CVE-2024-4436: Etcd: incomplete fix for cve-2022-41723 in openstack platform
The etcd package distributed with Red Hat OpenStack platform has been identified to have an incomplete fix for CVE-2022-41723. This happens because the etcd package in Red Hat OpenStack platform is using the http://golang.org/x/net/http2 instead the one provided by the Red Hat Enterprise linux versions, meaning it should be updated at compile time instead.
Other sources
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/golang.org/x/netto a version that resolves this vulnerability.Fixed in 0.7.0 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.20.1 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.19.6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4436?
CVE-2024-4436 is considered to be a moderate severity vulnerability.
How do I fix CVE-2024-4436?
To fix CVE-2024-4436, update the etcd package to the fixed versions for golang.org/x/net and golang as specified in the advisory.
Which software is affected by CVE-2024-4436?
CVE-2024-4436 affects the etcd package distributed with Red Hat OpenStack as well as the golang packages in specific versions.
Is there a known exploit for CVE-2024-4436?
As of now, there are no public exploits reported for CVE-2024-4436.
What versions should be updated to mitigate CVE-2024-4436?
To mitigate CVE-2024-4436, update to golang.org/x/net version 0.7.0 or later and golang version 1.19.6 or 1.20.1 or later.