Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

RedHat 8: RHSA-2022:6187-01 Important Update: Node Health Check Operator

red hat
Calendar Grey August 25, 2022
Dist Redhat Esm H88
The recent 0.3.1 security update for Node Health Check Operator on RHEL 8 bolsters system integrity by fixing severe vulnerabilities and enhancing logging and transmission security protocols
An update for node-healthcheck-operator-bundle-container and node-healthcheck-operator-container is now available for Node Healthcheck Operator 0.3 for RHEL 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, see:

https://access.redhat.com/articles/11258

Summary

This is an updated release of the Node Health Check Operator. You can use the Node Health Check Operator to deploy the Node Health Check controller. The controller identifies unhealthy nodes and uses the Self Node Remediation Operator to remediate the unhealthy nodes.
Security Fix(es):
* golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
* golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
* golang: crypto/elliptic: panic caused by oversized scalar (CVE-2022-28327)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, see the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2022-1705 https://access.redhat.com/security/cve/CVE-2022-28327 https://access.redhat.com/security/cve/CVE-2022-30631 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2022:6187-01
Product: RHWA
Issue date: 2022-08-25

Topic

An update for node-healthcheck-operator-bundle-container andnode-healthcheck-operator-container is now available for Node HealthcheckOperator 0.3 for RHEL 8. This Operator is delivered by Red Hat WorkloadAvailability.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2077689 - CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar

2107342 - CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read

2107374 - CVE-2022-1705 golang: net/http: improper sanitization of Transfer-Encoding header

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here