First published: Tue Jun 21 2022(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container Platform 3.11.715. See the following advisory for the container images for this release:<br><a href="https://access.redhat.com/errata/RHBA-2022:5000" target="_blank">https://access.redhat.com/errata/RHBA-2022:5000</a> Security Fix(es):<br><li> cri-o: memory exhaustion on the node when access to the kube api</li> (CVE-2022-1708)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/atomic-enterprise-service-catalog | <3.11.715-1.g2e6be86.el7 | 3.11.715-1.g2e6be86.el7 |
redhat/atomic-openshift | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.715-1.g99b2acf.el7 | 3.11.715-1.g99b2acf.el7 |
redhat/atomic-openshift-descheduler | <3.11.715-1.gd435537.el7 | 3.11.715-1.gd435537.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.715-1.g0fa231c.el7 | 3.11.715-1.g0fa231c.el7 |
redhat/atomic-openshift-metrics-server | <3.11.715-1.gf8bf728.el7 | 3.11.715-1.gf8bf728.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.715-1.gc8f26da.el7 | 3.11.715-1.gc8f26da.el7 |
redhat/atomic-openshift-service-idler | <3.11.715-1.g39cfc66.el7 | 3.11.715-1.g39cfc66.el7 |
redhat/atomic-openshift-web-console | <3.11.715-1.ga7c5920.el7 | 3.11.715-1.ga7c5920.el7 |
redhat/cri-o | <1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 | 1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.715-1.gedebe84.el7 | 3.11.715-1.gedebe84.el7 |
redhat/golang-github-prometheus-alertmanager | <3.11.715-1.g13de638.el7 | 3.11.715-1.g13de638.el7 |
redhat/golang-github-prometheus-prometheus | <3.11.715-1.g99aae51.el7 | 3.11.715-1.g99aae51.el7 |
redhat/openshift-ansible | <3.11.715-1.git.0.9151060.el7 | 3.11.715-1.git.0.9151060.el7 |
redhat/openshift-enterprise-autoheal | <3.11.715-1.gf2f435d.el7 | 3.11.715-1.gf2f435d.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.715-1.g22be164.el7 | 3.11.715-1.g22be164.el7 |
redhat/openshift-kuryr | <3.11.715-1.g0c4bf66.el7 | 3.11.715-1.g0c4bf66.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.715-1.g2e6be86.el7 | 3.11.715-1.g2e6be86.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.715-1.g2e6be86.el7 | 3.11.715-1.g2e6be86.el7 |
redhat/atomic-openshift | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-clients | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-clients-redistributable | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.715-1.g99b2acf.el7 | 3.11.715-1.g99b2acf.el7 |
redhat/atomic-openshift-descheduler | <3.11.715-1.gd435537.el7 | 3.11.715-1.gd435537.el7 |
redhat/atomic-openshift-docker-excluder | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.715-1.g0fa231c.el7 | 3.11.715-1.g0fa231c.el7 |
redhat/atomic-openshift-excluder | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-hyperkube | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-hypershift | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-master | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-metrics-server | <3.11.715-1.gf8bf728.el7 | 3.11.715-1.gf8bf728.el7 |
redhat/atomic-openshift-node | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.715-1.gc8f26da.el7 | 3.11.715-1.gc8f26da.el7 |
redhat/atomic-openshift-pod | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-sdn-ovs | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-service-idler | <3.11.715-1.g39cfc66.el7 | 3.11.715-1.g39cfc66.el7 |
redhat/atomic-openshift-template-service-broker | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-tests | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-web-console | <3.11.715-1.ga7c5920.el7 | 3.11.715-1.ga7c5920.el7 |
redhat/cri-o | <1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 | 1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 |
redhat/cri-o-debuginfo | <1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 | 1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.715-1.gedebe84.el7 | 3.11.715-1.gedebe84.el7 |
