Bug 2242803 (CVE-2023-44487)
Summary: | CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sandipan Roy <saroy> |
Component: | vulnerability | Assignee: | Sayan Biswas <sabiswas> |
Status: | MODIFIED --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | aazores, abarbaro, abishop, adudiak, adupliak, agarcial, ahanwate, aileenc, akostadi, alcohan, amasferr, amctagga, andrew.slice, anjoseph, ansmith, anstephe, aoconnor, aogburn, aprice, asatyam, asegurap, asoldano, ataylor, avibelli, bbaranow, bbuckingham, bcourt, bdettelb, bgeorges, bmaxwell, bniver, bodavis, boliveir, brian.stansberry, brking, caswilli, cbartlet, ccranfor, cdaley, cdewolf, chazlett, chfoley, clement.escoffier, cmah, cmiranda, cmoulliard, csutherl, dandread, danken, darran.lofthouse, davidn, dbenoit, dbhole, dcadzow, debarshir, dfreiber, dhanak, diagrawa, dkenigsb, dkreling, dkuc, dmayorov, doconnor, dosoudil, dperaza, drichtar, drow, dsimansk, dymurray, eaguilar, ebaron, ecerquei, eglynn, ehelms, emachado, epacific, eric.wittmann, fdeutsch, fdupont, fjansen, fjuma, flucifre, fmariani, fmongiar, ggainey, ggastald, ggrzybek, gkamathe, gmalinko, gmeno, gparvin, gsmet, haoli, hhorak, hkataria, ibek, ibolton, ikanello, istudens, ivassile, iweiss, jaharrin, jajackso, jamacku, janstey, jburrell, jcammara, jcantril, jchui, jclere, jdobes, jeder, jforrest, jhardy, jhe, jjoyce, jkang, jkoehler, jkoops, jlledo, jmartisk, jmatthew, jmitchel, jmontleo, jneedle, jnethert, jobarker, jolong, jorton, jpallich, jpechane, jpoth, jprabhak, jrokos, jross, jsamir, jschluet, jscholz, jsherril, jtanner, juwatts, jwendell, kaycoth, kegrant, kholdawa, kingland, koliveir, kshier, ktsao, kverlaen, lball, lchilton, lcouzens, lgamliel, lgao, lhh, lmadsen, lphiri, lsvaty, lthon, luhliari, luizcosta, lzap, mabashia, manderse, matzew, max.andersen, mbenjamin, mbocek, mburns, mcressma, mgarciac, mhackett, mhulan, mkleinhe, mkudlej, mmadzin, mmagr, mmakovy, mnewsome, mnovotny, mosmerov, mpierce, mrajanna, mresvani, mrunge, mskarbek, msochure, mstefank, msvehla, mulliken, mwringe, nboldt, nipatil, njean, nmoumoul, nobody, nodejs-maint, nwallace, nweather, odf-bz-bot, oezr, olubyans, omaciel, omajid, orabin, oramraz, owatkins, pahickey, pajung, pantinor, pbraun, pcongius, pcreech, pdelbell, pdrozd, pdwyer, peholase, pesilva, pgaikwad, pgallagh, pgrist, pierdipi, pjindal, plodge, pmackay, probinso, psegedy, pskopek, psrna, rblanco, rcernich, rchan, rfreiman, rguimara, rhaigner, rhos-maint, rhuss, rjohnson, rkieley, rkubis, rmartinc, rogbas, rojacob, rowaters, rruss, rstancel, rstepani, rsvoboda, sakbas, saroy, sausingh, sbiarozk, sbroz, sdawley, security-response-team, sfeifer, sfroberg, sgott, shbose, shvarugh, simaishi, sipoyare, slucidi, smaestri, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, sthirugn, sthorger, stirabos, swoodman, szappis, tcarlin, tcunning, teagle, tfister, thason, thavo, tjochec, tkasparek, tkral, tom.jenkinson, tqvarnst, trathi, twalsh, vereddy, vimartin, vkrizan, vkumar, vmugicag, vsroka, whayutin, wtam, yfang, yguenane, zmiele, zsadeh |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | golang 1.21.3, golang 1.20.10, tomcat 11.0.0-m12, tomcat 10.1.14, tomcat 9.0.81, tomcat 8.5.94, nghttp2 1.57.0, netty 4.1.100.Final | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit.
