RHSA-2023:3447: Important: Red Hat OpenStack Platform 16.1 (etcd) security update
A highly-available key value store for shared configurationSecurity Fix(es): Information discosure via debug function (CVE-2021-28235) golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3447?
The severity of RHSA-2023:3447 is classified as important.
How do I fix RHSA-2023:3447?
To fix RHSA-2023:3447, upgrade to etcd version 3.3.23-14.el8.
What vulnerabilities are addressed in RHSA-2023:3447?
RHSA-2023:3447 addresses CVE-2021-28235 for information disclosure and CVE-2022-41723 for performance issues in HPACK decoding.
Which packages are affected by RHSA-2023:3447?
The affected packages in RHSA-2023:3447 include etcd, etcd-debuginfo, and etcd-debugsource.
Is there a workaround for RHSA-2023:3447?
Currently, the recommended action is to apply the update rather than seeking a workaround.