First published: Thu Jan 27 2022(Updated: )
The OpenShift Container Storage solution provides persistent storage<br>service for OpenShift Containers and OpenShift Infrastructure services.<br>Security Fix(es):<br><li> golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> panic in ReadRequest and ReadResponse when reading a very large header (CVE-2021-31525)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> With this update, the Heketi packages are upgraded to upstream version 10.4.0. (BZ#2012287)</li> All users of OpenShift Container Storage 3.11 are advised to upgrade to these updated packages, which fix these bugs.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/heketi | <10.4.0-2.el7 | 10.4.0-2.el7 |
redhat/heketi-client | <10.4.0-2.el7 | 10.4.0-2.el7 |
redhat/python-heketi | <10.4.0-2.el7 | 10.4.0-2.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.