RHSA-2024:1923MediumCVSS 5.5
Red Hat Security Advisory: Migration Toolkit for Runtimes security, bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-1300 — io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support CVE-2024-26308 — commons-compress: OutOfMemoryError unpacking broken Pack200 file
🎯 Affected products16
- Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-operator-bundle@sha256:6818c3c795716c2cdb80050e705be0198aed6fef11d63fd28eeb8c21bf5fcb25_amd64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-operator-bundle@sha256:8f983034ba9454f79cc57f7a2d85dc50222638f576b454a1c8e9cd557665aaf3_arm64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-operator-bundle@sha256:d12e0dacb99d6efa4cce47fe89f27eb6ebb3c64308d5b742d81b55fced08f63b_s390x as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-operator-bundle@sha256:da17b288e5503ff99d747b07062368879799b661e4a7a6354c7162da7427ea7c_ppc64le as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-rhel8-operator@sha256:3f19f1908b9e44ecebebe2c2fcd30f17632f2807275da0b766aeff9f44b88152_arm64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-rhel8-operator@sha256:5e7df9c2c211b4a3230638efc87735fc702b01d42737eff48128150f02a6f204_ppc64le as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-rhel8-operator@sha256:92b03b5cccbdbf5394b4ea7a8521395d1b7fdcb1de4569dafe646f00c1c10d4c_s390x as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-rhel8-operator@sha256:a3d0772c5ebda63371edf4f53b78f053bd9035498304e9f2091a0b76c6c26153_amd64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-container-rhel8@sha256:6eb6177323899560f965b9b142335be8577bcd1330d86185545d25dfa97796ca_amd64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-container-rhel8@sha256:86c57b36f6224c54305f7833c1452b9d3fe276f09b295978f8e95bc258593599_ppc64le as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-container-rhel8@sha256:9052080bb46a5009e1497a198618b76311c6eefd386810da38d5d04ea05606c4_s390x as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-executor-container-rhel8@sha256:1b09f65401896e35e4ad5bc4979baafb0600f83630ee97173033195f030271db_s390x as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-executor-container-rhel8@sha256:b1076f9d028b653ff74926f09abb291395a0eb5d13c7e1522bc199fed9f68646_amd64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-executor-container-rhel8@sha256:b604d2e9dd393d52ba64cb39eec10cfab62d60a0b142df967de57734c87ff310_arm64 as a component of Migration Toolkit for Runtimes 1 on RHEL 8
- mtr/mtr-web-executor-container-rhel8@sha256:f9607ef871579e739205639e31d22aad24dd777f0ae0959e9cf3a064d3d27ead_ppc64le as a component of Migration Toolkit for Runtimes 1 on RHEL 8
✅ Remediation
Install the latest version of the Migration Toolkit for Runtimes from the Red Hat catalog in the OperatorHub page within your OpenShift instance. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available for this vulnerability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:1923
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2263139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264989
- externalhttps://issues.redhat.com/browse/WINDUPRULE-1043
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1923.json