RHSA-2023:1079: Moderate: Red Hat OpenStack Platform 16.2 (osp-director-downloader-container, osp-director-agent-container and osp-director-operator-container) security update
Security Fix(es): archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1079?
The severity of RHSA-2023:1079 is considered high due to potential unbounded memory consumption vulnerabilities.
How do I fix RHSA-2023:1079?
To fix RHSA-2023:1079, apply the latest security updates provided by Red Hat for your affected software.
What vulnerabilities are addressed in RHSA-2023:1079?
RHSA-2023:1079 addresses two vulnerabilities: CVE-2022-2879 related to unbounded memory consumption in archive/tar and CVE-2022-41715 concerning regex parsing.
Who is affected by RHSA-2023:1079?
Any users running the affected versions of Red Hat software with the specified vulnerabilities are at risk from RHSA-2023:1079.
What are the potential impacts of not addressing RHSA-2023:1079?
Failing to address RHSA-2023:1079 may lead to excessive memory consumption and potential denial of service due to exploitation of the vulnerabilities.