RHSA-2023:1014: Important: Red Hat OpenStack Platform 17.0 (etcd) security update
A highly-available key value store for shared configurationSecurity Fix(es): Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1014?
The severity of RHSA-2023:1014 is classified as important.
How do I fix RHSA-2023:1014?
To fix RHSA-2023:1014, update etcd and related packages to version 3.4.14-3.el9.
What vulnerability is addressed by RHSA-2023:1014?
RHSA-2023:1014 addresses CPU and memory abuse vulnerabilities arising from parsing malicious or large YAML documents (CVE-2022-3064).
What packages are affected by RHSA-2023:1014?
The affected packages in RHSA-2023:1014 include etcd, etcd-debuginfo, and etcd-debugsource.
Is there a workaround for RHSA-2023:1014?
Currently, no specific workaround is provided for RHSA-2023:1014; the recommended action is to apply the patch.