Red Hat Security Advisory: Red Hat Ceph Storage 7.1 container image security, and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2024-22195 — jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
🎯 Affected products23
- Red Hat Ceph Storage 7.1 Tools
- rhceph/ceph-nvmeof-cli-rhel9@sha256:8f81cd8b292f9556bd070ce7544b3da902b76c818b3f63b2f92da2f9b85577b4_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/ceph-nvmeof-cli-rhel9@sha256:931e21e519fd5d983313d1f36f8c0585c07e80a6fc9396880fa395c11eb6e3e6_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/ceph-nvmeof-rhel9@sha256:06cfbdb4b4b25598a351dfecbfeabd9db546c3d0092fd9ea1f04ed18fb8faed6_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/ceph-nvmeof-rhel9@sha256:345c8760bbbe70b3b992b97ac40d6160e9c55634931a397bb226764ac9dfcb6a_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/grafana-rhel9@sha256:1b8dda6cf9a50a601f51bc7d98b98948998e0abd86e98bad622144c52f50843b_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/grafana-rhel9@sha256:22e29ab0738ce353ca48d3f938cbee0277592dcdfd0644201c30616f2369dd32_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/grafana-rhel9@sha256:bca988c20c1cc1f0ceb98e44907089ed7e21188c9e928130d32d201ca8f06b37_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/keepalived-rhel9@sha256:176a386fc3bd29a56039c6eb70ef1f504190b633e533b41a52953160f82feb30_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/keepalived-rhel9@sha256:17bbf30b0bf19f3120f0732f1818c55266a5beb1bd36a7d67da1a3fd2bbc8886_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/keepalived-rhel9@sha256:7733dd9a62992c5fa63a1e19aa6cc148448482bfb9dcfc80d1cd12c971b487db_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-7-rhel9@sha256:3d75ca419b9ef00cf2c944680737e84e6e1059e0f33156bc21d4dbf76a7da5b1_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-7-rhel9@sha256:461ebba0a5b67ae0f95e8a6160de6e68bfdd868bb747df3f77f722ba25edc10e_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-7-rhel9@sha256:dec6015491862315e776ca9397bd0a13b10657e00ed8390367477f1231509ea3_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:224a49c01a8e016c744d12415e5592eb4872b23ce509ecacf4f20c9b836ca35d_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:6600b6e96f3126775ab5faa5c177a1c18b14afd20f1b7ab553faec837271e50e_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:cedce5376ab17fd5bbb274009cbd94d4c558ef0d548f86a6ef479d9d25a63c6f_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:24576483bf4bf367e5556d93f4fd2bf0774a05fe5be6f81edeee9c71354e3647_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:405b6e55259c0f8eaca8034f1369cf388e19ba0ec3da3eaea52d23aab7034de1_s390x as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:eadeedfaa124d2ae3cdd5e42180aa17296c555bd231ddd37c89955dd51ff8e39_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:be6f908a081fcefb3e6925ee2d416ba0abf6f488b7297d18a69af95250386f3f_ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:ce91a88201bba1e5f6058ff2c58eecfce3fd06f5fb55c2042708248b69425cf5_amd64 as a component of Red Hat Ceph Storage 7.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:fbee3bd0c1c84c25d8508e8c68f8ad933457dcd2263c118c3da2554002f48a49_s390x as a component of Red Hat Ceph Storage 7.1 Tools
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/7 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:3927
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/cve/CVE-2023-39325
- externalhttps://access.redhat.com/security/cve/CVE-2024-22195
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268114
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3927.json