Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7236-1 January 28, 2025 linux, linux-azure, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-hwe-6.8, linux-ibm, linux-lowlatency, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oracle, linux-oracle-6.8, linux-raspi vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-lowlatency: Linux low latency kernel - linux-nvidia: Linux kernel for NVIDIA systems - linux-nvidia-lowlatency: Linux low latency kernel for NVIDIA systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-gcp-6.8: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-6.8: Linux hardware enablement (HWE) kernel - linux-nvidia-6.8: Linux kernel for NVIDIA systems - linux-oracle-6.8: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Netfilter; - Network traffic control; - VMware vSockets driver; (CVE-2024-53164, CVE-2024-53103, CVE-2024-53141) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1004-gkeop 6.8.0-1004.6 linux-image-6.8.0-1017-gke 6.8.0-1017.21 linux-image-6.8.0-1018-raspi 6.8.0-1018.20 linux-image-6.8.0-1019-ibm 6.8.0-1019.19 linux-image-6.8.0-1019-oracle 6.8.0-1019.20 linux-image-6.8.0-1019-oracle-64k 6.8.0-1019.20 linux-image-6.8.0-1021-azure 6.8.0-1021.25 linux-image-6.8.0-1021-azure-fde 6.8.0-1021.25 linux-image-6.8.0-1021-gcp 6.8.0-1021.23 linux-image-6.8.0-1021-nvidia 6.8.0-1021.23 linux-image-6.8.0-1021-nvidia-64k 6.8.0-1021.23 linux-image-6.8.0-1021-nvidia-lowlatency 6.8.0-1021.23.1 linux-image-6.8.0-1021-nvidia-lowlatency-64k 6.8.0-1021.23.1 linux-image-6.8.0-52-generic 6.8.0-52.53 linux-image-6.8.0-52-generic-64k 6.8.0-52.53 linux-image-6.8.0-52-lowlatency 6.8.0-52.53.1 linux-image-6.8.0-52-lowlatency-64k 6.8.0-52.53.1 linux-image-azure 6.8.0-1021.25 linux-image-azure-fde 6.8.0-1021.25 linux-image-gcp 6.8.0-1021.23 linux-image-generic 6.8.0-52.53 linux-image-generic-64k 6.8.0-52.53 linux-image-generic-64k-hwe-24.04 6.8.0-52.53 linux-image-generic-hwe-24.04 6.8.0-52.53 linux-image-generic-lpae 6.8.0-52.53 linux-image-gke 6.8.0-1017.21 linux-image-gkeop 6.8.0-1004.6 linux-image-gkeop-6.8 6.8.0-1004.6 linux-image-ibm 6.8.0-1019.19 linux-image-ibm-classic 6.8.0-1019.19 linux-image-ibm-lts-24.04 6.8.0-1019.19 linux-image-kvm 6.8.0-52.53 linux-image-lowlatency 6.8.0-52.53.1 linux-image-lowlatency-64k 6.8.0-52.53.1 linux-image-lowlatency-64k-hwe-24.04 6.8.0-52.53.1 linux-image-lowlatency-hwe-24.04 6.8.0-52.53.1 linux-image-nvidia 6.8.0-1021.23 linux-image-nvidia-64k 6.8.0-1021.23 linux-image-nvidia-lowlatency 6.8.0-1021.23.1 linux-image-nvidia-lowlatency-64k 6.8.0-1021.23.1 linux-image-oracle 6.8.0-1019.20 linux-image-oracle-64k 6.8.0-1019.20 linux-image-raspi 6.8.0-1018.20 linux-image-virtual 6.8.0-52.53 linux-image-virtual-hwe-24.04 6.8.0-52.53 Ubuntu 22.04 LTS linux-image-6.8.0-1019-oracle 6.8.0-1019.20~22.04.1 linux-image-6.8.0-1019-oracle-64k 6.8.0-1019.20~22.04.1 linux-image-6.8.0-1021-gcp 6.8.0-1021.23~22.04.1 linux-image-6.8.0-1021-nvidia 6.8.0-1021.23~22.04.1 linux-image-6.8.0-1021-nvidia-64k 6.8.0-1021.23~22.04.1 linux-image-6.8.0-52-generic 6.8.0-52.53~22.04.1 linux-image-6.8.0-52-generic-64k 6.8.0-52.53~22.04.1 linux-image-gcp 6.8.0-1021.23~22.04.1 linux-image-generic-64k-hwe-22.04 6.8.0-52.53~22.04.1 linux-image-generic-hwe-22.04 6.8.0-52.53~22.04.1 linux-image-nvidia-6.8 6.8.0-1021.23~22.04.1 linux-image-nvidia-64k-6.8 6.8.0-1021.23~22.04.1 linux-image-nvidia-64k-hwe-22.04 6.8.0-1021.23~22.04.1 linux-image-nvidia-hwe-22.04 6.8.0-1021.23~22.04.1 linux-image-oem-22.04 6.8.0-52.53~22.04.1 linux-image-oem-22.04a 6.8.0-52.53~22.04.1 linux-image-oem-22.04b 6.8.0-52.53~22.04.1 linux-image-oem-22.04c 6.8.0-52.53~22.04.1 linux-image-oem-22.04d 6.8.0-52.53~22.04.1 linux-image-oracle 6.8.0-1019.20~22.04.1 linux-image-oracle-64k 6.8.0-1019.20~22.04.1 linux-image-oracle-edge 6.8.0-1019.20~22.04.1 linux-image-virtual-hwe-22.04 6.8.0-52.53~22.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc),a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7236-1 CVE-2024-53103, CVE-2024-53141, CVE-2024-53164 Package Information: https://launchpad.net/ubuntu/+source/linux/6.8.0-52.53 https://launchpad.net/ubuntu/+source/linux-azure/6.8.0-1021.25 https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1021.23 https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1017.21 https://launchpad.net/ubuntu/+source/linux-gkeop/6.8.0-1004.6 https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1019.19 https://launchpad.net/ubuntu/+source/linux-lowlatency/6.8.0-52.53.1 https://launchpad.net/ubuntu/+source/linux-nvidia/6.8.0-1021.23 https://launchpad.net/ubuntu/+source/linux-nvidia-lowlatency/6.8.0-1021.23.1 https://launchpad.net/ubuntu/+source/linux-oracle/6.8.0-1019.20 https://launchpad.net/ubuntu/+source/linux-raspi/6.8.0-1018.20 https://launchpad.net/ubuntu/+source/linux-gcp-6.8/6.8.0-1021.23~22.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-6.8/6.8.0-52.53~22.04.1 https://launchpad.net/ubuntu/+source/linux-nvidia-6.8/6.8.0-1021.23~22.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-6.8/6.8.0-1019.20~22.04.1 . Multiple vulnerabilities have been addressed in the Linux kernel for Ubuntu systems. Quick update is advised.. Ubuntu Kernel Security, Linux Kernel Update, Security Advisory, Ubuntu Security Fixes. . Severity: Important. LinuxSecurity.com Team
Moderate: kernel security update. {"type":"TYPE_SECURITY","shortCode":"RX","name":"RXSA-2024:6567","synopsis":"Moderate: kernel security update","severity":"SEVERITY_MODERATE","topic":"An update is available for kernel.\nThis update affects Rocky Linux SIG Cloud 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)\n\n* kernel: nfsd: fix RELEASE_LOCKOWNER (CVE-2024-26629)\n\n* kernel: mm: cachestat: fix folio read-after-free in cache walk (CVE-2024-26630)\n\n* kernel: mm\/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (CVE-2024-26720)\n\n* kernel: Bluetooth: af_bluetooth: Fix deadlock (CVE-2024-26886)\n\n* kernel: kprobes\/x86: Use copy_from_kernel_nofault() to read from unsafe address (CVE-2024-26946)\n\n* kernel: KVM: SVM: Flush pages under kvm-> lock to fix UAF in svm_register_enc_region() (CVE-2024-35791)\n\n* kernel: mm: cachestat: fix two shmem bugs (CVE-2024-35797)\n\n* kernel: x86\/coco: Require seeding RNG with RDRAND on CoCo systems (CVE-2024-35875)\n\n* kernel: mm\/hugetlb: fix missing hugetlb_lock for resv uncharge (CVE-2024-36000)\n\n* kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area (CVE-2023-52801)\n\n* kernel: net: fix out-of-bounds access in ops_init (CVE-2024-36883)\n\n* kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() (CVE-2024-36019)\n\n* kernel: usb-storage: alauda: Check whether the media is initialized (CVE-2024-38619)\n\n* kernel: net: bridge: mst: fix vlan use-after-free (CVE-2024-36979)\n\n* kernel: scsi: qedf: Ensure the copied buf is NUL terminated (CVE-2024-38559)\n\n* kernel: xhci: Handle TD clearing for multiple streams case (CVE-2024-40927)\n\n* kernel: cxl\/region: Fix memregion leaks indevm_cxl_add_region() (CVE-2024-40936)\n\n* kernel: net\/sched: Fix UAF when resolving a clash (CVE-2024-41040)\n\n* kernel: ppp: reject claimed-as-LCP but actually malformed packets (CVE-2024-41044)\n\n* kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() (CVE-2024-41055)\n\n* kernel: PCI\/MSI: Fix UAF in msi_capability_init (CVE-2024-41096)\n\n* kernel: xdp: Remove WARN() from __xdp_reg_mem_model() (CVE-2024-42082)\n\n* kernel: x86: stop playing stack games in profile_pc() (CVE-2024-42096)\n\n* kernel: Revert "mm\/writeback: fix possible divide-by-zero in wb_dirty_limits(), again" (CVE-2024-42102)\n\n* kernel: mm: avoid overflows in dirty throttling logic (CVE-2024-42131)\n\n* kernel: nvme: avoid double free special payload (CVE-2024-41073)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux SIG Cloud 9"],"fixes":[{"ticket":"2265797","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2265797","description":""},{"ticket":"2269434","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2269434","description":""},{"ticket":"2269436","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2269436","description":""},{"ticket":"2273141","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2273141","description":""},{"ticket":"2275678","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2275678","description":""},{"ticket":"2278206","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2278206","description":""},{"ticket":"2281052","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281052","description":""},{"ticket":"2281151","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281151","description":""},{"ticket":"2281727","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281727","description":""},{"ticket":"2281968","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281968","description":""},{"ticket":"2282709","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2282709","description":""},{"ticket":"2284271","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2284271","description":""},{"ticket":"2284402","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2284402","description":""},{"ticket":"2293273","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293273","description":""},{"ticket":"2293276","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293276","description":""},{"ticket":"2293440","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293440","description":""},{"ticket":"2297511","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297511","description":""},{"ticket":"2297520","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297520","description":""},{"ticket":"2300409","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300409","description":""},{"ticket":"2300414","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300414","description":""},{"ticket":"2300429","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300429","description":""},{"ticket":"2300491","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300491","description":""},{"ticket":"2300520","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300520","description":""},{"ticket":"2300713","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300713","description":""},{"ticket":"2301465","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2301465","description":""},{"ticket":"2301496","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2301496","description":""},{"ticket":"2301637","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2301637","description":""}],"cves":[{"name":"CVE-2023-52463","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-52463","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2023-52801","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-52801","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26629","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26629","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26630","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26630","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26720","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26720","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26886","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26886","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26946","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