RHSA-2021:0916: Moderate: Red Hat OpenStack Platform 16.1.4 (etcd) security update
A highly-available key value store for shared configuration.Security Fix(es): large slice causes panic in decodeRecord method (CVE-2020-15106) DoS in wal/wal.go (CVE-2020-15112) directories created via os.MkdirAll are not checked for permissions (CVE-2020-15113) gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS (CVE-2020-15114) improper validation of passwords allow an attacker to guess or brute-force user's passwords (CVE-2020-15115) no authentication is performed against endpoints provided in the -endpoints flag (CVE-2020-15136) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2021:0916?
RHSA-2021:0916 addresses vulnerabilities including CVE-2020-15106, CVE-2020-15112, and improper permission checks on directories created via os.MkdirAll.
What is the severity level of RHSA-2021:0916?
The severity level of RHSA-2021:0916 is considered important due to the potential impact on system stability and security.
How can I mitigate vulnerabilities in RHSA-2021:0916?
To mitigate vulnerabilities in RHSA-2021:0916, you should upgrade to etcd version 3.3.23-1.el8.
What software packages are affected by RHSA-2021:0916?
The affected software packages include etcd, etcd-debuginfo, and etcd-debugsource versions below 3.3.23-1.el8.
Is there a recommended action for RHSA-2021:0916?
The recommended action for RHSA-2021:0916 is to apply the security update to the affected packages as soon as possible.