redhat/openshift-ansible | <3.11.715-1.git.0.9151060.el7 | 3.11.715-1.git.0.9151060.el7 |
redhat/openshift-ansible-docs | <3.11.715-1.git.0.9151060.el7 | 3.11.715-1.git.0.9151060.el7 |
redhat/openshift-ansible-playbooks | <3.11.715-1.git.0.9151060.el7 | 3.11.715-1.git.0.9151060.el7 |
redhat/openshift-ansible-roles | <3.11.715-1.git.0.9151060.el7 | 3.11.715-1.git.0.9151060.el7 |
redhat/openshift-enterprise-autoheal | <3.11.715-1.gf2f435d.el7 | 3.11.715-1.gf2f435d.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.715-1.g22be164.el7 | 3.11.715-1.g22be164.el7 |
redhat/openshift-kuryr-cni | <3.11.715-1.g0c4bf66.el7 | 3.11.715-1.g0c4bf66.el7 |
redhat/openshift-kuryr-common | <3.11.715-1.g0c4bf66.el7 | 3.11.715-1.g0c4bf66.el7 |
redhat/openshift-kuryr-controller | <3.11.715-1.g0c4bf66.el7 | 3.11.715-1.g0c4bf66.el7 |
redhat/prometheus | <3.11.715-1.g99aae51.el7 | 3.11.715-1.g99aae51.el7 |
redhat/prometheus-alertmanager | <3.11.715-1.g13de638.el7 | 3.11.715-1.g13de638.el7 |
redhat/prometheus-node-exporter | <3.11.715-1.g609cd20.el7 | 3.11.715-1.g609cd20.el7 |
redhat/python2-kuryr-kubernetes | <3.11.715-1.g0c4bf66.el7 | 3.11.715-1.g0c4bf66.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.715-1.g2e6be86.el7 | 3.11.715-1.g2e6be86.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.715-1.g2e6be86.el7 | 3.11.715-1.g2e6be86.el7 |
redhat/atomic-openshift | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-clients | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.715-1.g99b2acf.el7 | 3.11.715-1.g99b2acf.el7 |
redhat/atomic-openshift-descheduler | <3.11.715-1.gd435537.el7 | 3.11.715-1.gd435537.el7 |
redhat/atomic-openshift-hyperkube | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-hypershift | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-master | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-metrics-server | <3.11.715-1.gf8bf728.el7 | 3.11.715-1.gf8bf728.el7 |
redhat/atomic-openshift-node | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.715-1.gc8f26da.el7 | 3.11.715-1.gc8f26da.el7 |
redhat/atomic-openshift-pod | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-sdn-ovs | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-service-idler | <3.11.715-1.g39cfc66.el7 | 3.11.715-1.g39cfc66.el7 |
redhat/atomic-openshift-template-service-broker | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-tests | <3.11.715-1.git.0.e449bb4.el7 | 3.11.715-1.git.0.e449bb4.el7 |
redhat/atomic-openshift-web-console | <3.11.715-1.ga7c5920.el7 | 3.11.715-1.ga7c5920.el7 |
redhat/cri-o | <1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 | 1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 |
redhat/cri-o-debuginfo | <1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 | 1.11.16-0.17.rhaos3.11.git4c0a8ad.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.715-1.gedebe84.el7 | 3.11.715-1.gedebe84.el7 |
redhat/openshift-ansible-test | <3.11.715-1.git.0.9151060.el7 | 3.11.715-1.git.0.9151060.el7 |
redhat/openshift-enterprise-autoheal | <3.11.715-1.gf2f435d.el7 | 3.11.715-1.gf2f435d.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.715-1.g22be164.el7 | 3.11.715-1.g22be164.el7 |
redhat/prometheus | <3.11.715-1.g99aae51.el7 | 3.11.715-1.g99aae51.el7 |
redhat/prometheus-alertmanager | <3.11.715-1.g13de638.el7 | 3.11.715-1.g13de638.el7 |
redhat/prometheus-node-exporter | <3.11.715-1.g609cd20.el7 | 3.11.715-1.g609cd20.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:4999 is critical.
To fix RHSA-2022:4999, upgrade the relevant packages to the specified versions as provided in the advisory.
RHSA-2022:4999 affects multiple packages related to Red Hat OpenShift Container Platform.
Yes, RHSA-2022:4999 is a known vulnerability documented by Red Hat.
RHSA-2022:4999 was released on October 6, 2022.