RHSA-2024:2728: Important: Red Hat OpenStack Platform 17.1 director Operator container images security update
Important: Red Hat OpenStack Platform 17.1 director Operator container images security update
Other sources
Red Hat OpenStack Platform provides the facilities for building, deploying and monitoring a private or public infrastructure-as-a-service (IaaS) cloud running on commonly available physical hardware.<br>The Red Hat OpenStack Platform (RHOSP) director Operator adds the ability to install and run a RHOSP cloud within OpenShift Container Platform.<br>Security Fix(es):<br><li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> golang: x/crypto/ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2728?
The severity of RHSA-2024:2728 is classified as important.
How do I fix RHSA-2024:2728?
To fix RHSA-2024:2728, you should update the Red Hat OpenStack Platform to the latest container images provided in the advisory.
Which versions of Red Hat OpenStack are affected by RHSA-2024:2728?
RHSA-2024:2728 affects Red Hat OpenStack Platform 17.1 director Operator container images.
What vulnerabilities are addressed in RHSA-2024:2728?
RHSA-2024:2728 addresses security vulnerabilities related to the Red Hat OpenStack Platform container images.
Is it mandatory to apply the RHSA-2024:2728 update?
While not legally mandatory, applying the RHSA-2024:2728 update is highly recommended to ensure the security and stability of your OpenStack deployment.