Bug 2279357 (CVE-2024-4436)

Summary: CVE-2024-4436 etcd: Incomplete fix for CVE-2022-41723 in OpenStack Platform
Product: [Other] Security Response Reporter: Marco Benatto <mbenatto>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abishop, eglynn, jjoyce, jschluet, lhh, lsvaty, mburns, mgarciac, pgrist
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: golang.org/x/net 0.7.0, golang 1.20.1, golang 1.19.6 Doc Type: ---
Doc Text:
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2279358, 2279359, 2279360    
Bug Blocks: 2279354    

Description Marco Benatto 2024-05-06 17:16:03 UTC
The etcd package distributed with Red Hat OpenStack platform has been identified to have an incomplete fix for CVE-2022-41723. This happens because the etcd package in Red Hat OpenStack platform is using the http://golang.org/x/net/http2 instead the one provided by the Red Hat Enterprise linux versions, meaning it should be updated at compile time instead.

Comment 3 errata-xmlrpc 2024-05-23 15:26:02 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2024:3352 https://access.redhat.com/errata/RHSA-2024:3352

Comment 4 errata-xmlrpc 2024-05-29 13:31:05 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.1

Via RHSA-2024:3467 https://access.redhat.com/errata/RHSA-2024:3467