RHSA-2022:0989: Moderate: Red Hat OpenStack Platform 16.1 (golang-qpid-apache) security update
Golang binding library for qpid-proton<br>Security Fix(es):<br><li> net: incorrect parsing of extraneous zero characters at the beginning of</li> an IP address octet (CVE-2021-29923)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0989?
The severity of RHSA-2022:0989 is determined to be moderate due to the incorrect parsing of extraneous zero characters in IP address octets.
What vulnerability is addressed by RHSA-2022:0989?
RHSA-2022:0989 addresses the vulnerability CVE-2021-29923 related to the Golang binding library for qpid-proton.
How do I fix RHSA-2022:0989?
To fix RHSA-2022:0989, upgrade the golang-qpid-apache package to version 0.32.0-rc1.9.el8 or later.
What software is affected by RHSA-2022:0989?
The affected software for RHSA-2022:0989 is the golang-qpid-apache package specifically the version below 0.32.0-rc1.9.el8.
Is there a workaround for RHSA-2022:0989?
There is no officially recommended workaround for RHSA-2022:0989; the advised action is to apply the software upgrade.