RHSA-2023:1816MediumCVSS 5.3
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.12.2 Bug Fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products64
- RHODF 4.12 for RHEL 8
- odf4/cephcsi-rhel8@sha256:02a45a4526c44cd9723abb0e155a627cd0d7e827dc11e4679ddab1067cf82239_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/cephcsi-rhel8@sha256:26cd66e3c1b82d8466b45ad04821c15a570ecb4527f5b21e7b80e8c2addc7779_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/cephcsi-rhel8@sha256:ec31241541e2abd78bf8cf2a627c7c2372f613462f450f244b5652de4f84be75_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-core-rhel8@sha256:8e832ccabcce01c544a66a8f0dce82bf817fbb57b9c32f9d08fb6648615017a8_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-core-rhel8@sha256:b6259101dd506a40cf2ada869a74c6dfee70c962ef33059beb93a566fc6a7352_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-core-rhel8@sha256:f870f0e1c9101cc1235955958132cdccc4239a394a91b794f9c7d1076a831fc3_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-operator-bundle@sha256:ae25765423b3c26edbf244565fda9bb803f3f88806e5ad7351e7eea5249dab32_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-operator-bundle@sha256:b359aa18d0e121a5a8806c3bfcab145a432068d96023e1dfb6c0ff61729530ed_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-operator-bundle@sha256:c8d9b5a89e1855d531c36376b746dd04a7bdcce04b756a5e0575eb607cd4c5fb_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:571a9816824bd780addd14bdebdfa33d6e2dae774d2eaf3ce4598f77c5d2f46c_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:6e707cf70c75e3ffe056c741e8f8a743f9274c31136e1e6b0d54849f97f9e839_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:780f21748e8a2e93c825b73dfa339a10eb40ed118440ec1e6463f18be050660b_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:02aa79c70cdd7d6705901a0251ee034d6f99babffd6b53d284b2887977da56a2_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:0c16859624d28c4ead088206ffe90a931950846a3f468ffe4180384fafb2e914_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:6f263c6ff6c9eb52d5a74977705357422750016f0e20aa5b4f0a2758ae2bf714_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:d9869214ad82dbe0822c6d2fc6e68d3cc5f136eea360c6aa35ef80fc042e0e4f_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:e4a184006675f2b90d4d61dff86314567926a462221d719d4f49b5aa539fd4d7_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:f8bb8fc209169c07136bf564d008dc945022d91a2b9701a2c26a8c9e119e48ae_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-operator-bundle@sha256:1ceee23741fdbd8ea57c896394b7907a0d085747761aaff7499f9acd3da12c05_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-operator-bundle@sha256:5a7eb94cbe7c3c3beb5b0b578a594db5b21952a917b80d5d144fd131983136f6_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-operator-bundle@sha256:df37316320641fb32a777267be06ffcf40fac7c5e18347f9082b1ca16e64e6fb_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:aa296e043b81a7a56f50a030f145fc3ef29f5a5cd629b2e443ae4ebd4a579949_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:b79e124c25a496d6faf8cb4fc2b6c6cfc16168a375ab74d646aeb47b7d313432_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:f3febb8c575c0008630db316cd445ebfeb4cf22729109d29649e90835cf9864a_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/odf-console-rhel8@sha256:05ded1646a55559834a7b5b73efe4cc75eb5766dacbd13625ac762f6b653cd06_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/odf-console-rhel8@sha256:06fcb2723384a47645b02b1e5bf204ee164c237d5858d54dcdf824a3ed0dbb92_ppc64le as a component of RHODF 4.12 for RHEL 8
- odf4/odf-console-rhel8@sha256:9f618cd8acce0a97eb6da2bd07a198a5ea6dde4f89aed5d3db690e693b934e7b_amd64 as a component of RHODF 4.12 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:a03151222a299e9994de4e490169f326fe97b770966e37107d6615e4f8e5ed54_s390x as a component of RHODF 4.12 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:c749a20a95dd9a2d494c6850269da4c785a991f7f8315f284eb40a009012fad8_amd64 as a component of RHODF 4.12 for RHEL 8
- +34 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:1816
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2171968
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174335
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179978
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186455
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1816.json