Red Hat Security Advisory: OpenShift Virtualization 4.13.3 Images security and bug fix update
🔗 CVE IDs covered (9)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24536 — golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption CVE-2023-24537 — golang: go/parser: Infinite loop in parsing CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes
🎯 Affected products93
- CNV 4.13 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:0442bd3f6db788d815b39b4d4cd17eaeeda70faa07490421d1beb902ecbe8ea3_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:ff4c5f7d59fa938de6dd7394bc38c69ec142d90438232f242b35e77019d56d6b_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:65fd54535f9a912e84dc5137af6e889667c80064ee20ec0766d4ddbc44cd6842_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:a32c2591cd58f8fcdf75ffd6ca48438f98fe94ede1183fa9dfcb93eb246c4f9c_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:4f24428f6dec14f2fb6d0b023287f9acbe3f9266f677c53597996c68ac8fdea6_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:e0a2cf76b8762da61a9deda21ba99932104f53015f9976589cbc0ca0181b99c8_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:2840bb1ac72f1c3c1c829d8b4fc93d9b52a6ecfc2d9d5a6b6a3000e19a66993f_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:f2129875afb6ffb7d93ebf82982e2efb43bcbcdcb5bbea7ff13a487d1a226b0a_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:821913dc264e2779f0e7cb1fafc429463a64efe0f895d84ec1850937ac76c403_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:88eba23cc5acb861ddf0e975c6816a625a64f59d2db3cf9b41887fd9ebf77745_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:3a784f08efac5ec95080c8770a47768a4675beda2b15e4d971fe3a008a092dbe_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:fefd519fd61681629fc129bce217f8368ff61e9e2fa9787d9acfd178e9f751a5_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:42ca962f2fbb886038ce13440a55b55bbf1bb4e7b366fc0c6f043b3e67e5eebc_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:f517928ec380bbeb458987d56cfd71330f80f9a169c034f5fd852f3ad7c5f32e_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:7cd5e47a0a329c7b0dfbe6c50038adfe8f1db2a9c172b7a059d1b3ff1e009ca3_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:a3568cb89ac549ba53f4a01e8d23f821552bb794a2d4207e8b2f128b67290d57_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:129d3a66fea22d6c440baf10c072caeba209fbee903d8e5b1cae784f717ed41a_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:b6c863388340225a360d99c14fcd439b15bff4d173e6c79113a80fcf8e455564_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:1330e0a02b02934d52b2f9259796707d21955c200bdb5685a59020352d25966e_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:5f84aab0389c6a85c4ec58e230fea3694e3c800185f7ec1a090ccdce0c214d79_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:6184c3cfc8d282bd5a5c468fff7c8f726149b4010cdd5c8998f2f6b2d4f055c3_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:844d7d03c78e5ced5433a23beb81dbb9ef87be848964106252b8d7c23c4dcedb_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:318e10da8c6ead3b4e96fa78074179635297f6bcf4a1e5723896253d0123b28a_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:f8d3bab9e69a933e01d9b8758518a19d8c1c1f8fd64909a8ffc683159030895a_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:53d1b582811f62d1214425ef1997687886a08c47779bb61d009b46ece0d45139_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:cb09c73e12893427f6c723f529ea1e70a1bf90ac9f0780b5e1451f6d8ecfa3f7_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:0c8b9c4b62527d0452d76bab0a61c9d12d1c89791e8c9b63dc145a36b4f5d729_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:2287502d96bdf12b59d9f308242ef49da04792afb66d893927c6acf832ae581c_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:ddb6d5ddcc573fcf8d7d1aae5544cfaef9baa2438eaeb55715ec585c1a029356_arm64 as a component of CNV 4.13 for RHEL 9
- +63 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, upgrade Go to version 1.19.8, 1.20.3, or later, where the vulnerability has been addressed. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (42)
- selfhttps://access.redhat.com/errata/RHSA-2023:4664
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2054863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064160
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2130604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156525
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2172544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175651
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177977
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180666
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180719
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181999
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183915
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187509
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188144
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2190171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2203727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2220844
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2229148
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4664.json