RHSA-2024:8546: Important: Red Hat Advanced Cluster Management 2.9.5 bug fixes and container updates
Important: Red Hat Advanced Cluster Management 2.9.5 bug fixes and container updates
Other sources
Red Hat Advanced Cluster Management for Kubernetes 2.9.5 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console, with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated for this<br>release, for additional details:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.9/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.9/html/releasenotes/</a> Security fix(es):<br>nodejs/elliptic: EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended (CVE-2024-42459)<br>nodejs/elliptic: ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero (CVE-2024-42460)<br>nodejs/elliptic: ECDSA implementation malleability due to BER-enconded signatures being allowed (CVE-2024-42461)<br>Missing Validation in Elliptic's EDDSA Signature Verification (CVE-2024-48949)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8546?
The severity of RHSA-2024:8546 is categorized as important.
How do I fix RHSA-2024:8546?
To fix RHSA-2024:8546, you should update your Red Hat Advanced Cluster Management for Kubernetes to version 2.9.5.
What vulnerabilities are addressed in RHSA-2024:8546?
RHSA-2024:8546 addresses several bug fixes and container updates in Red Hat Advanced Cluster Management.
Is RHSA-2024:8546 applicable to all versions of Red Hat Advanced Cluster Management?
RHSA-2024:8546 specifically applies to Red Hat Advanced Cluster Management for Kubernetes version 2.9.5.
What should I do if I cannot update to version 2.9.5 for RHSA-2024:8546?
If you cannot update to version 2.9.5, it is advised to follow Red Hat's recommendations for mitigating risks associated with this vulnerability.