26946","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35791","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35791","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35797","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35797","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35875","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35875","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-36000","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36000","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-36019","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36019","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-36883","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36883","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-36979","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36979","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38559","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38559","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38619","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38619","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40927","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40927","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40936","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40936","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41040","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41040","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41044","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41044","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41055","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41055","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41073","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41073","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41096","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41096","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42082","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42082","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42096","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42096","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42102","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42102","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42131","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42131","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2024-09-17T00:57:55.623189Z","rpms":{"Rocky Linux SIG Cloud9":{"nvras":["bpftool-0:7.3.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","bpftool-0:7.3.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","bpftool-debuginfo-0:7.3.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","bpftool-debuginfo-0:7.3.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-0:5.14.0-427.35.1.el9_4.cloud.1.0.src.rpm","kernel-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-abi-stablelists-0:5.14.0-427.35.1.el9_4.cloud.1.0.noarch.rpm","kernel-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-cross-headers-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-cross-headers-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-devel-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-devel-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-devel-matched-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-devel-matched-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-modules-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-modules-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-modules-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-modules-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-debug-modules-extra-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-debug-modules-extra-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-devel-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-devel-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-devel-matched-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-devel-matched-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-doc-0:5.14.0-427.35.1.el9_4.cloud.1.0.noarch.rpm","kernel-headers-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-headers-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-modules-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-modules-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-modules-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-modules-core-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-modules-extra-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-modules-extra-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-tools-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-tools-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-tools-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-tools-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-tools-libs-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-tools-libs-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","kernel-tools-libs-devel-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","kernel-tools-libs-devel-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","perf-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","perf-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","perf-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","perf-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","python3-perf-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","python3-perf-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","python3-perf-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","python3-perf-debuginfo-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm","rtla-0:5.14.0-427.35.1.el9_4.cloud.1.0.aarch64.rpm","rtla-0:5.14.0-427.35.1.el9_4.cloud.1.0.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Explore the latest kernel security patch for Rocky Linux, addressing several critical concerns ofmoderate seriousness.. Rocky Linux Kernel Update, Security Fixes, System Stability Enhancements. . LinuxSecurity.com Team
