RHSA-2022:8938: Low: Release of OpenShift Serverless 1.26.0
Version 1.26.0 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.8, 4.9, 4.10, and 4.11. This release includes security and bug fixes, and enhancements. golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191) golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565) For more details about the security issues, including the impact; a CVSS score;acknowledgments; and other related information refer to the CVE pages linked inthe References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8938?
The severity of RHSA-2022:8938 is categorized as moderate due to security issues addressed in the OpenShift Serverless Operator.
How do I fix RHSA-2022:8938?
To fix RHSA-2022:8938, upgrade to version 1.26.0 of the OpenShift Serverless Operator on the supported Red Hat OpenShift Container Platform versions.
What vulnerabilities are addressed in RHSA-2022:8938?
RHSA-2022:8938 addresses security vulnerabilities including CVE-2022-27191 related to a crash in a golang.org/x/crypto/ssh server.
Which versions of OpenShift Container Platform are affected by RHSA-2022:8938?
RHSA-2022:8938 affects Red Hat OpenShift Container Platform versions 4.8, 4.9, 4.10, and 4.11.
Is there a need for immediate action on RHSA-2022:8938?
Yes, immediate action is recommended for RHSA-2022:8938 to mitigate potential security risks.