-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Cryostat security update Advisory ID: RHSA-2022:0163-01 Product: Cryostat Advisory URL: https://access.redhat.com/errata/RHSA-2022:0163 Issue date: 2022-01-18 CVE Names: CVE-2021-3712 CVE-2021-44716 ==================================================================== 1. Summary: Updated RHEL-8 based Cryostat container images are now available Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: The RHEL-8 based Cryostat container images have been updated with a security fix for "CVE-2021-44716 golang: net/http: limit growth of header canonicalization cache". Users of RHEL-8 based Cryostat container images are advised to upgrade to these updated images, which contain backported patches to correct this security issue. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory in Red Hat Ecosystem Catalog (see References). 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2030801 - CVE-2021-44716 golang: net/http: limit growth of header canonicalization cache 5. References: https://access.redhat.com/security/cve/CVE-2021-3712 https://access.redhat.com/security/cve/CVE-2021-44716 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYecDGNzjgjWX9erEAQg0VBAAogeHhFtvwdPznsOhcnH+UrrLoB1DU/jh 2HR1Wzol7oV6CavpnBNLx39ZLrjINxSu0OqtbpcS/9p5aelhfOuyRBROQVK9XAt1 n3zwqoeTsonEOK8UcAD6tIJBwuFRzm6sJOVyTmn0W3BDrndjX2r0F2YcT76tY3W+ vjmMr92aM4D71RzEjvXkTfbEXujPRdh62tO4O6yMv/i2S1L/T4qJOigZm/cwGuNd c+S0mWlhZj9sFkD7rqIZxLokm6piSnyaaT/5JdQzG4cEyAzoHWZILZvQ7IBdnhly Qk4C8zcqj65wvqJlP8eybQ5PZAb1mbWgAg4sR4f2l2oGJ0BWHANIRUTslwWian0K N4E+j9YA868gCBCvZUO2P3UYDIDQCLDaB3ARtTpZZOlZmIdv+tvODb7Wdyr9O8+l Rgd5v8XlrDf7jtwuu3wS1XrfAkNY3WaihMSImRwgq2IW6q1qmCsFdNJXblkdsk1Q xYfisXFagwHnMZq1iD+OZPXN/QuMDSYAZlWzpNB5fOC2wU7LSJzwtnQWEeuy99Rh ELQbkvpbHFVObYFHxVTJrMPU3X4TIv+8IJ5tFwwK9NgZZw2hYsIPUIU7El6061J1 +2ofyRvMGJCmh1VAiBvDmPLerLdpvyR/nLCRtveLWT58hv9knFBONerOnKy+MTgo YEArJdLHT4I=5Egn -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce