RHSA-2024:2767: Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update
Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update
Other sources
This project provides the possibility to switch from the Sensu-based<br>availability monitoring solution to a monitoring solution based on collectd<br>with AMQP-1.0 messaging bus.<br>Security Fix(es):<br><li> Memory leaks in code encrypting and decrypting RSA payloads</li> (CVE-2024-1394)<br><li> net/http/internal: Denial of Service (DoS) via Resource Consumption via</li> HTTP requests (CVE-2023-39326)<br><li> crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.</li> (CVE-2023-45287)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2767?
The severity of RHSA-2024:2767 is marked as important.
How do I fix RHSA-2024:2767?
To fix RHSA-2024:2767, update to the version 0.2.1-3.el8 of the collectd-sensubility package.
What software is affected by RHSA-2024:2767?
RHSA-2024:2767 affects Red Hat OpenStack Platform 17.1 with the collectd-sensubility package.
What changes does RHSA-2024:2767 implement?
RHSA-2024:2767 implements a security update transitioning monitoring solutions to use collectd with AMQP-1.0.
Is there a debug package associated with RHSA-2024:2767?
Yes, there is a debug package, specifically collectd-sensubility-debuginfo, associated with RHSA-2024:2767.