RHSA-2023:3204: Moderate: OpenShift Virtualization 4.13.0 RPMs security and bug fix update
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.This advisory contains OpenShift Virtualization 4.13.0 RPMs.Security Fix(es): golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664) golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags (CVE-2022-32149) golang: net/url: JoinPath does not strip relative path components in all circumstances (CVE-2022-32190) golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): 4.13.0 rpms (BZ#2124993)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3204?
The CVE associated with RHSA-2023:3204 is classified as moderate.
What vulnerabilities are addressed in RHSA-2023:3204?
RHSA-2023:3204 addresses security issues related to errors in the golang net/http server handling.
How do I fix RHSA-2023:3204?
To remediate RHSA-2023:3204, update the affected packages to the latest versions listed in the advisory.
Which versions of kubevirt are affected by RHSA-2023:3204?
RHSA-2023:3204 affects kubevirt versions up to 4.13.0-1469.el9, 4.13.0-1469.el8, and 4.13.0-1469.el7.
Are there any specific packages affected by RHSA-2023:3204?
Yes, the packages affected include kubevirt, kubevirt-virtctl, and kubevirt-virtctl-redistributable across multiple versions.