RHSA-2023:3366
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: OpenShift Container Platform 4.13.2 packages and security update
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•bpftool
< 0:7.0.0-284.16.1.el9_2
- redhat•bpftool-debuginfo
< 0:7.0.0-284.16.1.el9_2
- redhat•buildah
< 1:1.29.1-1.1.rhaos4.13.el9
- redhat•buildah-debuginfo
< 1:1.29.1-1.1.rhaos4.13.el9
- redhat•buildah-debugsource
< 1:1.29.1-1.1.rhaos4.13.el9
- redhat•buildah-tests
< 1:1.29.1-1.1.rhaos4.13.el9
- redhat•buildah-tests-debuginfo
< 1:1.29.1-1.1.rhaos4.13.el9
- redhat•cri-o
< 0:1.26.3-7.rhaos4.13.gitec064c9.el8 | < 0:1.26.3-8.rhaos4.13.gitec064c9.el9
- redhat•cri-o-debuginfo
< 0:1.26.3-7.rhaos4.13.gitec064c9.el8 | < 0:1.26.3-8.rhaos4.13.gitec064c9.el9
- redhat•cri-o-debugsource
< 0:1.26.3-7.rhaos4.13.gitec064c9.el8 | < 0:1.26.3-8.rhaos4.13.gitec064c9.el9
- redhat•cri-tools
< 0:1.26.0-2.el9
- redhat•cri-tools-debuginfo
< 0:1.26.0-2.el9
- redhat•cri-tools-debugsource
< 0:1.26.0-2.el9
- redhat•kernel
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-debuginfo
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-devel
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-devel-matched
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-modules
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-modules-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-modules-extra
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-modules-internal
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debug-modules-partner
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-debuginfo
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-devel
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-devel-matched
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-modules
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-modules-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-modules-extra
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-modules-internal
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-64k-modules-partner
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-abi-stablelists
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-debuginfo
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-devel
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-devel-matched
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-modules
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-modules-core
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-modules-extra
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-modules-internal
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-modules-partner
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debug-uki-virt
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debuginfo
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debuginfo-common-aarch64
< 0:5.14.0-284.16.1.el9_2
- redhat•kernel-debuginfo-common-ppc64le
< 0:5.14.0-284.16.1.el9_2
Showing first 50 affected entries in server-rendered view.
References (53)
- https://access.redhat.com/errata/RHSA-2023:3366
- https://access.redhat.com/security/updates/classification/#important
- https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2064702
- https://bugzilla.redhat.com/show_bug.cgi?id=2178492
- https://bugzilla.redhat.com/show_bug.cgi?id=2196027
- https://bugzilla.redhat.com/show_bug.cgi?id=2203008
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3366.json
- https://access.redhat.com/security/cve/CVE-2022-27191
- https://www.cve.org/CVERecord?id=CVE-2022-27191
- https://nvd.nist.gov/vuln/detail/CVE-2022-27191
- https://groups.google.com/g/golang-announce/c/-cp44ypCT5s/m/wmegxkLiAQAJ
- https://access.redhat.com/security/cve/CVE-2022-41722
- https://www.cve.org/CVERecord?id=CVE-2022-41722
- https://nvd.nist.gov/vuln/detail/CVE-2022-41722
- https://access.redhat.com/security/cve/CVE-2022-41724
- https://www.cve.org/CVERecord?id=CVE-2022-41724
- https://nvd.nist.gov/vuln/detail/CVE-2022-41724
- https://go.dev/cl/468125
- https://go.dev/issue/58001
- https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E
- https://pkg.go.dev/vuln/GO-2023-1570
- https://access.redhat.com/security/cve/CVE-2023-24534
- https://bugzilla.redhat.com/show_bug.cgi?id=2184483
- https://www.cve.org/CVERecord?id=CVE-2023-24534
- https://nvd.nist.gov/vuln/detail/CVE-2023-24534
- https://go.dev/issue/58975
- https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8
- https://access.redhat.com/security/cve/CVE-2023-24537
- https://bugzilla.redhat.com/show_bug.cgi?id=2184484
- https://www.cve.org/CVERecord?id=CVE-2023-24537
- https://nvd.nist.gov/vuln/detail/CVE-2023-24537
- https://github.com/golang/go/issues/59180
- https://access.redhat.com/security/cve/CVE-2023-24538
- https://bugzilla.redhat.com/show_bug.cgi?id=2184481
- https://www.cve.org/CVERecord?id=CVE-2023-24538
- https://nvd.nist.gov/vuln/detail/CVE-2023-24538
- https://github.com/golang/go/issues/59234
- https://access.redhat.com/security/cve/CVE-2023-24539
- https://bugzilla.redhat.com/show_bug.cgi?id=2196026
- https://www.cve.org/CVERecord?id=CVE-2023-24539
- https://nvd.nist.gov/vuln/detail/CVE-2023-24539
- https://github.com/golang/go/issues/59720
- https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU
- https://access.redhat.com/security/cve/CVE-2023-24540
- https://www.cve.org/CVERecord?id=CVE-2023-24540
- https://nvd.nist.gov/vuln/detail/CVE-2023-24540
- https://go.dev/issue/59721
- https://access.redhat.com/security/cve/CVE-2023-29400
- https://bugzilla.redhat.com/show_bug.cgi?id=2196029
- https://www.cve.org/CVERecord?id=CVE-2023-29400
- https://nvd.nist.gov/vuln/detail/CVE-2023-29400
- https://go.dev/issue/59722