A malicious actor can in theory kill / DOS a server in Go instrumented using prometheus/client_golang InstrumentHandlerCounter in the version below 1.11.1. InstrumentHandlerCounter function code: https://github.com/prometheus/client_golang/blob/22da9497b8f0d53072dfc4721904faa7395d8318/prometheus/promhttp/instrument_server.go#L95 Security advisory: https://github.com/prometheus/client_golang/security/advisories/GHSA-cg3q-j54f-5p7p Upstream fix: https://github.com/prometheus/client_golang/commit/9075cdf61646b5adf54d3ba77a0e4f6c65cb4fd7 [main] https://github.com/prometheus/client_golang/commit/989baa30fe956631907493ccee1f8e7708660d96 [release-1.11]
Created buildah tracking bugs for this issue: Affects: fedora-34 [bug 2067357] Created caddy tracking bugs for this issue: Affects: fedora-34 [bug 2067358] Created conmon tracking bugs for this issue: Affects: fedora-34 [bug 2067359] Created cri-o:1.18/cri-o tracking bugs for this issue: Affects: fedora-34 [bug 2067360] Created golang-github-deislabs-oras tracking bugs for this issue: Affects: fedora-34 [bug 2067361] Created golang-github-distribution-3 tracking bugs for this issue: Affects: fedora-34 [bug 2067362] Created golang-github-docker-compose-on-kubernetes tracking bugs for this issue: Affects: fedora-34 [bug 2067363] Created golang-github-docker-distribution tracking bugs for this issue: Affects: fedora-34 [bug 2067364] Created golang-github-hashicorp-consul-sdk tracking bugs for this issue: Affects: fedora-34 [bug 2067365] Created golang-github-hetznercloud-hcloud tracking bugs for this issue: Affects: fedora-34 [bug 2067366] Created golang-github-moby-buildkit tracking bugs for this issue: Affects: fedora-34 [bug 2067367] Created golang-github-prometheus tracking bugs for this issue: Affects: epel-7 [bug 2067351] Affects: epel-8 [bug 2067354] Affects: epel-all [bug 2067347] Created golang-github-prometheus-alertmanager tracking bugs for this issue: Affects: epel-8 [bug 2067350] Created golang-github-prometheus-client tracking bugs for this issue: Affects: fedora-34 [bug 2067368] Created golang-github-prometheus-node-exporter tracking bugs for this issue: Affects: epel-7 [bug 2067352] Affects: epel-8 [bug 2067355] Affects: epel-all [bug 2067346] Created golang-github-skynetservices-skydns tracking bugs for this issue: Affects: fedora-34 [bug 2067369] Created golang-github-theupdateframework-notary tracking bugs for this issue: Affects: fedora-34 [bug 2067370] Created golang-k8s-apiextensions-apiserver tracking bugs for this issue: Affects: fedora-34 [bug 2067371] Created golang-k8s-apiserver tracking bugs for this issue: Affects: fedora-34 [bug 2067372] Created golang-k8s-cloud-provider tracking bugs for this issue: Affects: fedora-34 [bug 2067373] Created golang-k8s-controller-manager tracking bugs for this issue: Affects: fedora-34 [bug 2067374] Created golang-k8s-kube-aggregator tracking bugs for this issue: Affects: fedora-34 [bug 2067375] Created golang-k8s-kubernetes tracking bugs for this issue: Affects: fedora-34 [bug 2067376] Created golang-k8s-legacy-cloud-providers tracking bugs for this issue: Affects: fedora-34 [bug 2067377] Created golang-k8s-pod-security-admission tracking bugs for this issue: Affects: fedora-34 [bug 2067378] Created golang-k8s-sample-apiserver tracking bugs for this issue: Affects: fedora-34 [bug 2067379] Created golang-sigs-k8s-application tracking bugs for this issue: Affects: fedora-34 [bug 2067380] Created mantle tracking bugs for this issue: Affects: epel-7 [bug 2067348] Created origin tracking bugs for this issue: Affects: fedora-34 [bug 2067381] Created podman tracking bugs for this issue: Affects: fedora-34 [bug 2067382] Created rclone tracking bugs for this issue: Affects: epel-7 [bug 2067353] Affects: epel-8 [bug 2067356] Affects: epel-all [bug 2067349] Created skopeo tracking bugs for this issue: Affects: fedora-34 [bug 2067383] Created source-to-image tracking bugs for this issue: Affects: fedora-34 [bug 2067385] Created stargz-snapshotter tracking bugs for this issue: Affects: fedora-34 [bug 2067386]