Red Hat OpenShift Container Platform release 4.12.30 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.12.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.12.30 bug fix and security update Advisory ID: RHSA-2023:4671-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:4671 Issue date: 2023-08-23 CVE Names: CVE-2023-25173 ===================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.12.30 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.12. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.12.30. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2023:4674 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes/ocp-4-12-release-notes Security Fix(es): *containerd: Supplementary groups are not set up properly (CVE-2023-25173) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes/ocp-4-12-release-notes You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:86ee723d4dc2a83f836232d1d03f8b4193940c50a2636ee86924acb5d14b0b64 (For s390x architecture) The image digest is sha256:c6e023eaa4e80a044bbaeaed5b578d18afddf0b52ad12571ee3a42aa0ff5862a (For ppc64le architecture) The image digest is sha256:0a1dbd83d0552d0332c327d9bd9b1fce8ed73d89937178208d29a73276b72c1c (For aarch64 architecture) The image digest is sha256:21145f1df3c0e88d50de5c697d7fab316f4792f91320a7196ed0dfd94396c0d9 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions forupgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/updating_clusters/updating-cluster-cli 4. Bugs fixed (https://bugzilla.redhat.com/): 2174485 - CVE-2023-25173 containerd: Supplementary groups are not set up properly 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OCPBUGS-14386 - Update cluster-bootstrap 4.12 dependencies and image OCPBUGS-16410 - ensure fixes land for large inodes OCPBUGS-16846 - [Openshift Pipelines] Stop option for pipelinerun is not working OCPBUGS-17192 - "Duplicate RoleBinding" leads to "Unsupported value" error OCPBUGS-17558 - [4.12] Missing Azure File CSI NFS support 6. References: https://access.redhat.com/security/cve/CVE-2023-25173 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes/ocp-4-12-release-notes 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk5nCxAAoJENzjgjWX9erEilsQAI+QV6P2sngvpUvxGsvsK5Kx fa9w7/Er51AeI7LUWmArvj0pgKumjEr/toRD3fC/YfTm8jHhszDL2aFtk1zU54vR qIqajS6LDdILAJ0U8d9amuu5YxH8DFnyQYAfc+aYFyTaEy1i2Q/Rp0HcUa91pN3x eq4gyrRsYP+ovBK0XZqHw50Cx5Qn++ONIPlhOabbsmx5TtmQU0YxDe++LJ5yoT2O uGQPTcxE6WdqsC5Ulvx+F6XXbg2ITmxMiltu3Oln4ySKPCp+JhLyh4wJIuucqYVL slT3/wMsOHD2IRkxGI7rHMnemaemHPlDkHttLd/2M9LO2u1u+MWHfUzqHB+7qQGp HtlICid3TfX6lL6ypcF0DzbcvU/gc9Ju0f2YCdlLsitMe3Gr6RskWpVtkDRZ4zRb xVeOGqek4WSP8gouYYZlL+iciapy3yiL4EUR4s8jIBAjGChU9+/d/gbumKzCrNup cV9ypdsKPKs2PrnZLqeP1ryT3ZR7kaoM65h7UbBKb3oC4U2/BcJj+d679mqveOR/ Y/ESqqU3tdHwavxtHsZJGhhhgpEklio/sqoYh4EsIe+qgDmHMXVcwZK6pBswE5zO frigYOAMEE3l8zVBsDDdOuc+gIXpzdp4rRrk9Mni7E9/MV5NB2LrOJxPkfk+9LBc OC/3MhzxhOnlqiEoTb5J =BflD -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Container Platform release 4.13.6 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.13.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.13.6 security and extras update Advisory ID: RHSA-2023:4225-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:4225 Issue date: 2023-07-27 CVE Names: CVE-2022-41723 CVE-2023-1260 CVE-2023-2828 CVE-2023-3089 CVE-2023-24329 CVE-2023-24534 CVE-2023-24536 CVE-2023-24537 CVE-2023-24538 CVE-2023-24539 CVE-2023-27561 CVE-2023-29400 ===================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.13.6 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.13. Red Hat Product Security has rated this update as having a security impact of [impact]. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.13.6. See the following advisory for the container images for this release: Security Fix(es): * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, andother related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes 4. Bugs fixed (https://bugzilla.redhat.com/): 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OCPBUGS-16170 - Backport X710 Backplane and Base T to SRIOV network operator version 4.13 6. References: https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2023-1260 https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-24534 https://access.redhat.com/security/cve/CVE-2023-24536 https://access.redhat.com/security/cve/CVE-2023-24537 https://access.redhat.com/security/cve/CVE-2023-24538 https://access.redhat.com/security/cve/CVE-2023-24539 https://access.redhat.com/security/cve/CVE-2023-27561 https://access.redhat.com/security/cve/CVE-2023-29400 https://access.redhat.com/security/updates/classification#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat,Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkwdRjAAoJENzjgjWX9erEBbwP/0uXUKIbxgbxZL+SpfzZAdtP X1oLO/cAYqpDSGREKNGp7FJ1ZdzzMnb9R3T+UPdpWwe5E/Nqi3pr8E5fV9bOyjrr zIEJgb5HoAJRqzZXeCuNqamdtTc7huL729N73aOCyNwW/NdJg9QoR/fEI/nOmQOh vCywa5O7ZBVotNLSZCteU6a4XNt3mSLzFWFHGYbfyC0Dr9B2yr+TOOmRWB2i9Gur CcjfmXpIiItcGholfPuqN2R7sDkgMaCSQMXtq34f6DMMdYdZ9dxdtVEgO8gmUE8Q R5FRvXiIq4lokN43feyuuxNHJXeFlmWXyqj59I8bxkv7lixGCu83Iyy4A7Q3oEWG