RHSA-2022:0727: Moderate: OpenShift Logging bug fix and security update (5.1.9)
OpenShift Logging bug fix and security update (5.1.9)Security Fix(es): jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception (CVE-2020-28491) origin-aggregated-logging/elasticsearch: Incomplete fix for netty-codec-http CVE-2021-21409 (CVE-2022-0552) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What security issues does RHSA-2022:0727 address?
RHSA-2022:0727 addresses vulnerabilities related to jackson-dataformat-cbor leading to potential OutOfMemoryError exceptions and an incomplete fix for certain logging issues in Elasticsearch.
How do I fix RHSA-2022:0727?
To fix RHSA-2022:0727, you should apply the latest OpenShift Logging updates as recommended in the advisories.
What is the severity of RHSA-2022:0727?
The severity of RHSA-2022:0727 is classified as potentially critical due to OutOfMemoryError vulnerabilities that can affect system stability.
Can RHSA-2022:0727 affect system performance?
Yes, RHSA-2022:0727 can negatively impact system performance if the OutOfMemoryError occurs under heavy load conditions.
Is RHSA-2022:0727 applicable to all versions of OpenShift?
No, RHSA-2022:0727 specifically applies to OpenShift Logging versions that are affected by the identified vulnerabilities.