Created buildah tracking bugs for this issue: Affects: fedora-35 [bug 2067422] Affects: fedora-all [bug 2067389] Created caddy tracking bugs for this issue: Affects: fedora-35 [bug 2067423] Affects: fedora-all [bug 2067390] Created conmon tracking bugs for this issue: Affects: fedora-35 [bug 2067424] Affects: fedora-all [bug 2067391] Created cri-o:1.18/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2067392] Created cri-o:1.20/cri-o tracking bugs for this issue: Affects: fedora-35 [bug 2067454] Created cri-o:1.21/cri-o tracking bugs for this issue: Affects: fedora-35 [bug 2067425] Created cri-o:1.22/cri-o tracking bugs for this issue: Affects: fedora-34 [bug 2067451] Created etcd tracking bugs for this issue: Affects: openstack-rdo [bug 2067421] Created golang-github-deislabs-oras tracking bugs for this issue: Affects: fedora-35 [bug 2067426] Affects: fedora-all [bug 2067393] Created golang-github-distribution-3 tracking bugs for this issue: Affects: fedora-35 [bug 2067427] Affects: fedora-all [bug 2067394] Created golang-github-docker-compose-on-kubernetes tracking bugs for this issue: Affects: fedora-all [bug 2067395] Created golang-github-docker-distribution tracking bugs for this issue: Affects: fedora-35 [bug 2067428] Affects: fedora-all [bug 2067396] Created golang-github-hashicorp-consul-api tracking bugs for this issue: Affects: fedora-35 [bug 2067455] Affects: fedora-all [bug 2067397] Created golang-github-hashicorp-consul-sdk tracking bugs for this issue: Affects: fedora-35 [bug 2067429] Created golang-github-hetznercloud-hcloud tracking bugs for this issue: Affects: fedora-35 [bug 2067430] Affects: fedora-all [bug 2067398] Created golang-github-moby-buildkit tracking bugs for this issue: Affects: fedora-35 [bug 2067431] Affects: fedora-all [bug 2067399] Created golang-github-prometheus-client tracking bugs for this issue: Affects: fedora-35 [bug 2067432] Affects: fedora-all [bug 2067400] Created golang-github-skynetservices-skydns tracking bugs for this issue: Affects: fedora-35 [bug 2067433] Affects: fedora-all [bug 2067401] Created golang-github-theupdateframework-notary tracking bugs for this issue: Affects: fedora-35 [bug 2067434] Affects: fedora-all [bug 2067402] Created golang-helm-3 tracking bugs for this issue: Affects: fedora-35 [bug 2067435] Created golang-k8s-apiextensions-apiserver tracking bugs for this issue: Affects: fedora-35 [bug 2067436] Affects: fedora-all [bug 2067403] Created golang-k8s-apiserver tracking bugs for this issue: Affects: fedora-35 [bug 2067437] Affects: fedora-all [bug 2067404] Created golang-k8s-cloud-provider tracking bugs for this issue: Affects: fedora-35 [bug 2067438] Affects: fedora-all [bug 2067405] Created golang-k8s-controller-manager tracking bugs for this issue: Affects: fedora-35 [bug 2067439] Affects: fedora-all [bug 2067406] Created golang-k8s-kube-aggregator tracking bugs for this issue: Affects: fedora-35 [bug 2067440] Affects: fedora-all [bug 2067407] Created golang-k8s-kubernetes tracking bugs for this issue: Affects: fedora-35 [bug 2067441] Affects: fedora-all [bug 2067409] Created golang-k8s-legacy-cloud-providers tracking bugs for this issue: Affects: fedora-35 [bug 2067442] Affects: fedora-all [bug 2067410] Created golang-k8s-pod-security-admission tracking bugs for this issue: Affects: fedora-35 [bug 2067443] Affects: fedora-all [bug 2067411] Created golang-k8s-sample-apiserver tracking bugs for this issue: Affects: fedora-35 [bug 2067444] Affects: fedora-all [bug 2067412] Created golang-sigs-k8s-application tracking bugs for this issue: Affects: fedora-35 [bug 2067445] Affects: fedora-all [bug 2067413] Created grafana tracking bugs for this issue: Affects: fedora-34 [bug 2067452] Affects: fedora-35 [bug 2067446] Affects: fedora-all [bug 2067414] Created mantle tracking bugs for this issue: Affects: fedora-34 [bug 2067453] Affects: fedora-all [bug 2067415] Created origin tracking bugs for this issue: Affects: fedora-35 [bug 2067447] Affects: fedora-all [bug 2067416] Created podman tracking bugs for this issue: Affects: fedora-35 [bug 2067448] Affects: fedora-all [bug 2067417] Created skopeo tracking bugs for this issue: Affects: fedora-all [bug 2067418] Created source-to-image tracking bugs for this issue: Affects: fedora-35 [bug 2067449] Affects: fedora-all [bug 2067419] Created stargz-snapshotter tracking bugs for this issue: Affects: fedora-35 [bug 2067450] Affects: fedora-all [bug 2067420]
Created cri-o:1.21/cri-o tracking bugs for this issue: Affects: fedora-34 [bug 2067457]
Created golang-github-hashicorp-consul-api tracking bugs for this issue: Affects: fedora-34 [bug 2067706]
This issue has been addressed in the following products: RHOL-5.4-RHEL-8 Via RHSA-2022:1461 https://access.redhat.com/errata/RHSA-2022:1461