fiX9USnKg44MS5ZjXn2V6MKxp591RvLExpbL9DxdHQVTDXmbrzh6XwRbALyMJfdZ b1kiq5iwGsPOyV9em0rU0YKiJ2j0fs77+e1BrW3kH0+qsFQE8DJ1/eID+2JEO+pv i0U0jHHtka1zU2KwAVGDawdX8E2SG5bCY/b9RhGvG4rjFk6R7rm9jlJ91m4e0ebZ Xofy5lWmrUyiFZgU8b+k3gjG1jzAD4hguKHA80Pf4ETW3OGwpu4ogJkEBuI5FO6L D2GArFcsZnnjZZmLOqxwqKDEN4+n4ZbmqoglxsMgkC1eT8NluKe3Oo1Yn/uRZh4A 18zYfxPSfI3bISZy6NY3 =EBKt -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Container Platform release 4.13.5 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.13.5 security update Advisory ID: RHSA-2023:4091-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:4091 Issue date: 2023-07-20 CVE Names: CVE-2022-4304 CVE-2022-4450 CVE-2022-41717 CVE-2022-41723 CVE-2022-46663 CVE-2023-0215 CVE-2023-0361 CVE-2023-0464 CVE-2023-0465 CVE-2023-0466 CVE-2023-1255 CVE-2023-1260 CVE-2023-2253 CVE-2023-2650 CVE-2023-2700 CVE-2023-3089 CVE-2023-24329 CVE-2023-24534 CVE-2023-24536 CVE-2023-24537 CVE-2023-24538 CVE-2023-24539 CVE-2023-27561 CVE-2023-29400 CVE-2023-32067 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.13.5 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShiftContainer Platform 4.13.5 See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2023:4093 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes Security Fix(es): * golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) * distribution/distribution: DoS from malicious API request (CVE-2023-2253) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digestis sha256:af19e94813478382e36ae1fa2ae7bbbff1f903dded6180f4eb0624afe6fc6cd4 (For s390x architecture) The image digest is sha256:d4d2c747fade057e55f64e02a34bb752bd2cd1484b02f029d0842d346f872870 (For ppc64le architecture) The image digest is sha256:48466f0b7c86292379c5d987ec37f0d4a4cc26a69357374e127a7293b230c943 (For aarch64 architecture) The image digest is sha256:e9afcbe007e2440d2b862dc7709138df73dd851421d69c7f39f195301e0cda53 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/updating_clusters/updating-cluster-cli 4. Bugs fixed (https://bugzilla.redhat.com/): 2161274 - CVE-2022-41717 golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding 2189886 - CVE-2023-2253 distribution/distribution: DoS from malicious API request 5. JIRA issues fixed (https://issues.redhat.com/): OCPBUGS-10326 - Re-enable operator-install-single-namespace.spec.ts test OCPBUGS-11143 - [Azure] Replace master failed as new master did not add into lb backend OCPBUGS-11974 - User telemetry is broken (inaccurate) due to the fact that page titles are not unique. OCPBUGS-12206 - [4.13] Keep systemd journal using LZ4 compression (via new env var) OCPBUGS-12256 - ptp operator socket management need rework since a few test case fails due to cleaning up the file before other processes are terminated. OCPBUGS-12743 - [4.13] SNO cluster deployment failing due to authentication and console CO in degraded state OCPBUGS-12785 - [release-4.13] Enable/Disable plugin options are not shown on Operator details page OCPBUGS-13311 - Kubelet CA file not written by MCD firstboot OCPBUGS-13323 - [4.13]Bootimage bump tracker OCPBUGS-13642 - [release-4.13] OLM k8sResourcePrefix x-descriptor dropdown unexpectedly clears selections OCPBUGS-13747 - [4.13] cgroupv1 support for cpu balancing is broken for non-SNO nodes OCPBUGS-13752 - AdditionalTrustBundle is only included when doing mirroring OCPBUGS-13809 - OVN image pre-puller pod uses `imagePullPolicy: Always` and blocks upgrade when there is no registry OCPBUGS-13812 - [azure] Installer doesn't validate diskType on ASH which lead to install fails with unsupported disktype OCPBUGS-14030 - Invalid CA certificate bundle provided by service account token OCPBUGS-14166 - Make Serverless form is broken OCPBUGS-14189 - Route Checkbox getting checked even if it is unchecked during editing the Serverless Function form OCPBUGS-14251 - Add new console metrics to cluster-monitoring-operator telemetry configuration (4.13) OCPBUGS-14267 - [Openshift Pipelines] Metrics page is broken OCPBUGS-14310 - Could not import multiple resources via JSON (while YAML supports this) OCPBUGS-14318 - [release-4.13] gather podDisruptionBudget only from openshift namespaces OCPBUGS-14336 - [Openshift Pipelines] Link to Openshift Route from service is breaking because of hardcoded value of targetPort OCPBUGS-14426 - Failed to list Kepler CSV OCPBUGS-14459 - The MCD repeats a "State and Reason" log line even when nothing is happening OCPBUGS-14482 - Sync RHEL9 Dockerfiles to regular Dockerfiles OCPBUGS-14598 - Update Jenkins to use 4.13 images OCPBUGS-14773 - (release-4.13) gather "gateway-mode-config" config map from "openshift-network-operator" namespace OCPBUGS-14867 - When installing SNO with bootstrap in place it takes cluster-policy-controller 6 minutes to acquire the leader lease OCPBUGS-14916 - images: RHEL-8-based container image is broken OCPBUGS-14943 - visiting Configurations page returns error Cannot read properties of undefined (reading 'apiGroup') OCPBUGS-15031 - (release-4.13) Insights config not correctly deserialized OCPBUGS-15101 - IngressVIP getting attach to two nodes atonce OCPBUGS-15130 - Helm Repository "Edit" button results in 404 OCPBUGS-15139 - The whereabouts-reconciler should not set an hard-coded node selector on the kubernetes.io/architecture label OCPBUGS-15161 - CPMS: Surface cpms vs machine diff OCPBUGS-15171 - CPO doesn't skip AWS resource deletion for 'Unknown' OIDC state OCPBUGS-15187 - images: RHEL-8 container image is missing `xz` OCPBUGS-15224 - [4.13] openvswitch user is not in the hugetblfs group OCPBUGS-15225 - while/after upgrading to OKD 4.11 2023-01-14 CoreDNS has a problem with UDP overflows OCPBUGS-15228 - Create helm release page