Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.3.3 security and bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-24788 — golang: net: malformed DNS message can cause infinite loop CVE-2024-24789 — golang: archive/zip: Incorrect handling of certain ZIP files CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
🎯 Affected products45
- 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:0bfabd1fcecfae735c416448e8a9dc8157167d52c9cce22e761bb74aaa416623_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:7529c769d2623c15ad5e32f33beab05a4e77f17da291970b439854b775136b64_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:b68efcaa3a07d5805c70bbc1eb9f4174bb7917dabeaebddd2209d625dadb4794_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:e9524e454c8698f49fe4d1bbe6f4aa5c9b68f0b04a912cd6e99125256712ba68_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:cc431d7fb365705dcecd67207ba27caed9c1012f384636d58d19e3e2ba3308fc_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:d427ec72eec6dc76d68df469b003a0017e975247a183629f699e1bc0dd3b1837_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:f09ed623ea3706ae57d99f95a9525d28123cd509fe71f66ba5c1d01a70252cb9_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:f0ac38b1ccb331ca40b8e5eef98fa3525bcd8e8589e6cbb48ee05bd6da3b4c87_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:275a38d0dde8d7e8198d6af284f88e82da92f7160c061453f5d9c43c24b8d9a6_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:6c08b61453ea32053cff09000e121cc82d3724aa32eed6e225531d77b073adae_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:aeb62050d36284627ad3d9b34f61bf90df5fc29464c72456c14e8446546b42fb_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:e8661e90c8358ef0176a71b8538bbe27902de63a607c37ce42a84f5025a800d1_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:32c9740721783d532a9a0213593de666ff35dabd021b0f6645b16d5c5f340e07_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:5a882e8435cd567d83ee79d331be7a11f8da78c5597381837f6d22d0a419a5bb_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:97c6ea39330004c24cbf1fd27a61eb0e562b9cc4c49d61b699e16f85cfe42f4e_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:9ef09f818c9e7ec15ce68059ab9110467c736a6ad0cf2a4f8c83537eb23d0e5c_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:5ea3c67336db1099c6a7949aeb7ee267e8c47bced9e1e298eac31cadf90eeaf3_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:bb450dc76d62307bce4ae29857cc41b24d03661e2b425e05b0dc2d22a77392cb_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:c58a76c073beb4d9a5fe875aa70ae0e35cf067d168af8537d7d82774e08edad6_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:dcc19c605fe06e26a57c30d994e38d71caf0f5fffd7d38836361410cade09f9f_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:451247c3f4ce3f087b7040f41d990f1f2096651dfe37f6ecdf7486b5768b614c_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:9a6c63e535890108d3380e0a828e8c7f6b5fc00366fab41598ed2ac2f095abd1_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:9ba1eebc2eccfcd920fe9a609f40c9b0bf63f7205aa91e4b72d69b18638582bb_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:e9283d12d5e6018e3bf3aa990b23591cc49367ab08f9ee6349610972ffa358d6_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:52faffab91250e8a8f84a94e6e118ba853b9054faaa2bb464ae2a6d3cd1ccfda_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:8f77ccd24b3ded8ebc6dcd7b8e1a9f97d425291f20f7a3e7be60b49e3fea569e_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:9a6130569de756dae1906fda639bf468ff1df0e1eb6f3590d0b5205fa3e55c69_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:dc96720cf67b85a48ebe47862bfa5c1c70cfd2f8781f9c263b28baa45e1bc23e_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:33b3fb333a87ce54377f1094b20de9e78e4af6f736cface819c041738041c5eb_ppc64le as a component of 9Base-OADP-1.3
- +15 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2024:4982
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292787
- externalhttps://issues.redhat.com/browse/OADP-4110
- externalhttps://issues.redhat.com/browse/OADP-4211
- externalhttps://issues.redhat.com/browse/OADP-4265
- externalhttps://issues.redhat.com/browse/OADP-4268
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4982.json