CVE-2023-39325 was assigned for the Rapid Reset Attack in the Go language packages.
Security Bulletin
https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2243237, 2243238, 2243239, 2243240, 2243324, 2246204, 2242817, 2243126, 2243127, 2243212, 2243219, 2243220, 2243221, 2243222, 2243223, 2243224, 2243227, 2243242, 2243243, 2243247, 2243248, 2243249, 2243250, 2243251, 2243252, 2243253, 2243278, 2243280, 2243281, 2243320, 2243321, 2243322, 2243323, 2243325, 2243326, 2243327, 2243328, 2243329, 2243330, 2243331, 2243347, 2243348, 2243350, 2243353, 2243354, 2243355, 2243356, 2243357, 2243358, 2243359, 2243360, 2243362, 2243363, 2243364, 2243365, 2243366, 2243367, 2243368, 2243369, 2243370, 2243371, 2243372, 2243374, 2243375, 2243376, 2243377, 2243399, 2243470, 2243471, 2243472, 2243473, 2243502, 2243503, 2243504, 2243505, 2243534, 2243535, 2243536, 2243537, 2243550, 2243551, 2243552, 2243553, 2243558, 2243559, 2243560, 2243561, 2243562, 2243564, 2243576, 2243582, 2243605, 2243611, 2243612, 2243613, 2243641, 2243663, 2243696, 2243832, 2243833, 2243834, 2243837, 2243838, 2243890, 2243891, 2243892, 2243893, 2243894, 2243895, 2244166, 2245036, 2245037, 2245039, 2245040, 2245101, 2246197, 2246198, 2246199, 2246200, 2246201, 2246202, 2246203, 2246205, 2246206, 2246208, 2246209, 2246210, 2246211, 2246295 | ||
Bug Blocks: | 2243139 |
Description
Sandipan Roy
2023-10-09 04:47:38 UTC
Created dotnet6.0 tracking bugs for this issue: Affects: fedora-all [bug 2243127] Created dotnet7.0 tracking bugs for this issue: Affects: fedora-all [bug 2243126] Created flatbuffers tracking bugs for this issue: Affects: fedora-37 [bug 2243249] Created grpc tracking bugs for this issue: Affects: fedora-all [bug 2243250] Created httpd tracking bugs for this issue: Affects: fedora-all [bug 2243247] Created mod_http2 tracking bugs for this issue: Affects: fedora-all [bug 2243248] Created proxygen tracking bugs for this issue: Affects: fedora-all [bug 2243253] Created trafficserver tracking bugs for this issue: Affects: epel-all [bug 2243251] Affects: fedora-all [bug 2243252] Created etcd tracking bugs for this issue: Affects: fedora-all [bug 2243321] Created grpc tracking bugs for this issue: Affects: openstack-rdo [bug 2243320] Created jetty tracking bugs for this issue: Affects: fedora-all [bug 2243327] Created nghttp2 tracking bugs for this issue: Affects: epel-all [bug 2243323] Affects: fedora-all [bug 2243322] Created nginx tracking bugs for this issue: Affects: fedora-all [bug 2243326] Created nodejs tracking bugs for this issue: Affects: epel-all [bug 2243324] Affects: fedora-all [bug 2243325] Created varnish tracking bugs for this issue: Affects: epel-all [bug 2243331] Affects: fedora-all [bug 2243328] Created varnish-modules tracking bugs for this issue: Affects: fedora-all [bug 2243329] Created varnish:6.0/varnish tracking bugs for this issue: Affects: fedora-all [bug 2243330] Created godot tracking bugs for this issue: Affects: epel-all [bug 2243611] Created libsoup3 tracking bugs for this issue: Affects: fedora-all [bug 2243612] Created tomcat tracking bugs for this issue: Affects: fedora-all [bug 2243613] This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2023:5705 https://access.redhat.com/errata/RHSA-2023:5705 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5706 https://access.redhat.com/errata/RHSA-2023:5706 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5707 https://access.redhat.com/errata/RHSA-2023:5707 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5710 https://access.redhat.com/errata/RHSA-2023:5710 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5708 https://access.redhat.com/errata/RHSA-2023:5708 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5711 https://access.redhat.com/errata/RHSA-2023:5711 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5714 https://access.redhat.com/errata/RHSA-2023:5714 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5715 https://access.redhat.com/errata/RHSA-2023:5715 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5709 https://access.redhat.com/errata/RHSA-2023:5709 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5712 