doesn't show a YAML editor when schema isn't available (httpd-imagestreams chart) OCPBUGS-15230 - Allow installer to use existing Azure NSG during OpenShift IPI install OCPBUGS-15246 - Bump to kubernetes 1.26.6 OCPBUGS-15281 - Leftover IngressController Preventing Clean Uninstall OCPBUGS-15289 - GCP XPN Installs Require bindPrivateDNSZone Permission in host project OCPBUGS-15330 - CPMSO: fix linting issue comment in test OCPBUGS-15335 - PipelineRun failed with log 'Tasks Completed: 3 (Failed: 1, Cancelled 0), Skipped: 1.' OCPBUGS-15360 - Serverless functions UI warning is misleading OCPBUGS-15372 - [4.13z] Duplicate acls cause network policy failure for namespaces with long names (> 61 chars) OCPBUGS-15376 - [4.13] Cleanup Tech debt: remove unused repo code OCPBUGS-15410 - [release-4.13] Add Git Repository (PAC) doesn't setup GitLab and Bitbucket configuration correct OCPBUGS-15434 - [GWAPI] [4.13.z] The DNS provider failed to ensure the record, invalid value for name (gcp) OCPBUGS-15457 - python-grpcio and python-protobuf are unneeded dependencies OCPBUGS-15463 - [release-4.13] Unable to set protectKernelDefaults from "true" to "false" in kubelet.conf [release-4.13] OCPBUGS-15465 - [CI Watcher] Testing uninstall of Business Automation Operator "attempts to uninstall the Operator and delete all Operand Instances, shows 'Error Deleting Operands' alert" OCPBUGS-15476 - Network Operator not setting its version and blockingupgrade completion OCPBUGS-15481 - [CI Watcher] Broken pipeline-plugin e2e tests: PipelineResource CRD isn't installed anymore OCPBUGS-15512 - HCP Service Loadbalancer uses default SecurityGroup OCPBUGS-15515 - CI fails on TestAWSELBConnectionIdleTimeout OCPBUGS-15557 - TUI stuck on agent installer network boot setup OCPBUGS-15580 - updated nmstate builds will not work for MCO OCPBUGS-15585 - [4.13] Cannot fix a misconfigured Egress Firewall OCPBUGS-15586 - [4.13] NetworkPolicy not working as expected when allowing inbound traffic from any namespace OCPBUGS-15589 - Dynamic conversion webhook clientConfig not retained as operator installs OCPBUGS-15591 - GCP bootstrap VM should allow SecureBoot setting on 4.13 clustersOCPBUGS-15606 - Can't use git lfs in BuildConfig git source with strategy Docker OCPBUGS-15608 - [release-4.13] Clean up old RHEL9 dockerfiles to reduce confusion OCPBUGS-15720 - Helm Chart installation form hangs on create if JSON-schema is using 2019-09 or 2020-20 standard revisions OCPBUGS-15721 - Helm Chart installation form hangs on create if JSON-schema contains unknown value format OCPBUGS-15722 - Helm Chart installation screen fails to render if JSON schema contains remote $refs OCPBUGS-15734 - [4.13] binary should be compiled on RHEL9 OCPBUGS-15736 - TuneD reverts node level profiles on termination OCPBUGS-15738 - tuned daemonset rprivate default mount propagation with `hostPath: path: /` volumeMount breaks CSI driver relying on multipath OCPBUGS-15746 - Alibaba clusters are TechPreview and should not be upgradeable OCPBUGS-15756 - [release-4.13] Bump Jenkins and Jenkins Agent Base image versions OCPBUGS-15777 - ironic-agent-image PRs permafailing due to udevadm command missing OCPBUGS-15782 - [OSD] There is no error message shown on node label edit modal OCPBUGS-15787 - Project admins cannot see 'Pipelines' section in 'import from git' from RHOCP4 web console OCPBUGS-15808 - [4.13.x] Downstream OLM PSA plug-in is disabled OCPBUGS-15848 - The upgrade Helm Release tab in OpenShift GUIDeveloper console is not refreshing with updated values. OCPBUGS-15892 - 9% of OKD tests failing on error: tag latest failed: Internal error occurred: registry.centos.org/dotnet/dotnet-31-centos7:latest: Get "": dial tcp: lookup registry.centos.org on 172.30.0.10:53: no such host OCPBUGS-15962 - ovn-k8s-cni-overlay: /lib64/libc.so.6: version `GLIBC_2.34' not found on 4.12-to-4.13 OCPBUGS-15965 - Active Endpoint Connection blocks cluster uninstallation OCPBUGS-16084 - [4.13] OCP 4.14.0-ec.3 machine-api-controller pod crashing OCPBUGS-7762 - openshift-tests does not file Azure Disk zone topology 6.References: https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-41717 https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2022-46663 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-0464 https://access.redhat.com/security/cve/CVE-2023-0465 https://access.redhat.com/security/cve/CVE-2023-0466 https://access.redhat.com/security/cve/CVE-2023-1255 https://access.redhat.com/security/cve/CVE-2023-1260 https://access.redhat.com/security/cve/CVE-2023-2253 https://access.redhat.com/security/cve/CVE-2023-2650 https://access.redhat.com/security/cve/CVE-2023-2700 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-24534 https://access.redhat.com/security/cve/CVE-2023-24536 https://access.redhat.com/security/cve/CVE-2023-24537 https://access.redhat.com/security/cve/CVE-2023-24538 https://access.redhat.com/security/cve/CVE-2023-24539 https://access.redhat.com/security/cve/CVE-2023-27561 https://access.redhat.com/security/cve/CVE-2023-29400 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification/#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJkuYVOAAoJENzjgjWX9erExUgP/2/25PbUv77tHgYG+Oj5rmcT oTnu0LnBLOsDXYGOomnrE/UZFvWtQr8lGWpvkHpZjJjg7IZo4vN4mUhK+z7dM+3M zuyV++GHDF/zr1XxYf6xWWWNtdCTwWsUKcb6FB4J+WCiUJ8PSYFY3lbPcvAbTamP Hj1JHc3/NxYswwfwBcmK+E4DX4y0XImRdu5+vIXZdp5dpTBehchnSa+Mgjt7vdwi rHi7CdAsHDrPQhThlIRmc17cwsqiZS760xxpx9UNHvix5UQA9ns+OcUx/dLaGR9E dp41kCebze5st+wpBMCPoOZEvHJIMjC6ODFVb4mzRbhbAbWJS6GZl2V783v5RGrr FemE7DDKKt6QEjZhT61GXVS9EdWdFrNii5kmgEiUc/F6Md0fHrPcdt5yxK0dhPZb 3R/64vcMsHllsEStpg8s1aieAZbpmheylEKK+zf82Vz3nlBNX5kxi2IxCrl4nG6X KublzGkkKiNXS9rZqzPDRgtGAn5Qi01U9kUzVgdKGfMsyRnvAVDeZf/FUdOhCm7M h2Yt9M2cgPImRWatKkECpsAwcHbgGtsFL96/5z6CSOoXbqkB2xV6LVixsoa4ys76 cHsXRPJFDU97Y1I9h1kJbro/N8UdPZSicVdsWrLYadujBrhaPq5MoW+B1FpayaDh +AfFGtVd9LRp5sYROCuT =2EuA -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Container Platform release 4.13.3 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.13.3 bug fix and security update Advisory ID: RHSA-2023:3537-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:3537 Issue date: 2023-06-13 CVE Names: CVE-2022-41723 CVE-2023-25173 CVE-2023-26054 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.13.3 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13. Red Hat Product Security has rated this update as having a security impact of [impact]. