RHSA-2023:4421HighCVSS 8.1

Red Hat Security Advisory: OpenShift Virtualization 4.12.5 security and bug fix update

Published
August 1, 2023
Last Modified
September 19, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace

🎯 Affected products44

  • CNV 4.12 for RHEL 8
  • container-native-virtualization/bridge-marker@sha256:a02ee77372f00b27846a0c6deffac66e0668d7813e5f098e59ff3c5f78537ef3_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/cluster-network-addons-operator@sha256:1f751fc283f4eb594dd24460b90940e3d6e1a0f8e8bbb4ea15b0256fc848583d_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/cnv-containernetworking-plugins@sha256:66cc9726f789717c9951f2791aefd51f500fad5eb0c6a23d08e9b2bab1f18b8a_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/cnv-must-gather-rhel8@sha256:34f9bf00d59822c9412082e3f2ba68ea1eeae77f150b543a3708b4510c6c675e_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/hco-bundle-registry@sha256:fdbd8e15ed4c3893bec71866c5bf37caca1e4cb9c021c77e72b48d28a7357215_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/hostpath-csi-driver@sha256:1f9d10182a5ba15b921eb09acbbd55646fbe3f40ac134f43d282be6416acabe5_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:f082d07f0cf9f8163118975603febe0979c112891008a4b74c9d66a4ef2d84a4_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/hostpath-provisioner-rhel8@sha256:83874adef85863588975c65ef95aa75ef8a7af1cceab9055c619d50d4da26652_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/hyperconverged-cluster-operator@sha256:9216dcd92910ff2ff80400a821ece03d1afefa94d0a654ad6d9fcb74ea16f51a_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:9709ecd32bd81bf4c19d1ad69cbfde7c9777b7eed3b3f02ef992a9320f195d04_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubemacpool@sha256:095bcfb80af438568a4d2c393d2ab92b0e6f6df782b05255668cc74078dcf7cb_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-console-plugin@sha256:dd5fd3ae594c809bbafd1bac216a66181c1df830a437aae67754e8e31b628759_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-ssp-operator@sha256:3abb2f27ec40057c57fa5033e85d4526980ece6f9da4482e0c48bd6c6a9fa5f4_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:38168a4e9f3fda1822f53bb0043672dc5aada1668308c326f98de89a51c68ef9_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:b81ca97734c4a3a46805d95e88346c0d54e5e89e3638de80bc6b89cfd847b0fe_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:51ae5c8256adccda6e0cb8bbdcd540f3d8d613c42382c31dfdf7782665344ea6_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:21a3d11e32961f3aabec9b3fdb25e57d3f003967fef75b705d59a3a0bce3d98b_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:e0478361a5a04266317228b67920af7f15b4870bc34bd79f30e47935979a3e02_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:c777f0013dc0e370278889c6ac304a39bcd2c2787defd8f4b1b39266a7ab4457_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:cd460395a513a6046bc42985d41019f552cbce7d6c74fef5ee0118b63ba06de5_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:7eab7f2b7b31bf439756d43c5c5e684a2e7b4a115b07a53bb9e12276b69f1efe_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:8a7c02ab82cc707403382ea9f5a777822809a52e5f1b70fb7a896c005c955acc_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/kubevirt-template-validator@sha256:b249b2ca3363fc76e8b7e7f2f76bf2bad971312e4b126aa951a4efbf551f4e6a_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/libguestfs-tools@sha256:0951a7b40987bd4f3b0069cecb699b9f22eaee89bfacf268b3fff5fd806b76bc_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/ovs-cni-marker@sha256:48da54894b425c570bcb171cb68469f8d3819a341f147eb788606bd92b7fab3d_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/ovs-cni-plugin@sha256:9ba33511da257af1e061d53f58355fdc6a320bf82e9eb28f7b04b92a03da7d89_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/virt-api@sha256:0aa7e3348376ce3906bc2262f1e6d33ab9ba854b00bc1bdad71aedba08d86294_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/virt-artifacts-server@sha256:40c36b29faee798fe21a86219f07126062759659be634a205fb29f81e78a65a9_amd64 as a component of CNV 4.12 for RHEL 8
  • container-native-virtualization/virt-cdi-apiserver@sha256:5c93c9c7395fcc7c3abed1cfbd52a8cd3d8b062dcca5e99e1d54c18fea3dcda7_amd64 as a component of CNV 4.12 for RHEL 8
  • +14 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (18)