https://access.redhat.com/errata/RHSA-2023:5712 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5713 https://access.redhat.com/errata/RHSA-2023:5713 This issue has been addressed in the following products: Red Hat Developer Tools Via RHSA-2023:5719 https://access.redhat.com/errata/RHSA-2023:5719 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:5720 https://access.redhat.com/errata/RHSA-2023:5720 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5721 https://access.redhat.com/errata/RHSA-2023:5721 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5738 https://access.redhat.com/errata/RHSA-2023:5738 This issue has been addressed in the following products: Red Hat Data Grid 8.4.5 Via RHSA-2023:5716 https://access.redhat.com/errata/RHSA-2023:5716 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5749 https://access.redhat.com/errata/RHSA-2023:5749 This issue has been addressed in the following products: Red Hat build of Quarkus 2.13.8 Via RHSA-2023:5724 https://access.redhat.com/errata/RHSA-2023:5724 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5764 https://access.redhat.com/errata/RHSA-2023:5764 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Via RHSA-2023:5766 https://access.redhat.com/errata/RHSA-2023:5766 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5765 https://access.redhat.com/errata/RHSA-2023:5765 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2023:5767 https://access.redhat.com/errata/RHSA-2023:5767 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2023:5768 https://access.redhat.com/errata/RHSA-2023:5768 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5770 https://access.redhat.com/errata/RHSA-2023:5770 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5769 https://access.redhat.com/errata/RHSA-2023:5769 This issue has been addressed in the following products: Red Hat Integration Via RHSA-2023:5780 https://access.redhat.com/errata/RHSA-2023:5780 This issue has been addressed in the following products: Red Hat JBoss Web Server 5.7 on RHEL 7 Red Hat JBoss Web Server 5.7 on RHEL 8 Red Hat JBoss Web Server 5.7 on RHEL 9 Via RHSA-2023:5783 https://access.redhat.com/errata/RHSA-2023:5783 This issue has been addressed in the following products: Red Hat JBoss Web Server Via RHSA-2023:5784 https://access.redhat.com/errata/RHSA-2023:5784 This issue has been addressed in the following products: Migration Toolkit for Runtimes 1 on RHEL 8 Via RHSA-2023:5802 https://access.redhat.com/errata/RHSA-2023:5802 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5803 https://access.redhat.com/errata/RHSA-2023:5803 This issue has been addressed in the following products: Migration Toolkit for Runtimes 1 on RHEL 8 Via RHSA-2023:5801 https://access.redhat.com/errata/RHSA-2023:5801 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 8 Red Hat Ansible Automation Platform 2.4 for RHEL 9 Via RHSA-2023:5805 https://access.redhat.com/errata/RHSA-2023:5805 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2023:5679 https://access.redhat.com/errata/RHSA-2023:5679 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2023:5835 https://access.redhat.com/errata/RHSA-2023:5835 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5837 https://access.redhat.com/errata/RHSA-2023:5837 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5838 https://access.redhat.com/errata/RHSA-2023:5838 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:5840 https://access.redhat.com/errata/RHSA-2023:5840 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:5841 https://access.redhat.com/errata/RHSA-2023:5841 RHEL9 advisory: https://access.redhat.com/errata/RHSA-2023:5738 Fixed in package: golang-1.19.13-1.el9_2.x86_64.rpm New base image rhel9/go-toolset:1.19.13-4 contains rpm golang-1.19.13-1.el9_2.x86_64. $âž” podman run -it --rm --entrypoint /bin/bash --user root registry.redhat.io/rhel9/go-toolset:1.19.13-4 -c "go version; rpm -qa | grep golang-" go version go1.19.13 linux/amd64 golang-src-1.19.13-1.el9_2.noarch golang-bin-1.19.13-1.el9_2.x86_64 golang-1.19.13-1.el9_2.x86_64 There have been a handful of other CVE fixes since the above release: https://catalog.redhat.com/software/containers/rhel9/go-toolset/61df08166d9a1b7b2aab2344/history?0=a&1=m&2=d&3=6&4=4 --- RHEL8 advisory: https://access.redhat.com/errata/RHSA-2023:5721 Fixed in package: golang-1.19.13-1.module+el8.8.0+20373+d9cd605c New base image rhel8/go-toolset:1.19.13-2 @ https://catalog.redhat.com/software/containers/rhel8/go-toolset/5b9c810add19c70b45cbd666 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:5717 https://access.redhat.com/errata/RHSA-2023:5717 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5849 https://access.redhat.com/errata/RHSA-2023:5849 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5850 https://access.redhat.com/errata/RHSA-2023:5850 This issue has been addressed in the following products: RHACS-4.1-RHEL-8 Via RHSA-2023:5851 https://access.redhat.com/errata/RHSA-2023:5851 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:5864 https://access.redhat.com/errata/RHSA-2023:5864 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5866 https://access.redhat.com/errata/RHSA-2023:5866 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2023:5865 https://access.redhat.com/errata/RHSA-2023:5865 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5867 https://access.redhat.com/errata/RHSA-2023:5867 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5863 https://access.redhat.com/errata/RHSA-2023:5863 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5869 https://access.redhat.com/errata/RHSA-2023:5869 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2023:5920 https://access.redhat.com/errata/RHSA-2023:5920 This issue has been addressed in the following products: EAP 7.4 async for CVE-2023-44487 (Rapid Reset) Via RHSA-2023:5922 https://access.redhat.com/errata/RHSA-2023:5922 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5924 https://access.redhat.com/errata/RHSA-2023:5924 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5930 https://access.redhat.com/errata/RHSA-2023:5930 This issue has been addressed in the following products: Red Hat Satellite 6.13 for RHEL 8 Via RHSA-2023:5931 https://access.redhat.com/errata/RHSA-2023:5931 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:5929 https://access.redhat.com/errata/RHSA-2023:5929 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5928 https://access.redhat.com/errata/RHSA-2023:5928 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2023:5935 https://access.redhat.com/errata/RHSA-2023:5935 This issue has been addressed in the following products: Red Hat JBoss AMQ Via RHSA-2023:5945 https://access.redhat.com/errata/RHSA-2023:5945 This issue has been addressed in the following products: Red Hat JBoss AMQ Via RHSA-2023:5946 https://access.redhat.com/errata/RHSA-2023:5946 This issue has been addressed in the following products: RHOL-5.6-RHEL-8 Via RHSA-2023:5541 https://access.redhat.com/errata/RHSA-2023:5541 This issue has been addressed in the following products: RHOL-5.7-RHEL-8 Via RHSA-2023:5530 https://access.redhat.com/errata/RHSA-2023:5530 This issue has been addressed in the following products: RHBOP 8.38.0 SP2 Via RHSA-2023:5956 https://access.redhat.com/errata/RHSA-2023:5956 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 Via RHSA-2023:5969 https://access.redhat.com/errata/RHSA-2023:5969 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 Via RHSA-2023:5971 https://access.redhat.com/errata/RHSA-2023:5971 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2023:5965 https://access.redhat.com/errata/RHSA-2023:5965 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2023:5964 https://access.redhat.com/errata/RHSA-2023:5964 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 Via RHSA-2023:5970 https://access.redhat.com/errata/RHSA-2023:5970 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2023:5967 https://access.redhat.com/errata/RHSA-2023:5967 This issue has been addressed in the following products: Red Hat AMQ Streams 2.5.1 Via RHSA-2023:5973 https://access.redhat.com/errata/RHSA-2023:5973 This issue has been addressed in the following products: NETWORK-OBSERVABILITY-1.4.0-RHEL-9 Via RHSA-2023:5974 https://access.redhat.com/errata/RHSA-2023:5974 This issue