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.13.3. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2023:3536 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about thesechanges: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes Security Fix(es): * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) * containerd: Supplementary groups are not set up properly (CVE-2023-25173) * buildkit: Data disclosure in provenance attestation describing a build (CVE-2023-26054) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:bc9835804046aa844c874d2cc37387ec95fe7e87d8ce96129fba78d465c932fa (For s390x architecture) The image digest is sha256:c26d48b04d8864fc20145204b543957824d1d86696c82efdd9738d096796326d (For ppc64le architecture) The image digest is sha256:2bf60fe7b0c72a301aa26544e3faabb61fe750e449ee130ee6945b588a727e67 (For aarch64 architecture) The image digestis sha256:f61d496a3b69582f0f1c54da973a58241b3e6001d8d1a696368d604b9ae774f2 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/updating_clusters/updating-cluster-cli 4. Bugs fixed (https://bugzilla.redhat.com/): 2174485 - CVE-2023-25173 containerd: Supplementary groups are not set up properly 2176447 - CVE-2023-26054 buildkit: Data disclosure in provenance attestation describing a build 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OCPBUGS-10527 - When there are 2 pipelines displayed in the dropdown menu, selecting one, unchecks the Add Pipeline checkbox OCPBUGS-11530 - GCP usage api response include other projects and can causes negative quota calculation OCPBUGS-11851 - [4.13] nto: makefile: fix render-sync make target OCPBUGS-12918 - [GWAPI] OSSM 2.4 spec.techPreview.controlPlaneMode field not supported anymore OCPBUGS-13011 - Azure cloud node manager stopped applying beta topology labels OCPBUGS-13168 - Invalid CA certificate bundle provided by service account token OCPBUGS-13399 - Error logs related to NTO Service during HostedCluster creation OCPBUGS-13727 - Invalid docker ref parsing when tag and sha are both provided OCPBUGS-13735 - Cluster-api SA can't create events OCPBUGS-13749 - NTO does not include PerformanceProfiles in oc adm must-gather OCPBUGS-13765 - IPI baremetal install root device hints should accept by-path device alias OCPBUGS-13811 - Volume unmount repeats after successful unmount, preventing pod delete OCPBUGS-13964 - mtls CRL not working when using an intermediate CA OCPBUGS-13967 - CRL configmap is limited by 1MB max, not allowing formultiple public CRLS. OCPBUGS-14000 - Package openvswitch2.17 conflicts with openvswitch2.15 during the 4.12 to 4.13 upgrade of RHEL worker OCPBUGS-14085 - Log vcenter version in raw string format in problem-detector OCPBUGS-14098 - The vsphere-problem-detector-operator panics if vsphere Infrastructure field is empty OCPBUGS-14135 - SCOS times out during provisioning of BM nodes OCPBUGS-14165 - Labels added in the Git import flow are not propagated to the pipeline resources OCPBUGS-14171 - gracefully fail when iam:GetRole is denied OCPBUGS-14173 - [4.13] Fast track BZ#2196441 (Network Manager) OCPBUGS-14195 - Topology UI doesn't recognize Serverless Rust function for proper UI icon OCPBUGS-14249 - oc does not preserve a speficic release image provided with --to-image=' OCPBUGS-14258 - Adjust vSphere connection plugin to OCP 4.13 - backport OCPBUGS-14315 - IPv6 interface and address missing in all pods - OCP 4.12-ec-2 BM IPI OCPBUGS-14438 - 4.13.z: [Clone of OCPBugs-8287]SNO 4.10: Power cycle node and MAC address of NIC not available when VDU application starts on Intel E810-C Nic 6. References: https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2023-25173 https://access.redhat.com/security/cve/CVE-2023-26054 https://access.redhat.com/security/updates/classification/#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes/ocp-4-13-release-notes 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZIlFG9zjgjWX9erEAQjFHg/+JD8RnnEEsvLQK8UlMG1kcmCTXfPA4xHu U6d3UjOzpFkUqJKS7VA+pOPCo5rhhR+ysE3hhSqrYeFIVLBX73vzfnYTvEHO0PpU gWbHIrMAplWa8dZ5g6h0U8zXB+2DAFLTJjs/28GGKS4/VHMwJSWDiMZKDsTA3V1l hM/Lz6aflcLkXDExxIXk1Q0WIy3TLx/RX9dbMlHe8oU/bh+rPuXfBc7XakfhnEOt oHgAJqTjziAcsfleCyh4/5wmrUofNZBekV1S5CZn/23nDoctKDCsiF3ndNt8wokp u3wbwMdgmaaiI/wqrmiY3gAV6+/AvsqMUsViEiAEh1iwAvN38pl3ALWI1R8pUtxR D0TKP2aetv7zdYrcRXptB9w/lH5QEHipYhyqqbtrjXbF8XDggORYsbXi1KLqYHZa vI0TVCM4bcbeDzF/VqF3mnyBGkYzbuiY9PNLymBsrtQ5SEfLfMuB0nWxMnEaAEaq uhEtCZadYZ6JtI2REbPFvMzBLWfX2HR2Ajwy0Efe0Uj1oOe3jy5Zvsi5TiW3klVI 6o+g4pUGPixVSixBcNXqPKyKDZeEEtLPo3l1ZIyp7E/dZKElI/7nMROVyWkMZX79 UBpztFnPjpHtXsgEUhsZ7wLPR/YrClqmxl0Sb+0zfhqSM3qpjQwlMVSHOMERyjfw OeqeVYbjEpU=YSnm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Container Platform release 4.10.56 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.10.56 security update Advisory ID: RHSA-2023:1656-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:1656 Issue date: 2023-04-12 CVE Names: CVE-2021-20329 CVE-2022-3172 CVE-2022-31690 CVE-2022-31692 CVE-2022-42889 CVE-2023-0266 CVE-2023-0286 CVE-2023-0461 CVE-2023-24422 CVE-2023-27898 CVE-2023-27899 CVE-2023-27903 CVE-2023-27904 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.10.56 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.10.56. