537
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1529.json