has been addressed in the following products: STF-1.5-RHEL-8 Via RHSA-2023:5976 https://access.redhat.com/errata/RHSA-2023:5976 This issue has been addressed in the following products: EAP-XP 4.0.0 on EAP 7.4.13 Via RHSA-2023:5978 https://access.redhat.com/errata/RHSA-2023:5978 This issue has been addressed in the following products: Red Hat Satellite 6.12 for RHEL 8 Via RHSA-2023:5979 https://access.redhat.com/errata/RHSA-2023:5979 This issue has been addressed in the following products: Red Hat Satellite 6.11 for RHEL 7 Red Hat Satellite 6.11 for RHEL 8 Via RHSA-2023:5980 https://access.redhat.com/errata/RHSA-2023:5980 This issue has been addressed in the following products: Satellite Client 6 for RHEL 6 Satellite Client 6 for RHEL 7 Satellite Client 6 for RHEL 8 Satellite Client 6 for RHEL 9 Via RHSA-2023:5982 https://access.redhat.com/errata/RHSA-2023:5982 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5989 https://access.redhat.com/errata/RHSA-2023:5989 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Via RHSA-2023:6023 https://access.redhat.com/errata/RHSA-2023:6023 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2023:6022 https://access.redhat.com/errata/RHSA-2023:6022 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2023:6021 https://access.redhat.com/errata/RHSA-2023:6021 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:6020 https://access.redhat.com/errata/RHSA-2023:6020 This issue has been addressed in the following products: Red Hat AMQ Streams 2.2.2 Via RHSA-2023:6030 https://access.redhat.com/errata/RHSA-2023:6030 This issue has been addressed in the following products: Cryostat 2 on RHEL 8 Via RHSA-2023:6031 https://access.redhat.com/errata/RHSA-2023:6031 This issue has been addressed in the following products: Node Maintenance Operator 5.0 for RHEL 8 Via RHSA-2023:6039 https://access.redhat.com/errata/RHSA-2023:6039 This issue has been addressed in the following products: Self Node Remediation 0.7 for RHEL 8 Via RHSA-2023:6041 https://access.redhat.com/errata/RHSA-2023:6041 This issue has been addressed in the following products: Cost Management for RHEL 8 Via RHSA-2023:6044 https://access.redhat.com/errata/RHSA-2023:6044 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.2 Via RHSA-2023:6048 https://access.redhat.com/errata/RHSA-2023:6048 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:6057 https://access.redhat.com/errata/RHSA-2023:6057 This issue has been addressed in the following products: OpenShift-Pipelines-1.12-RHEL-8 Via RHSA-2023:6059 https://access.redhat.com/errata/RHSA-2023:6059 This issue has been addressed in the following products: OpenShift-Pipelines-1.12-RHEL-8 Via RHSA-2023:6061 https://access.redhat.com/errata/RHSA-2023:6061 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:5902 https://access.redhat.com/errata/RHSA-2023:5902 This issue has been addressed in the following products: RHOL-5.5-RHEL-8 Via RHSA-2023:5542 https://access.redhat.com/errata/RHSA-2023:5542 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6077 https://access.redhat.com/errata/RHSA-2023:6077 This issue has been addressed in the following products: RHINT Camel-Springboot 3.20.3 Via RHSA-2023:6079 https://access.redhat.com/errata/RHSA-2023:6079 This issue has been addressed in the following products: RHINT Camel-Springboot 4.0.1 Via RHSA-2023:6080 https://access.redhat.com/errata/RHSA-2023:6080 This issue has been addressed in the following products: RHACS-3.74-RHEL-8 Via RHSA-2023:6084 https://access.redhat.com/errata/RHSA-2023:6084 This issue has been addressed in the following products: Red Hat Openshift distributed tracing 2.9 Via RHSA-2023:6085 https://access.redhat.com/errata/RHSA-2023:6085 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2023:5896 https://access.redhat.com/errata/RHSA-2023:5896 This issue has been addressed in the following products: OADP-1.1-RHEL-8 Via RHSA-2023:6115 https://access.redhat.com/errata/RHSA-2023:6115 This issue has been addressed in the following products: RHINT Camel-K-1.10.4 Via RHSA-2023:6117 https://access.redhat.com/errata/RHSA-2023:6117 This issue has been addressed in the following products: OADP-1.2-RHEL-8 Via RHSA-2023:6118 https://access.redhat.com/errata/RHSA-2023:6118 This issue has been addressed in the following products: Spring Boot 2.7.17 Via RHSA-2023:6114 https://access.redhat.com/errata/RHSA-2023:6114 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6120 https://access.redhat.com/errata/RHSA-2023:6120 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.3 for RHEL 8 Via RHSA-2023:6119 https://access.redhat.com/errata/RHSA-2023:6119 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.8 for RHEL 8 Via RHSA-2023:6122 https://access.redhat.com/errata/RHSA-2023:6122 This issue has been addressed in the following products: RODOO-1.0-RHEL-8 Via RHSA-2023:5947 https://access.redhat.com/errata/RHSA-2023:5947 This issue has been addressed in the following products: OSSO-1.1-RHEL-8 Via RHSA-2023:5933 https://access.redhat.com/errata/RHSA-2023:5933 This issue has been addressed in the following products: Migration Toolkit for Runtimes 1 on RHEL 8 Via RHSA-2023:6137 https://access.redhat.com/errata/RHSA-2023:6137 This issue has been addressed in the following products: JBCS httpd 2.4.57 SP1 Via RHSA-2023:6106 https://access.redhat.com/errata/RHSA-2023:6106 This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2023:6105 https://access.redhat.com/errata/RHSA-2023:6105 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.2 for RHEL 8 Via RHSA-2023:6145 https://access.redhat.com/errata/RHSA-2023:6145 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 Via RHSA-2023:6148 https://access.redhat.com/errata/RHSA-2023:6148 This issue has been addressed in the following products: OpenShift Custom Metrics Autoscaler 2 Via RHSA-2023:6144 https://access.redhat.com/errata/RHSA-2023:6144 This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.7 Via RHSA-2023:6161 https://access.redhat.com/errata/RHSA-2023:6161 This issue has been addressed in the following products: Service Interconnect 1 for RHEL 8 Service Interconnect 1 for RHEL 9 Via RHSA-2023:6165 https://access.redhat.com/errata/RHSA-2023:6165 This issue has been addressed in the following products: OpenShift Developer Tools and Services for OCP 4.13 Via RHSA-2023:6179 https://access.redhat.com/errata/RHSA-2023:6179 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:6129 https://access.redhat.com/errata/RHSA-2023:6129 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.1 for RHEL 8 Via RHSA-2023:6200 https://access.redhat.com/errata/RHSA-2023:6200 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 Via RHSA-2023:6202 https://access.redhat.com/errata/RHSA-2023:6202 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:5006 https://access.redhat.com/errata/RHSA-2023:5006 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:5009 https://access.redhat.com/errata/RHSA-2023:5009 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:6217 https://access.redhat.com/errata/RHSA-2023:6217 This issue has been addressed in the following products: OSSO-1.2-RHEL-8 Via RHSA-2023:6154 https://access.redhat.com/errata/RHSA-2023:6154 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2023:6233 https://access.redhat.com/errata/RHSA-2023:6233 This issue has been addressed in the following products: RHEL-9-CNV-4.13 Via RHSA-2023:6235 https://access.redhat.com/errata/RHSA-2023:6235 This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.4 for RHEL 8 Via RHSA-2023:6239 https://access.redhat.com/errata/RHSA-2023:6239 This issue has been addressed in the following products: RHEL-8-CNV-4.12 Via RHSA-2023:6248 https://access.redhat.com/errata/RHSA-2023:6248 This issue has been addressed in the following products: RHEL-8-CNV-4.11 Via RHSA-2023:6251 https://access.redhat.com/errata/RHSA-2023:6251 This issue has been addressed in the following products: MTA-6.2-RHEL-9 MTA-6.2-RHEL-8 Via RHSA-2023:6280 https://access.redhat.com/errata/RHSA-2023:6280 This issue has been addressed in the following products: Red Hat Data Grid 7.3.11 Via RHSA-2023:6286 https://access.redhat.com/errata/RHSA-2023:6286 This issue has been addressed in the following products: Red Hat OpenShift Serverless 1.30 Via RHSA-2023:6296 https://access.redhat.com/errata/RHSA-2023:6296 