Red Hat Security Advisory: Red Hat OpenShift Distributed Tracing 2.8.0 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products43
- Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-agent-rhel8@sha256:8a43f264074ee58981c8a80becceb4fca6488a641882b56ac19c11b19a8107e2_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-agent-rhel8@sha256:b689645b06be8513d1960c4431ada2f7615d72cdc5df43adac38bd161b266a25_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-agent-rhel8@sha256:c328aa56ba47b44064ef4bdb049078845fcd69604ce4a999817804781a5f0149_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-all-in-one-rhel8@sha256:0b20755ee5537736b1fe1371bd0052a48cafe921c49019bb9b370ec2973fa08d_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-all-in-one-rhel8@sha256:251e1a11abbb91bf0316c27242cc5f965f276dfecb388c19f9dfd93bc894622b_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-all-in-one-rhel8@sha256:e4bb5f4ec8077fd88d504bbdf9dc776011ec4bb459a6f8716c26ab0e62cbf70e_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-collector-rhel8@sha256:1bd71465d819d4698e6f22f22c2b85b582602197aa7ce200ed8359cc5eb5651c_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-collector-rhel8@sha256:b8f0ecc3f3f5e6ef95795b5d6e4c1101ac262798bc7f98d88a4d72c9bb8df2de_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-collector-rhel8@sha256:ff04f6b0953c885bac0b58c0373eef52cc667901df03ecf40568c30132d46f31_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-es-index-cleaner-rhel8@sha256:1ad7cb4a53bba1ce64294865f2ea98bea7e12abc8b2ce3fb929b4ac6c7a9e534_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-es-index-cleaner-rhel8@sha256:2faac03b2c880856c059d1eba1ec41d464115a2ad26fa1fac53de5aebcae91e5_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-es-index-cleaner-rhel8@sha256:98fe80fbd583a0f52d96045196806fdc4564ec3dd6baf06ab5d2e69bd4e78c3b_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-es-rollover-rhel8@sha256:0bfe941f7a7af8f9d7aebeb7705837c3aa5858f6b282c511659d82bb71b466b1_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-es-rollover-rhel8@sha256:75b3492d01d93b5f14dd8b8cae913f4c9a379cde9738b16b653f17065f461004_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-es-rollover-rhel8@sha256:8936533e85752a84a10dde80dd637bd362af950a5b71b4d89929e704cc22cbd2_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-ingester-rhel8@sha256:1374bd615cd61d87b6d2a0fe2a41d40cfb6ff88cd652bcb1cdeedea7bc222394_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-ingester-rhel8@sha256:496ff69d2598e54e2ca83e6c2ea10d471ad152711423932b28c70dc7265a99e8_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-ingester-rhel8@sha256:8713a0e37285d6e5c7133221c07dcf4012d832bd47bf6657829fbfa4add1d049_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-query-rhel8@sha256:0fb36c45aeaf6ce09946a3bc90637a1d9a118f3d86c950105a916263de49501e_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-query-rhel8@sha256:104db728c93ca8fd7a3abd8889e6a0d1ec4db34ea6e2d4350dba029651adeb17_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-query-rhel8@sha256:c6cb58f3440abb96c0ad5d3837131836cd8cd0b0e30582bf6fecdd2ec7f23fb5_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-rhel8-operator@sha256:21ba897b333be9d40a02d4ea2c89af013331b3c06fbb86c5a9759f61039086f9_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-rhel8-operator@sha256:45aa2c351ee0e9cc8bbcb2cdedd6e673f3196464529a44be6ec74cc150eb6751_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/jaeger-rhel8-operator@sha256:69b565bd59f81777c857981508eaa4a177a8d1a0ffb96507758cde425681e36e_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/opentelemetry-collector-rhel8@sha256:00416535e7d8201734bf0f7d7f3279c064eb1311b8d64b89784622a05bc65244_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/opentelemetry-collector-rhel8@sha256:b7873e3eb7d40a27c638644474e04ddc364b77ec1ad1399e35da38fce22fc0b6_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/opentelemetry-collector-rhel8@sha256:db9c1a9684e33ddb8f4967f6d2ecd5c2969d1fd358ee9f7de2d991d2e6653936_ppc64le as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/opentelemetry-rhel8-operator@sha256:2d81f81659c6d9f4aa3ebeacf60f13ccd3365772114ab5df9bc099f7ea2ec033_amd64 as a component of Red Hat OpenShift distributed tracing 2.8
- rhosdt/opentelemetry-rhel8-operator@sha256:8e34697b56eae5a94f96d20195aeb9310c42b8ab608e1afdab2f680d2fc391ad_s390x as a component of Red Hat OpenShift distributed tracing 2.8
- +13 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:2728
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/containers
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_2728.json