RHSA-2023:3450: Moderate: OpenShift Serverless Client kn 1.29.0 release
Red Hat OpenShift Serverless Client kn 1.29.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.29.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms.<br>This release includes security and bug fixes, and enhancements.<br>Security Fixes in this release include:<br><li> containerd: Supplementary groups are not set up properly(CVE-2023-25173)</li> <li> golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding(CVE-2022-41723)</li> <li> golang: net/http, mime/multipart: denial of service from excessive resource consumption(CVE-2022-41725)</li> <li> golang: crypto/tls: large handshake records may cause panics(CVE-2022-41724)</li> <li> golang: html/template: backticks not treated as string delimiters(CVE-2023-24538)</li> <li> golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption(CVE-2023-24536)</li> <li> golang: net/http, net/textproto: denial of service from excessive memory allocation(CVE-2023-24534)</li> <li> golang: go/parser: Infinite loop in parsing(CVE-2023-24537)</li> For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information refer to the CVE pages linked in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3450?
The severity for RHSA-2023:3450 is not explicitly stated, but it involves security and bug fixes for OpenShift Serverless CLI.
How do I fix RHSA-2023:3450?
To fix RHSA-2023:3450, update the openshift-serverless-clients package to version 1.8.1-3.el8 or later.
What versions of openshift-serverless-clients are affected by RHSA-2023:3450?
Versions of openshift-serverless-clients up to 1.8.1-3.el8 are affected by RHSA-2023:3450.
Are there known issues with RHSA-2023:3450?
RHSA-2023:3450 addresses known issues related to security vulnerabilities and bugs in the CLI.
What platforms are impacted by RHSA-2023:3450?
RHSA-2023:3450 affects RHEL platforms where the openshift-serverless-clients are installed.