RHSA-2024:2930: Important: logging for Red Hat OpenShift security update
Important: logging for Red Hat OpenShift security update
Other sources
TODO: add package description<br>Security Fix(es):<br><li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2930?
The severity of RHSA-2024:2930 is classified as important.
How do I fix RHSA-2024:2930?
To fix RHSA-2024:2930, update your Logging Subsystem for Red Hat OpenShift to the latest version provided in the advisory.
What vulnerability affects RHSA-2024:2930?
RHSA-2024:2930 addresses a denial-of-service vulnerability caused by unlimited CONTINUATION frames in net/http and x/net/http2 (CVE-2023-45288).
Which products are affected by RHSA-2024:2930?
The affected products include the Logging Subsystem for Red Hat OpenShift on various architectures including IBM Power, ARM 64, and IBM Z.
Is there a workaround for RHSA-2024:2930?
There is no specific workaround for RHSA-2024:2930; applying the necessary updates is recommended.