Bug 2279361 (CVE-2024-4437)

Summary: CVE-2024-4437 etcd: Incomplete fix for CVE-2021-44716 in OpenStack Platform
Product: [Other] Security Response Reporter: Marco Benatto <mbenatto>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abishop, eglynn, jjoyce, jschluet, lhh, lsvaty, mburns, mgarciac, pgrist
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Go 1.17.5, Go 1.16.12 Doc Type: ---
Doc Text:
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2279362, 2279363, 2279364    
Bug Blocks: 2279354    

Description Marco Benatto 2024-05-06 17:21:05 UTC
The etcd package distributed with Red Hat OpenStack platform has been identified to have an incomplete fix for CVE-2021-44716. This happens because the etcd package in Red Hat OpenStack platform is using the http://golang.org/x/net/http2 instead the one provided by the Red Hat Enterprise linux versions, meaning it should be updated at compile time instead

Comment 2 errata-xmlrpc 2024-05-23 15:26:10 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2024:3352 https://access.redhat.com/errata/RHSA-2024:3352

Comment 3 errata-xmlrpc 2024-05-29 13:31:01 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.1

Via RHSA-2024:3467 https://access.redhat.com/errata/RHSA-2024:3467