RHSA-2021:0980MediumCVSS 7.5
Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.1.5 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
🎯 Affected products2
- Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.1/html/install/installing#upgrading-by-using-the-operator
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2021:0980
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/cve/CVE-2020-14040
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1853652
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1903446
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1920654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1925281
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1931887
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1932430
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0980.json