Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat 2.5 RHSA-2023:0481-01 Moderate: Submariner Security Fix

red hat
Calendar Grey January 26, 2023
Dist Redhat Esm H88
Submariner 0.12.4 security patch resolves moderate risk vulnerabilities and errors for Red Hat ACM 2.6. Discover more details.
Submariner 0.12.3 packages that fix various bugs and add various enhancements that are now available for Red Hat Advanced Cluster Management for Kubernetes version 2.5

Solution

For details on how to install Submariner, refer to:

https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.5/html/add-ons/add-ons-overview#submariner-deploy-console

and

https://submariner.io/getting-started/

Summary

Submariner enables direct networking between pods and services on different Kubernetes clusters that are either on-premises or in the cloud.
For more information about Submariner, see the Submariner open source community website at: https://submariner.io/.
This advisory contains bug fixes and enhancements to the Submariner container images.
Major bug addressed:
ACM-2318: Submariner gateway node: Error updating load balancer with new hosts map
Security fix:
* CVE-2022-32149 golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags

References

https://access.redhat.com/security/cve/CVE-2022-32149 https://access.redhat.com/security/updates/classification#moderate

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:0481-01
Product: Red Hat ACM
Issue date: 2023-01-26

Topic

Submariner 0.12.3 packages that fix various bugs and add variousenhancements that are now available for Red Hat Advanced Cluster Managementfor Kubernetes version 2.5.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2134010 - CVE-2022-32149 golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

ACM-2318 - Submariner gateway node: Error updating load balancer with new hosts map

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here