RHSA-2024:7994: Important: Red Hat Advanced Cluster Management 2.11.3 bug fixes and container updates
Important: Red Hat Advanced Cluster Management 2.11.3 bug fixes and container updates
Other sources
Red Hat Advanced Cluster Management for Kubernetes 2.11.3 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/</a> Security fix(es):<br>nodejs/elliptic: EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended (CVE-2024-42459) <br>nodejs/elliptic: ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero (CVE-2024-42460) <br>nodejs/elliptic: ECDSA implementation malleability due to BER-enconded signatures being allowed (CVE-2024-42461)<br>CVE-2024-48949 Missing Validation in Elliptic's EDDSA Signature Verification
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:7994?
The severity of RHSA-2024:7994 is classified as Important.
What vulnerabilities are addressed in RHSA-2024:7994?
RHSA-2024:7994 addresses bug fixes and container updates for Red Hat Advanced Cluster Management for Kubernetes.
How do I update Red Hat Advanced Cluster Management to resolve RHSA-2024:7994?
You can resolve RHSA-2024:7994 by updating your Red Hat Advanced Cluster Management for Kubernetes to version 2.11.3.
Is RHSA-2024:7994 applicable to all versions of Red Hat Advanced Cluster Management?
RHSA-2024:7994 is specifically applicable to Red Hat Advanced Cluster Management for Kubernetes version 2.11.3.
Where can I find more information on RHSA-2024:7994?
For more information, you can refer to the Red Hat security advisory for RHSA-2024:7994.