RHSA-2022:0997: Moderate: Red Hat OpenStack Platform 16.2 (golang-qpid-apache) security update
Golang binding library for qpid-proton<br>Security Fix(es):<br><li> net: incorrect parsing of extraneous zero characters at the beginning of</li> an IP address octet (CVE-2021-29923)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0997?
The severity of RHSA-2022:0997 is determined by the associated CVE-2021-29923, which has a specific CVSS score indicating its impact.
How do I fix RHSA-2022:0997?
To fix RHSA-2022:0997, you should update the golang-qpid-apache package to a version greater than 0.32.0-rc1.9.el8.
What vulnerability is addressed in RHSA-2022:0997?
RHSA-2022:0997 addresses CVE-2021-29923, which involves incorrect parsing of extraneous zero characters in IP address octets.
Which package is affected by RHSA-2022:0997?
The package affected by RHSA-2022:0997 is golang-qpid-apache, specifically versions up to 0.32.0-rc1.9.el8.
Is there a CVE associated with RHSA-2022:0997?
Yes, RHSA-2022:0997 is associated with CVE-2021-29923, which pertains to a parsing error in network addresses.