RHSA-2024:4119HighCVSS 8.1

Red Hat Security Advisory: Updated rhceph-5.3 container image and security update

Published
June 26, 2024
Last Modified
September 14, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace CVE-2023-29402 — golang: cmd/go: go command may generate unexpected code at build time when using cgo CVE-2023-29404 — golang: cmd/go: go command may execute arbitrary code at build time when using cgo CVE-2023-29405 — golang: cmd/cgo: Arbitrary code execution triggered by linker flags CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products16

  • Red Hat Ceph Storage 5.3 Tools
  • rhceph/keepalived-rhel8@sha256:74771c06933519c95c043bafae50579949f7665a08bae94067242cbe122f0b2a_s390x as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/keepalived-rhel8@sha256:9320d6cd86c4854c303c1ff8bd5e7ea9402d57bb99305d3fa71777f3626074a6_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/keepalived-rhel8@sha256:d7a7306a478ede068442d2e550afb25997d07e7789ee2f42d0de28ad658725cc_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-5-dashboard-rhel8@sha256:03783e8b39467222b6bd555e446571f969ba1107b61566e13fa4b9fef3a97430_s390x as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-5-dashboard-rhel8@sha256:9e85ebc6bd674665b674e3779bd70db825d8bae0ef73f063d49db1a7f923cdc5_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-5-dashboard-rhel8@sha256:cb8fc50eb4bb7609338a48bdca64daf4bb779a88a4a77c40f90a5d3ed7449c3d_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-5-rhel8@sha256:008a14ab26285daa57be78f805fa6c306afc1e32c272e6793872d885f4c279e6_s390x as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-5-rhel8@sha256:3c192d212d04f82ed2837eaa17d0273a5520a83d37992b75e0895b5b5de47f83_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-5-rhel8@sha256:b12193ed871c1a7a755d257d3a962116cb6b4d8acfc93898faef56c389189c05_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-haproxy-rhel8@sha256:087a07054c1126010e512d626ac177f4618f605e487e9a9c7d2e260f574bc9ad_s390x as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-haproxy-rhel8@sha256:ba0192053b43c5fc28b6273f25f3c4834ad37e4775d60662ea1279a1060b19f7_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/rhceph-haproxy-rhel8@sha256:eb29356658ad65b020dfcaaee169fef501afbcb0cf4612c143fc5ec38829c578_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/snmp-notifier-rhel8@sha256:1b5654619c4c25949563b561ba0b3a156b43c1d62a5ffa71524cdd0993add2e6_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/snmp-notifier-rhel8@sha256:d6a2c4fb376a48844ef8b8c0b1a05593eabce7c49c57fbc88a0c96ec172ff6fe_s390x as a component of Red Hat Ceph Storage 5.3 Tools
  • rhceph/snmp-notifier-rhel8@sha256:f4715ac64a43f3a654914f567c36e7179a3413b1c455be2e0dbe3d9bba89db70_amd64 as a component of Red Hat Ceph Storage 5.3 Tools

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (16)