RHSA-2023:5976: Important: Service Telemetry Framework 1.5.2 security update
Important: Service Telemetry Framework 1.5.2 security update
Other sources
Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724) golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results (CVE-2023-24532) golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534) golang: net/http: insufficient sanitization of Host header (CVE-2023-29406) golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5976?
The severity of RHSA-2023:5976 is high with a severity value of 7.
How do I fix RHSA-2023:5976?
To fix RHSA-2023:5976, install the Service Telemetry Framework 1.5.2 security update from Red Hat.
Which software is affected by RHSA-2023:5976?
Red Hat OpenStack is affected by RHSA-2023:5976.
Where can I find more information about RHSA-2023:5976?
You can find more information about RHSA-2023:5976 on the Red Hat Bugzilla website. (Reference links: [Bug 2178492](https://bugzilla.redhat.com/show_bug.cgi?id=2178492), [Bug 2184483](https://bugzilla.redhat.com/show_bug.cgi?id=2184483), [Bug 2222167](https://bugzilla.redhat.com/show_bug.cgi?id=2222167))