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.10 Via RHSA-2022:1356 https://access.redhat.com/errata/RHSA-2022:1356
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-21698
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1762 https://access.redhat.com/errata/RHSA-2022:1762
This issue has been addressed in the following products: Red Hat OpenShift Logging 5.4 Via RHSA-2022:2216 https://access.redhat.com/errata/RHSA-2022:2216
This issue has been addressed in the following products: OpenShift Logging 5.2 Via RHSA-2022:2218 https://access.redhat.com/errata/RHSA-2022:2218
This issue has been addressed in the following products: OpenShift Logging 5.3 Via RHSA-2022:2217 https://access.redhat.com/errata/RHSA-2022:2217
This issue has been addressed in the following products: RHEL-7-CNV-4.10 RHEL-8-CNV-4.10 Via RHSA-2022:4667 https://access.redhat.com/errata/RHSA-2022:4667
This issue has been addressed in the following products: RHEL-8-CNV-4.10 Via RHSA-2022:4668 https://access.redhat.com/errata/RHSA-2022:4668
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2022:2280 https://access.redhat.com/errata/RHSA-2022:2280
This issue has been addressed in the following products: RHEL-8-CNV-4.10 Via RHSA-2022:5026 https://access.redhat.com/errata/RHSA-2022:5026
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Ironic content for Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5068 https://access.redhat.com/errata/RHSA-2022:5068
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5070 https://access.redhat.com/errata/RHSA-2022:5070
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5069 https://access.redhat.com/errata/RHSA-2022:5069
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2022:6042 https://access.redhat.com/errata/RHSA-2022:6042
This issue has been addressed in the following products: Openshift Serveless 1.24 Via RHSA-2022:6040 https://access.redhat.com/errata/RHSA-2022:6040
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2022:6061 https://access.redhat.com/errata/RHSA-2022:6061
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2022:6066 https://access.redhat.com/errata/RHSA-2022:6066
This issue has been addressed in the following products: RHOL-5.5-RHEL-8 Via RHSA-2022:6051 https://access.redhat.com/errata/RHSA-2022:6051
This issue has been addressed in the following products: Red Hat OpenShift Data Foundation 4.11 on RHEL8 Via RHSA-2022:6156 https://access.redhat.com/errata/RHSA-2022:6156
This issue has been addressed in the following products: OADP-1.1-RHEL-8 Via RHSA-2022:6290 https://access.redhat.com/errata/RHSA-2022:6290
This issue has been addressed in the following products: OADP-1.0-RHEL-8 Via RHSA-2022:6430 https://access.redhat.com/errata/RHSA-2022:6430
This issue has been addressed in the following products: RHEL-8-CNV-4.11 Via RHSA-2022:6526 https://access.redhat.com/errata/RHSA-2022:6526
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:6537 https://access.redhat.com/errata/RHSA-2022:6537
This issue has been addressed in the following products: OADP-1.0-RHEL-8 Via RHSA-2022:7261 https://access.redhat.com/errata/RHSA-2022:7261
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:7519 https://access.redhat.com/errata/RHSA-2022:7519
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:7529 https://access.redhat.com/errata/RHSA-2022:7529
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:8057 https://access.redhat.com/errata/RHSA-2022:8057
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2022:7399 https://access.redhat.com/errata/RHSA-2022:7399
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2022:9096 https://access.redhat.com/errata/RHSA-2022:9096
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0566 https://access.redhat.com/errata/RHSA-2023:0566
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0652 https://access.redhat.com/errata/RHSA-2023:0652
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:1158 https://access.redhat.com/errata/RHSA-2023:1158
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:2014 https://access.redhat.com/errata/RHSA-2023:2014
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:1326 https://access.redhat.com/errata/RHSA-2023:1326
This issue has been addressed in the following products: OADP-1.1-RHEL-8 Via RHSA-2023:5314 https://access.redhat.com/errata/RHSA-2023:5314