First published: Tue May 16 2023(Updated: )
Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood.<br>Security Fix(es):<br><li> golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879)</li> <li> golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> handle server errors after sending GOAWAY (CVE-2022-27664)</li> <li> golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.8 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cockpit-composer | <45-1.el8_8 | 45-1.el8_8 |
redhat/osbuild | <81-1.el8 | 81-1.el8 |
redhat/osbuild-composer | <75-1.el8 | 75-1.el8 |
redhat/weldr-client | <35.9-2.el8 | 35.9-2.el8 |
redhat/cockpit-composer | <45-1.el8_8 | 45-1.el8_8 |
redhat/osbuild | <81-1.el8 | 81-1.el8 |
redhat/osbuild-composer | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-core | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-core-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-debugsource | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-dnf-json | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-tests-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-worker | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-worker-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-luks2 | <81-1.el8 | 81-1.el8 |
redhat/osbuild-lvm2 | <81-1.el8 | 81-1.el8 |
redhat/osbuild-ostree | <81-1.el8 | 81-1.el8 |
redhat/osbuild-selinux | <81-1.el8 | 81-1.el8 |
redhat/python3-osbuild | <81-1.el8 | 81-1.el8 |
redhat/weldr-client | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-debuginfo | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-debugsource | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-tests-debuginfo | <35.9-2.el8 | 35.9-2.el8 |
redhat/osbuild-composer-core | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-core-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-debugsource | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-dnf-json | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-tests-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-worker | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-worker-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/weldr-client-debuginfo | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-debugsource | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-tests-debuginfo | <35.9-2.el8 | 35.9-2.el8 |
redhat/osbuild-composer | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-core | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-core-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-debugsource | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-dnf-json | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-tests-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-worker | <75-1.el8 | 75-1.el8 |
redhat/osbuild-composer-worker-debuginfo | <75-1.el8 | 75-1.el8 |
redhat/weldr-client | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-debuginfo | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-debugsource | <35.9-2.el8 | 35.9-2.el8 |
redhat/weldr-client-tests-debuginfo | <35.9-2.el8 | 35.9-2.el8 |
redhat/osbuild-composer | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-core | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-core-debuginfo | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-debuginfo | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-debugsource | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-dnf-json | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-tests-debuginfo | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-worker | <75-1.el8.aa | 75-1.el8.aa |
redhat/osbuild-composer-worker-debuginfo | <75-1.el8.aa | 75-1.el8.aa |
redhat/weldr-client | <35.9-2.el8.aa | 35.9-2.el8.aa |
redhat/weldr-client-debuginfo | <35.9-2.el8.aa | 35.9-2.el8.aa |
redhat/weldr-client-debugsource | <35.9-2.el8.aa | 35.9-2.el8.aa |
redhat/weldr-client-tests-debuginfo | <35.9-2.el8.aa | 35.9-2.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:2780 is classified as high due to the unbounded memory consumption vulnerability described in CVE-2022-2879.
To fix RHSA-2023:2780, you should update the affected packages to their recommended versions as specified in the advisory.
RHSA-2023:2780 affects several packages including cockpit-composer, osbuild, osbuild-composer, and weldr-client among others.
RHSA-2023:2780 addresses the unbounded memory consumption issue identified by CVE-2022-2879.
There are no specific workarounds for RHSA-2023:2780; the recommended solution is to apply the update provided.