RHSA-2023:2283: Moderate: skopeo security and bug fix update
The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files. Security Fix(es): golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) golang: crypto/tls: session tickets lack random ticketageadd (CVE-2022-30629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:2283?
The severity of RHSA-2023:2283 is classified as critical due to excessive memory growth vulnerabilities.
How do I fix RHSA-2023:2283?
To fix RHSA-2023:2283, update the skopeo package to version 1.11.2-0.1.el9 or later.
What are the affected packages in RHSA-2023:2283?
The affected packages in RHSA-2023:2283 include skopeo, skopeo-debuginfo, skopeo-debugsource, and skopeo-tests.
When was RHSA-2023:2283 released?
RHSA-2023:2283 was released as a security advisory by Red Hat in response to vulnerabilities found in skopeo.
Who is responsible for the vulnerabilities addressed in RHSA-2023:2283?
The vulnerabilities addressed in RHSA-2023:2283 were identified within the skopeo command's implementation and were fixed by the Red Hat security team.