This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2023:6298 https://access.redhat.com/errata/RHSA-2023:6298 This issue has been addressed in the following products: MTA-6.1-RHEL-8 Via RHSA-2023:6305 https://access.redhat.com/errata/RHSA-2023:6305 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6746 https://access.redhat.com/errata/RHSA-2023:6746 This issue has been addressed in the following products: OpenShift-Pipelines-1.11-RHEL-8 Via RHSA-2023:6779 https://access.redhat.com/errata/RHSA-2023:6779 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.8 Via RHSA-2023:6782 https://access.redhat.com/errata/RHSA-2023:6782 This issue has been addressed in the following products: OpenShift-Pipelines-1.11-RHEL-8 Via RHSA-2023:6781 https://access.redhat.com/errata/RHSA-2023:6781 This issue has been addressed in the following products: Node Healthcheck Operator 0.4 for RHEL 8 Via RHSA-2023:6783 https://access.redhat.com/errata/RHSA-2023:6783 This issue has been addressed in the following products: Node Healthcheck Operator 0.6 for RHEL 8 Via RHSA-2023:6784 https://access.redhat.com/errata/RHSA-2023:6784 This issue has been addressed in the following products: Machine Deletion Remediation 0.2 for RHEL 8 Via RHSA-2023:6785 https://access.redhat.com/errata/RHSA-2023:6785 This issue has been addressed in the following products: Fence Agents Remediation 0.2 for RHEL 8 Via RHSA-2023:6786 https://access.redhat.com/errata/RHSA-2023:6786 This issue has been addressed in the following products: NETWORK-OBSERVABILITY-1.4.0-RHEL-9 Via RHSA-2023:6787 https://access.redhat.com/errata/RHSA-2023:6787 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.8 Via RHSA-2023:6788 https://access.redhat.com/errata/RHSA-2023:6788 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:6272 https://access.redhat.com/errata/RHSA-2023:6272 This issue has been addressed in the following products: RHEL-9-CNV-4.14 Via RHSA-2023:6817 https://access.redhat.com/errata/RHSA-2023:6817 This issue has been addressed in the following products: Red Hat Satellite 6.14 for RHEL 8 Via RHSA-2023:6818 https://access.redhat.com/errata/RHSA-2023:6818 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2023:6832 https://access.redhat.com/errata/RHSA-2023:6832 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7205 https://access.redhat.com/errata/RHSA-2023:7205 This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.2 for RHEL 8 Via RHSA-2023:7215 https://access.redhat.com/errata/RHSA-2023:7215 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:6836 https://access.redhat.com/errata/RHSA-2023:6836 This issue has been addressed in the following products: KMM-1.1-RHEL-9 Via RHSA-2023:7218 https://access.redhat.com/errata/RHSA-2023:7218 This issue has been addressed in the following products: CERT-MANAGER-1.12-RHEL-9 Via RHSA-2023:6269 https://access.redhat.com/errata/RHSA-2023:6269 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:6837 https://access.redhat.com/errata/RHSA-2023:6837 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:6840 https://access.redhat.com/errata/RHSA-2023:6840 This issue has been addressed in the following products: Red Hat Fuse 7.12.1 Via RHSA-2023:7247 https://access.redhat.com/errata/RHSA-2023:7247 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:6839 https://access.redhat.com/errata/RHSA-2023:6839 This issue has been addressed in the following products: OpenShift Developer Tools and Services for OCP 4.14 Via RHSA-2023:7288 https://access.redhat.com/errata/RHSA-2023:7288 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:7334 https://access.redhat.com/errata/RHSA-2023:7334 This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2023:7335 https://access.redhat.com/errata/RHSA-2023:7335 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.9 Via RHSA-2023:7344 https://access.redhat.com/errata/RHSA-2023:7344 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.9 Via RHSA-2023:7345 https://access.redhat.com/errata/RHSA-2023:7345 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:7315 https://access.redhat.com/errata/RHSA-2023:7315 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Ironic