Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13



Published: 2023-07-21
Risk High
Patch available YES
Number of vulnerabilities 10
CVE-ID CVE-2023-1260
CVE-2023-3089
CVE-2023-24534
CVE-2023-24536
CVE-2023-24537
CVE-2023-24538
CVE-2023-24539
CVE-2023-27561
CVE-2023-29400
CVE-2019-19921
CWE-ID CWE-264
CWE-326
CWE-400
CWE-399
CWE-835
CWE-94
CWE-79
CWE-284
Exploitation vector Network
Public exploit Public exploit code for vulnerability #10 is available.
Vulnerable software
Subscribe
openshift4-aws-iso (Red Hat package)
Operating systems & Components / Operating system package or component

openshift-kuryr (Red Hat package)
Operating systems & Components / Operating system package or component

nmstate (Red Hat package)
Operating systems & Components / Operating system package or component

containernetworking-plugins (Red Hat package)
Operating systems & Components / Operating system package or component

container-selinux (Red Hat package)
Operating systems & Components / Operating system package or component

ovn23.06 (Red Hat package)
Operating systems & Components / Operating system package or component

openvswitch3.1 (Red Hat package)
Operating systems & Components / Operating system package or component

openstack-ironic (Red Hat package)
Operating systems & Components / Operating system package or component

openshift-clients (Red Hat package)
Operating systems & Components / Operating system package or component

openshift-ansible (Red Hat package)
Operating systems & Components / Operating system package or component

openshift (Red Hat package)
Operating systems & Components / Operating system package or component

kernel-rt (Red Hat package)
Operating systems & Components / Operating system package or component

kernel (Red Hat package)
Operating systems & Components / Operating system package or component

cri-o (Red Hat package)
Operating systems & Components / Operating system package or component

Vendor Red Hat Inc.

Security Bulletin

This security bulletin contains information about 10 vulnerabilities.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU78481

Risk: Low

CVSSv3.1: 3.7 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-1260

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improper access restrictions within kube-apiserver. A remote authenticated user with "update, patch" permissions to the "pods/ephemeralcontainers" subresource can bypass SCC admission restrictions and gain control over a privileged pod.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Inadequate Encryption Strength

EUVDB-ID: #VU78005

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-3089

CWE-ID: CWE-326 - Inadequate Encryption Strength

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists within the OpenShift container platform configuration with enabled FIPS mode, which resulted in usage of not validated cryptographic modules. A remote attacker can perform various attacks against not validated cryptographic modules and gain access to sensitive information.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Resource exhaustion

EUVDB-ID: #VU74571

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-24534

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing HTTP and MIME headers in net/textproto. A remote attacker can cause an HTTP server to allocate large amounts of memory from a small request and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Resource management error

EUVDB-ID: #VU74572

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-24536

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within mime/multipart and net/textproto components when parsing multipart forms. A remote attacker can pass specially crafted request to the application and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Infinite loop

EUVDB-ID: #VU74573

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-24537

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when calling any of the Parse functions on Go source code which contains //line directives with very large line numbers. A remote attacker can consume all available system resources and cause denial of service conditions.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Code Injection

EUVDB-ID: #VU74574

Risk: High

CVSSv3.1: 7.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-24538

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in html/template when handling JavaScript templates that contain backticks in code. If a template contains a Go template action within a JavaScript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary JavaScript code into the Go template.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Cross-site scripting

EUVDB-ID: #VU75790

Risk: Medium

CVSSv3.1: 5.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-24539

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when handling angle brackets in CSS context. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Improper access control

EUVDB-ID: #VU74190

Risk: Low

CVSSv3.1: 6.1 [CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-27561

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper access restrictions in the libcontainer/rootfs_linux.go. A local user can gain elevated privileges on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Cross-site scripting

EUVDB-ID: #VU75792

Risk: Medium

CVSSv3.1: 5.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-29400

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when processing HTML attributes. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Improper access control

EUVDB-ID: #VU25847

Risk: Low

CVSSv3.1: 6 [CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2019-19921

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions, related to libcontainer/rootfs_linux.go in runc. A local user with ability to spawn two containers with custom volume-mount configurations, and run custom images can escalate privileges on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

openshift4-aws-iso (Red Hat package): before 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8

openshift-kuryr (Red Hat package): before 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8

nmstate (Red Hat package): before 2.2.12-1.rhaos4.13.el8

containernetworking-plugins (Red Hat package): before 1.0.1-8.rhaos4.13.el8

container-selinux (Red Hat package): before 2.215.0-1.rhaos4.13.el8

ovn23.06 (Red Hat package): before 23.06.0-13.el9fdp

openvswitch3.1 (Red Hat package): before 3.1.0-32.el9fdp

openstack-ironic (Red Hat package): before 21.3.1-0.20230706125653.c8f8157.el9

openshift-clients (Red Hat package): before 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9

openshift-ansible (Red Hat package): before 4.13.0-202306230038.p0.g148be47.assembly.stream.el9

openshift (Red Hat package): before 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9

kernel-rt (Red Hat package): before 5.14.0-284.23.1.rt14.308.el9_2

kernel (Red Hat package): before 5.14.0-284.23.1.el9_2

cri-o (Red Hat package): before 1.26.3-11.rhaos4.13.git78941bf.el9

External links

http://access.redhat.com/errata/RHSA-2023:4093


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###