First published: Wed Oct 30 2019(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the ansible-operator, apb, containernetworking-plugins, golang-github-openshift-prometheus-alert-buffer, golang-github-prometheus-promu and openshift-eventrouter RPM packages for Red Hat OpenShift Container Platform 4.1.21. These packages have been rebuilt with an updated version of Go to address the below security issues.<br>Security Fix(es):<br><li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible-operator | <0.0.1-3.git.59.4beb3d2.el7 | 0.0.1-3.git.59.4beb3d2.el7 |
redhat/apb | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/containernetworking-plugins | <0.8.1-4.el7 | 0.8.1-4.el7 |
redhat/golang-github-openshift-prometheus-alert-buffer | <0-3.gitceca8c1.el7 | 0-3.gitceca8c1.el7 |
redhat/golang-github-prometheus-promu | <0-5.git85ceabc.el7 | 0-5.git85ceabc.el7 |
redhat/openshift-eventrouter | <0.2-3.gited73fb6.el7 | 0.2-3.gited73fb6.el7 |
redhat/ansible-operator | <0.0.1-3.git.59.4beb3d2.el7 | 0.0.1-3.git.59.4beb3d2.el7 |
redhat/ansible-operator-container-scripts | <0.0.1-3.git.59.4beb3d2.el7 | 0.0.1-3.git.59.4beb3d2.el7 |
redhat/ansible-operator-devel | <0.0.1-3.git.59.4beb3d2.el7 | 0.0.1-3.git.59.4beb3d2.el7 |
redhat/apb | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/apb-container-scripts | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/apb-devel | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/containernetworking-plugins | <0.8.1-4.el7 | 0.8.1-4.el7 |
redhat/containernetworking-plugins-debuginfo | <0.8.1-4.el7 | 0.8.1-4.el7 |
redhat/golang-github-openshift-prometheus-alert-buffer | <0-3.gitceca8c1.el7 | 0-3.gitceca8c1.el7 |
redhat/golang-github-prometheus-promu | <0-5.git85ceabc.el7 | 0-5.git85ceabc.el7 |
redhat/openshift-eventrouter | <0.2-3.gited73fb6.el7 | 0.2-3.gited73fb6.el7 |
redhat/openshift-eventrouter-debuginfo | <0.2-3.gited73fb6.el7 | 0.2-3.gited73fb6.el7 |
redhat/prometheus-promu | <0-5.git85ceabc.el7 | 0-5.git85ceabc.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:3265 is classified as important.
To fix RHSA-2019:3265, update the affected packages to the specified remedial versions listed in the advisory.
Affected packages include ansible-operator, apb, containernetworking-plugins, and others as detailed in the advisory.
You are vulnerable to RHSA-2019:3265 if you are using any of the affected package versions outlined in the advisory.
RHSA-2019:3265 was released on December 5, 2019.