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2023:1655 Space precludes documenting all the container images in this advisory. See the following Release Notesdocumentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes Security Fix(es): * mongo-go-driver: specific cstrings input may not be properly validated (CVE-2021-20329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.10 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:60f6c51a852f084a020c3dc32b92cbd91ed293b82c6c5b48aac51460566688c7 (For s390x architecture) The image digest is sha256:2307b63fe771e3f1ebd5eb30d9bdc429ecbfb86833943b61cdc48847e8e11461 (For ppc64le architecture) The image digest is sha256:166f394473cca2a379a4915fb6631b7232078d7eb0e0eb7ef99133f8b6d48b9d (For aarch64 architecture) The image digestis sha256:7997b03ba9ee7477b242d57976244a8133fc4f8402a8cc83081accdc08d9a715 All OpenShift Container Platform 4.10 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/updating_clusters/updating-cluster-cli 4. Bugs fixed (https://bugzilla.redhat.com/): 1971033 - CVE-2021-20329 mongo-go-driver: specific cstrings input may not be properly validated 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OCPBUGS-10491 - Prometheus continuously restarts due to slow WAL replay OCPBUGS-10524 - Traffic from egress IPs was interrupted after Cluster patch to Openshift 4.10.46 OCPBUGS-10703 - MTU migration configuration is cleaned up prematurely while in progress OCPBUGS-10750 - 'oc adm upgrade channel ...' should not clobber unrecognized spec properties OCPBUGS-10777 - TestNewAppRun unit test failing OCPBUGS-10814 - Risk cache warming takes too long on channel changes OCPBUGS-11236 - Bump Jenkins to 2.387.1 OCPBUGS-11238 - Jenkins images based on rhel8 are wrongly tagged with rhel7 OCPBUGS-8314 - Bump to kubernetes 1.23.17 6.References: https://access.redhat.com/security/cve/CVE-2021-20329 https://access.redhat.com/security/cve/CVE-2022-3172 https://access.redhat.com/security/cve/CVE-2022-31690 https://access.redhat.com/security/cve/CVE-2022-31692 https://access.redhat.com/security/cve/CVE-2022-42889 https://access.redhat.com/security/cve/CVE-2023-0266 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/cve/CVE-2023-0461 https://access.redhat.com/security/cve/CVE-2023-24422 https://access.redhat.com/security/cve/CVE-2023-27898 https://access.redhat.com/security/cve/CVE-2023-27899 https://access.redhat.com/security/cve/CVE-2023-27903 https://access.redhat.com/security/cve/CVE-2023-27904 https://access.redhat.com/security/updates/classification/#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes https://access.redhat.com/articles/11258 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZDbeftzjgjWX9erEAQi18g/9HjS5qch0p8gZxDq4ZSMSwcKbBfKdy7hn 5Mzmpvw1RKeUZGdUBlPWF0zTUzNEimcaQ4RqApegxqxfMrfIihzrastTVWeXsx33 TC1goYRygd2Swxe5lEZ7E/CS9FH7O3ggz0dGwAXKdz+DmXlGa8aoWRRzpzrp7vzi PD4Jwpe+t+acqmNQKDX7PdM58++1Yd+BOEMllkkbxFS6RpJ4JBBaY0TDLkJfU4hB 0GJ4G9mdBDXuzlxj+jtc2DLMSvFQ5qAmGUxjTZLI8dFVbuCz52rTr9Ek414aiZw5 3hGOCPPJq7jL9ruzTFBbkuus8nBVtTt914jb2emBKT2v7IM4YQK1i6UsCyDUue61 34UhYC7N1L7n0lZe8RSTVCSYRLVL8+9Zdr1kAHAojJunABWgVXAJjZZdOXmlKOYR Rr/mbh+jRx3cWoiFaYwvtRPfwxknaE8fwdxIsQYfLxGOm6sdpSSPOFSTMmE+nMsy 8+MCBoljCThwjXNZN6Z92NheRSvDdZQx90+sTF/u/YMFWiSu9t31OPT0nwQNudj9 8MqlovebS/uLXTHHDpiVT/hackE17PGQnmgRslQFAHuBp5gsnpXpw0cGyIB9Jlc7 6MRtbOCqao5A7TrRIiYWRRQzisK6laUam3y30WWDCCzXt/cacfm/kr9Ssx4eUc3m T9eS4aqy7Aw=0HQs -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Container Platform release 4.10.55 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: OpenShift Container Platform 4.10.55 security update Advisory ID: RHSA-2023:1393-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:1393 Issue date: 2023-03-29 CVE Names: CVE-2021-4238 CVE-2022-3564 CVE-2022-4269 CVE-2022-4378 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.10.55 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.10.55 See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2023:1392 Security Fix(es): * goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. AllOpenShift Container Platform 4.10 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes 4. Bugs fixed (https://bugzilla.redhat.com/): 2156729 - CVE-2021-4238 goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be 5. References: https://access.redhat.com/security/cve/CVE-2021-4238 https://access.redhat.com/security/cve/CVE-2022-3564 https://access.redhat.com/security/cve/CVE-2022-4269 https://access.redhat.com/security/cve/CVE-2022-4378 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZCOtStzjgjWX9erEAQjbvw//X0a/bbRgH8Dl//LJvsD3x9k4XLfBqlHS BHFfU98nTxNBknbqEKQtne4SeUXVRK3U0ZFwpYUumJuvqkfvcGt2pyf92jvdVtLJ MD5gf3scBgZ4y/6uIJEDfB/1xCTR+ReHaxX7FNwLmi8mCabY94KFV0UMPmQ+9AaK XE4sBS3aLe+FeYssD2OknGiNv5jq9W5bWLSLx/zaiN84Ec76vQ3gJzR5nRA4HlzH eZTYcPzsF8MUikuR2PdRJdwWB/057mQrqkI8xG+X9WEKPbipYLyxKAOT1mM1HXmW z2RHowb5UBNEGoMT0OlF+XDuPoFzu+suXnup+kbKnpvgK/6naZwHtSaLt+rKwkp3 ZCEso+bSG/FZ4vQ67ZSmTnFVJG+swsqll5whfWNGGgNFYRO+AQgW9FHahAh4oIip /xS3DpP7zMFJw8tnnTwz04HJc/Ey7sdjyETKrBrnmXmHh5JoNcgmYHqvIgiTlCAB 0eEtMW7c0yl/HY7qQxL7ttaXoPhY8WYalRNu9X6IOy5v1dSc75/7O9q8vJxL2I1N P+FJkhf7AyOZhtb9bXcizFdHX7nGB4kjWKWvFnrghnrNSvboscQ12TH2mo1GBnqL L5iSb1NYRVcC++I3TxdDuVU4j7oJcdNXpGYJrMqaOvjeiylIxe4axTUBRfaRSFbU dw+aJVm7jgU=dD5f -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.