content for Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:7325 https://access.redhat.com/errata/RHSA-2023:7325 This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 9 Via RHSA-2023:7484 https://access.redhat.com/errata/RHSA-2023:7484 This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 7 Via RHSA-2023:7482 https://access.redhat.com/errata/RHSA-2023:7482 This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 8 Via RHSA-2023:7483 https://access.redhat.com/errata/RHSA-2023:7483 This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2023:7486 https://access.redhat.com/errata/RHSA-2023:7486 This issue has been addressed in the following products: Red Hat Single Sign-On Via RHSA-2023:7488 https://access.redhat.com/errata/RHSA-2023:7488 This issue has been addressed in the following products: RHEL-9-CNV-4.13 RHEL-7-CNV-4.13 RHEL-8-CNV-4.13 Via RHSA-2023:7521 https://access.redhat.com/errata/RHSA-2023:7521 This issue has been addressed in the following products: RHEL-9-CNV-4.13 Via RHSA-2023:7522 https://access.redhat.com/errata/RHSA-2023:7522 This issue has been addressed in the following products: OADP-1.3-RHEL-9 Via RHSA-2023:7555 https://access.redhat.com/errata/RHSA-2023:7555 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:7481 https://access.redhat.com/errata/RHSA-2023:7481 This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2023:7587 https://access.redhat.com/errata/RHSA-2023:7587 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2023:7639 https://access.redhat.com/errata/RHSA-2023:7639 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2023:7637 https://access.redhat.com/errata/RHSA-2023:7637 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2023:7638 https://access.redhat.com/errata/RHSA-2023:7638 This issue has been addressed in the following products: EAP 7.4.14 Via RHSA-2023:7641 https://access.redhat.com/errata/RHSA-2023:7641 This issue has been addressed in the following products: RHINT Service Registry 2.5.4 GA Via RHSA-2023:7653 https://access.redhat.com/errata/RHSA-2023:7653 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Ironic content for Red Hat OpenShift Container Platform 4.12 Via RHSA-2023:7610 https://access.redhat.com/errata/RHSA-2023:7610 This issue has been addressed in the following products: OpenShift-Pipelines-1.10-RHEL-8 Via RHSA-2023:7699 https://access.redhat.com/errata/RHSA-2023:7699 This issue has been addressed in the following products: OpenShift-Pipelines-1.10-RHEL-8 Via RHSA-2023:7703 https://access.redhat.com/errata/RHSA-2023:7703 This issue has been addressed in the following products: RHEL-9-CNV-4.14 Via RHSA-2023:7704 https://access.redhat.com/errata/RHSA-2023:7704 This issue has been addressed in the following products: Red Hat Ceph Storage 6.1 Via RHSA-2023:7741 https://access.redhat.com/errata/RHSA-2023:7741 This issue has been addressed in the following products: OpenShift Developer Tools and Services for OCP 4.14 Via RHSA-2024:0777 https://access.redhat.com/errata/RHSA-2024:0777 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2023:7198 https://access.redhat.com/errata/RHSA-2023:7198 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2023:7201 https://access.redhat.com/errata/RHSA-2023:7201 This issue has been addressed in the following products: RODOO-1.1-RHEL-9 Via RHSA-2024:0269 https://access.redhat.com/errata/RHSA-2024:0269 This issue has been addressed in the following products: KDO-5.0-RHEL-9 Via RHSA-2024:0302 https://access.redhat.com/errata/RHSA-2024:0302 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1444 https://access.redhat.com/errata/RHSA-2024:1444 Marking EAP-8 as not affected because EAP 8 GA was released with the fixed version. This issue has been addressed in the following products: Red Hat Ceph Storage 6.1 Via RHSA-2024:2633 https://access.redhat.com/errata/RHSA-2024:2633 This issue has been addressed in the following products: RHEL-9-CNV-4.18 Via RHSA-2025:1838 https://access.redhat.com/errata/RHSA-2025:1838 This issue has been addressed in the following products: Red Hat AMQ Streams 2.5.2 Via RHSA-2024:6536 https://access.redhat.com/errata/RHSA-2024:6536 |