RHSA-2024:2060HighCVSS 7.5
Red Hat Security Advisory: OpenShift Virtualization 4.14.5 Images security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
🎯 Affected products89
- CNV 4.14 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:126f16e2903c77db72f3073e463fe3e33001cb393215b55afa56de94faad17c0_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:b195227def41999c24ce08545ad44b24e7b73e1f1cae449059771889021365e2_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:060d15b6a00a6f1ed5fd886467378d80ab232e4012ce33ffaa5843730b03be7e_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:eb70b77ceed22136afa7a2396414852d32adf029fa39781c0ffc27fddc18641f_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:1a1c15296c9dc8ded6915561aad06322ee3d7e0e3a553e5ed2cc1eda0ef6b736_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:d6316a5f0229d924fb2859a89074808979c8ed9dff7d6b71d4750c6aaff00d41_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:90bad38e33bfa1e04b5f39a26ec2c7a4f47f3c50321a8b13ac0c315e50478208_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:a9120cb7a5f374fafea5692a5093a201ee1eb414df9bedddad98f2117f1521a5_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:1134d3ce149f5b64bfca52a4e3d38a0b7864e6631b3edfc34c0592aa2ccb0b8e_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:ed605b46162edaa361bfecefdda6813ed8b67d400c7d1f8e623b88b692ec95db_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:5e975c3d0747bcf52cddb6ffbee781de728c57c60bdc4ecb2a929c5a3a53817b_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:d9a503464046f5357fb58d484c5ca4424a45b319417488f906ff892ee45dc491_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:914db4c900771b40b21c7a80993efbafa8b9d2b4002b46a58e8498f8c26ccb9c_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:bc1156fb8f028be1945e4cdb9f287a5a11d205a79fa2953dc6bfc255faf524f2_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:08928889fa993ed89aa05040b27ec560b7ba7f5d090a486390646bee8d16f977_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:c2dd6139eab4fe9cb0af485ed68a42890a883f58f5c81f5ce169dfcd54667663_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:4bf255ba25a7ca9c3b3dab9d2e3b105213a264dde08544c0a0d48e1e8e1bf286_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:936b3ace24072b9bf4f1c2008b236a92a3fe08c0749823e94daa5ffabbcd7848_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:3e62bb92d18561675c80d5e2f720153e1a82300edb6d37c4a824cbdd46fa8b83_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:bb00bd53da4c120e049b5e899b31aa935b749c9a0a449408578b18882c1f7990_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:d070efdb15fb0bfcb20f9e888cc28bc858a0088e6e9e969992480ddac1452bca_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:e2623a16266ec70cb3b4b4acf4f69bbe53f34d18ad53a37f40225940e0324589_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:6bcd09fad46e36de35550cb8213da1bd4b3e5e9274f8c6bc75583fdf0a656b63_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:acc13d82ab22b2c46f74ccc0c83e154ed46047ee3b9771bf7bf8f8f21eb1a145_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:33161895d85eb64e8b756d486c3083fbe6c32036421296c6234d4940971a6487_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:8fa75658260920f2210cec540d2635cf58fc5d5accad9e825541bee6e8a9a630_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:c87ea56b6e99e0ef34b2a8445aff7d7fdec5842f02a4c8001b4140a67111774a_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:d9fe342cb788df0201453b8650aa04a5e5d55b6a3940ebb6edd5b33ad1d2570b_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:3ebe33bac9e801ded32791295acc9596430bf4f4a55be1745fda4a137e02f5c6_amd64 as a component of CNV 4.14 for RHEL 9
- +59 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:2060
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://issues.redhat.com/browse/CNV-35848
- externalhttps://issues.redhat.com/browse/CNV-39957
- externalhttps://issues.redhat.com/browse/CNV-40266
- externalhttps://issues.redhat.com/browse/CNV-40279
- externalhttps://issues.redhat.com/browse/CNV-40627
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2060.json