RHSA-2023:1896: Critical: Red Hat Advanced Cluster Management 2.5 hotfix security update for console
Published Apr 20, 2023
·Updated
Security Fix(es) CVE-2023-29017 vm2: Sandbox Escape CVE-2023-29199 vm2: Sandbox Escape CVE-2023-30547 vm2: Sandbox Escape when exception sanitation
Affected Software
1 affected component
Red Hat Red Hat Advanced Cluster Management=2.5 hotfix
Remediation
Event History
May 26, 2026
Advisory Published
via Red Hat·08:55 PM
Data Sourced
via Red Hat·08:55 PM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
What is the severity of RHSA-2023:1896?
RHSA-2023:1896 addresses multiple critical vulnerabilities in the vm2 sandbox, leading to potential escapes.
2
How do I fix RHSA-2023:1896?
To fix RHSA-2023:1896, it is recommended to update to the latest patched version of the affected software.
3
What are the vulnerabilities addressed in RHSA-2023:1896?
RHSA-2023:1896 addresses CVE-2023-29017, CVE-2023-29199, and CVE-2023-30547 related to sandbox escapes.
4
Who is affected by RHSA-2023:1896?
RHSA-2023:1896 affects users and applications utilizing the vm2 sandbox that are prone to these vulnerabilities.
5
Is there a workaround for RHSA-2023:1896?
There are no specific workarounds mentioned in the advisory for RHSA-2023:1896, making an update the primary solution.