Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

RedHat: RHSA-2021-2374-01 Moderate: Openshift Logging Bug Fix Release

red hat
Calendar Grey June 14, 2021
Dist Redhat Esm H88
OpenShift Monitoring Issue Resolution Update categorized as moderate, focusing on resolving defects and providing security impact insights as communicated by Red Hat Security.
Openshift Logging Bug Fix Release (5.0.5) This release includes a security update

Solution

For OpenShift Container Platform 4.7 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.7/html/release_notes/ocp-4-7-release-notes

For Red Hat OpenShift Logging 5.0, see the following instructions to apply this update:

pgrading.html

Summary

Openshift Logging Bug Fix Release (5.0.5)
Security Fix(es):
* gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation (CVE-2021-3121)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-3121 https://access.redhat.com/security/cve/CVE-2021-27219 https://access.redhat.com/security/updates/classification#moderate

Package List


Advisory ID: RHSA-2021:2374-01
Product: Red Hat OpenShift Enterprise
Issue date: 2021-06-14

Topic

Openshift Logging Bug Fix Release (5.0.5)This release includes a security update.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here