RHSA-2023:6057: Critical: toolbox security update
Critical: toolbox security update
Other sources
Toolbox is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of Podman and other standard container technologies from OCI.Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:6057?
The severity of RHSA-2023:6057 is critical.
What is the vulnerability addressed by RHSA-2023:6057?
RHSA-2023:6057 addresses a critical vulnerability in the toolbox software.
How can I fix the vulnerability in RHSA-2023:6057?
To fix the vulnerability in RHSA-2023:6057, update the toolbox software to version 0.0.99.3-4.el9_0.
Where can I find more information about RHSA-2023:6057?
You can find more information about RHSA-2023:6057 in the Red Hat Security Advisory (RHSA), Bugzilla reports, and the provided reference links.
What software is affected by RHSA-2023:6057?
The affected software includes Red Hat Enterprise Linux for Power, little endian - Extended Update Support, Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions, Red Hat Enterprise Linux Server for ARM 64 - 4 years of updates, Red Hat Enterprise Linux for x86_64 - Extended Update Support, Red Hat Enterprise Linux for ARM 64 - Extended Update Support, Red Hat Enterprise Linux Server for IBM z Systems - 4 years of updates, and Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions.