RHSA-2023:2111MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.12.16 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents
🎯 Affected products175
- Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:2ae4c0066891dfea321aa379404fac4572586e73cad45d2d2310dea4fed76ed9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:3ab387903c971cce454c95555e4b8f919cbbb186f11449ddbd14c69c02b343d2_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:7522ae50bd90f498cff562b36496d88569957fede2876c97bdd08f28319b2748_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:bad432820cdd35919a0bca802c6b56feed630157f210523a90ef68680ac066d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:7f49415e3717c4f189697346f470345001b3c396cee6a0aea7fa8653e8257c65_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:805d1e17fdfa2737fddfcded66aad5407429b5ddbe78941ba6a4dcbf19559091_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:d3dc5bd5691614bb1f454aedcd7de7be4e11fdea6575252757c84154ab0dba51_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpu-network-rhel8-operator@sha256:1c5aa49107f3fac1042b80b6ba9574fd5e176507a3bcb0359fb37d58f85382b8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpu-network-rhel8-operator@sha256:952ad017a0a75fd61408ce2e7302c095bbaebb3763cceaf51371793239a09fcd_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:16d9a32f710dcbbe772905c1ac9fdff84f581bd30ffd43680db52ffe69768ed7_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:5a2bd52e3a4c77dd8e2c2992bd3f14d35bf8d094eebdd881e54af7d8da15f65b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:d10fb2abf0af6e18d0f4d5765fceb03208ba8238537ba717b02d3c1954cb2075_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:f2336cac24e8ceb3dbeaea2059b9b74e2185034c60bfe9256c8f3dc9467027c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:06af91381cb04a721bfea9b2766a257c300c73d450ccc8300f2f62a2989afb75_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:986f1b111b0ad5065102d5ec9ae685f0ef3ecc1717d7176a63f42d74d301d7b0_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:d4d916549a5cd2cdd59eab7341124405e74b276af0513b027fe9963d0b6a3bb5_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:f40795aa8861bb11704afd274017f246a6835e4d7b48a105e07b2fa65883a11f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:4b719a0534d77165d2988eca6b35fc778ec1a24601c32ae375cceb67b805492d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:62b0ff996f220fa3c2a64d7aea866b1bd0939c40ae061906b9ebbee5e84eb3e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:b43486778234c5bdfa05c82048fb1ac39d7f74b15c8ca92de9a4352d2a5e939c_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:d13a52f216289fc73a7380e42401f936e1a2b877a442be905b6377e95144a196_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:5055fdfac60f0306b750efc4cdf4e28a39ab32b48f3a7bcb20add2d3b9953bdc_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:87fb0ab6ce14134145937948edc330008133ac61570c34e6f71ba71ec3a3e006_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:c29e4ef61315d2fb8dcece0c2b0cc38e5813eea17acfa495b8e25e3fa50a4f67_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:d3df1665b7da8f3db7f0d67b470764b1c9a8bbfdef562a21f0f4409de7862731_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:1b7c97c7e851fd6e1584e316ce628915a9b31e09accbb1fcb27238162cc0e236_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:7cf259160572c26d436e9076cf524fc09be1ad188d7d493ac4b436cc2155e8bb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:90eff12b6bec2c031c464e97d8fb9f641839fca187ddb834dad890d182b60c95_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:f82602fcffa7c3b6fce73751751f7a7cfd6c1d38504ed664d9e576073af4c672_s390x as a component of Red Hat OpenShift Container Platform 4.12
- +145 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:2111
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html
- externalhttps://access.redhat.com/articles/11258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163037
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_2111.json