RHSA-2019:2661: Important: Red Hat OpenShift Container Platform 4.1 openshift RPM security update
Both the openshift and atomic-enterprise-service-catalog packages have been rebuilt with updates versions of golang. The golang packages provide the Go programming language compiler.Security Fix(es): HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512) HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2661?
The severity of RHSA-2019:2661 is classified as important.
How do I fix RHSA-2019:2661?
To fix RHSA-2019:2661, you need to update to the specified version of the affected packages, such as 4.1.14-201908290858.git.0.3bd3467.el8.
Which packages are affected by RHSA-2019:2661?
The affected packages include openshift, openshift-clients, atomic-enterprise-service-catalog, and openshift-hyperkube among others.
What vulnerabilities are addressed in RHSA-2019:2661?
RHSA-2019:2661 addresses vulnerabilities related to unbounded memory growth caused by flooding using PING frames in HTTP/2.
Is there a specific version recommended for resolving RHSA-2019:2661?
Yes, the recommended version for resolving RHSA-2019:2661 is 4.1.14-201908290858.git.0.3bd3467.el8.