RHSA-2023:5233MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Virtualization 4.13.4 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
🎯 Affected products93
- CNV 4.13 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:87bd65ea23d23fcea4176c13b14ea3341bdfb26ba494661404ab76eb1f7c9fea_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:ae40cb176edee7c31fb22a0f69db2b62483658a1ebd256cb21cc9c4ef88c3b2f_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:469a6831aa3c3262270e343674e0f9f4c0f5749957d30c50211ad07d185ee56e_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:dbcbe261728871e324205044905d07d063f45d61029735919d2db31513718012_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:3c78ccc9990f4c599d95b8a0b6100601898986e2cac17eb0ed448eab42690173_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:f07bf03c0afaf27b84a5d31458d152b5623cb0e9041110aa2900c1944bd799b3_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:729a18473b23041aba1bca997b0add89853b5050e34ed139552dd9a9dd9945cf_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:fbef3e3964432a5cb68dbdde80d44c0ae34a0be9b78c1f39226b4ec45b427d79_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:54197a68563a943f71f8183b9ea0793d91c5aae82a16618d6bcde732a7abace5_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:e507ac13769b706390e037493c58ab5036c31d6a1c3d8a349ae8afdec748399b_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:58ea23f9e0a0cd8d78ebe03fd6bd53e2abf526bbd9deab16f6ad8b859e5745e3_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:c700f760892417cc921a667dc1dc9135628f3ef172f7405891ab23725388c411_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:39bec2d49b7c52e654be0a6c25688e84f37bb3ef80f738fc388b70fcaa937256_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:f046ffe961c70b5d75b89de7da8300cf87253e9773fd3d5c0def82d28bc3a2f7_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:3bc71c074dcc815724e666ac98adf9c8be0dc25b4629ccb1a43fc8d6c18ad2f5_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:52b53a00bdfca53c9a19f5dfe64cd39af87b5841f0dcd7cba47367972060e400_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:663f64400079c641cf3e7fc0c7bb20dbbfe6530fe9375642009bc8aaea5fc1ed_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:808a766dcdf19f43548b757376ad7b11d5f853c4299a05027bdfbd16e629ca04_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:0426c7c961c929de2eb788c0722e54ebb83822f42ef5504bb84991ebef95ff2d_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:403982a55251168189828162a4647aa1b88e1024e290d9552b900d7b259f7aef_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:386ae49500da9e2115778121b7dc84266b8efc6032e3b5b8cc4d78f83912908c_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:586af2e3875ab9e1c802dee1ad7da6fb70a82e4182c2530ee3cbe01433b30957_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:0f474f9bed9c51f5b7fd59dbfc4ae4edf814d50f7b7ed2bc5c8faf58d012aeea_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:4bfc75011d41696cf2d68094f5437dfe3b4fcd9b315ff838aa3c2130e21484b7_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:0dfa34ec403176c7ec5f6b1d184c4e3a5555b98d722109845f4c9276a19b2c0c_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:f1e40135af9f4dd912517841cf08d0b8653d97ae9710ff75c3fb982c6dc7bcbf_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:0c98fa0fb3d0539b70c1a8c7687c2229c1d245664c67f469b9b7f231125b04fe_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:1cbcbaba9e36c5e097f0d62c7c0720b5fcf372d3730adec3c9c9b1d8d7daa998_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:6f3f6dee9346bfd1c0f56f73921c5804274539cb9d4dd79eb2ca7092796d97f9_amd64 as a component of CNV 4.13 for RHEL 9
- +63 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:5233
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232347
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5233.json