RHSA-2021:3748: Moderate: OpenShift Container Storage 3.11.z Container Images Security and Bug Fix Update
The OpenShift Container Storage solution provides persistent storage service for OpenShift Containers and OpenShift Infrastructure services.Security Fix(es): golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114) golang: net/http: panic in ReadRequest and ReadResponse when reading a very large header (CVE-2021-31525) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.All users of OpenShift Container Storage 3.11 container images are advised to pull these updated images from the Red Hat Container Registry.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3748?
The severity of RHSA-2021:3748 is classified as moderate.
How do I fix RHSA-2021:3748?
To fix RHSA-2021:3748, you should update Red Hat OpenShift Container Storage to the latest version available.
What vulnerabilities are addressed in RHSA-2021:3748?
RHSA-2021:3748 addresses vulnerabilities including CVE-2021-3114 related to incorrect operations on the P-224 curve in Go.
Who is affected by RHSA-2021:3748?
RHSA-2021:3748 affects users of Red Hat OpenShift Container Storage.
Is it mandatory to apply the RHSA-2021:3748 security fix?
While not always mandatory, applying the RHSA-2021:3748 security fix is strongly recommended to mitigate security risks.