RHSA-2023:3204MediumCVSS 7.5

Red Hat Security Advisory: OpenShift Virtualization 4.13.0 RPMs security and bug fix update

Published
May 18, 2023
Last Modified
August 14, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-32149 — golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests

🎯 Affected products16

  • CNV 4.13 for RHEL 7
  • CNV 4.13 for RHEL 8
  • CNV 4.13 for RHEL 9
  • kubevirt-0:4.13.0-1469.el7.src as a component of CNV 4.13 for RHEL 7
  • kubevirt-0:4.13.0-1469.el8.src as a component of CNV 4.13 for RHEL 8
  • kubevirt-0:4.13.0-1469.el9.src as a component of CNV 4.13 for RHEL 9
  • kubevirt-virtctl-0:4.13.0-1469.el7.x86_64 as a component of CNV 4.13 for RHEL 7
  • kubevirt-virtctl-0:4.13.0-1469.el8.aarch64 as a component of CNV 4.13 for RHEL 8
  • kubevirt-virtctl-0:4.13.0-1469.el8.x86_64 as a component of CNV 4.13 for RHEL 8
  • kubevirt-virtctl-0:4.13.0-1469.el9.aarch64 as a component of CNV 4.13 for RHEL 9
  • kubevirt-virtctl-0:4.13.0-1469.el9.x86_64 as a component of CNV 4.13 for RHEL 9
  • kubevirt-virtctl-redistributable-0:4.13.0-1469.el7.x86_64 as a component of CNV 4.13 for RHEL 7
  • kubevirt-virtctl-redistributable-0:4.13.0-1469.el8.aarch64 as a component of CNV 4.13 for RHEL 8
  • kubevirt-virtctl-redistributable-0:4.13.0-1469.el8.x86_64 as a component of CNV 4.13 for RHEL 8
  • kubevirt-virtctl-redistributable-0:4.13.0-1469.el9.aarch64 as a component of CNV 4.13 for RHEL 9
  • kubevirt-virtctl-redistributable-0:4.13.0-1469.el9.x86_64 as a component of CNV 4.13 for RHEL 9

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)