Resource exhaustion in Go programming language - CVE-2022-41715
Published: October 18, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in regexp/syntax when handling regular expressions. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Proxy Module
SUSE Manager Server Module
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Manager Client Tools Beta for SLE Micro
Fedora
SUSE Linux Enterprise Storage
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Manager Client Tools for SLE
SUSE Manager Client Tools Beta for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise High Performance Computing
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Submariner
Service Telemetry Framework
Ansible Automation Platform
IBM Watson Assistant for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Red Hat Application Interconnect
WebSphere Automation
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Spectrum Protect Plus
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Operations Dashboard
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Serverless Client
containerd
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Fusion Data Foundation
ObjectScale
Dell EMC Streaming Data Platform
IBM Cloud Pak for Watson AIOps
Storage Ceph
IBM Netezza for Cloud Pak for Data
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
QRadar Suite
Juniper Secure Analytics (JSA)
Splunk Enterprise
OpenShift Service Mesh
moby
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
IBM Cloud Pak System
OpenShift Developer Tools and Services
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.13 (Ubuntu package)
golang-1.13-go (Ubuntu package)
golang-1.13-src (Ubuntu package)
golang-1.16 (Ubuntu package)
golang-1.16-src (Ubuntu package)
golang-1.16-go (Ubuntu package)
toolbox-tests
toolbox
toolbox (Red Hat package)
firewalld-prometheus-config
dracut-saltboot
kiwi-desc-saltboot
udica
golang-github-QubitProducts-exporter_exporter
wire
wire-debuginfo
prometheus-postgres_exporter
python3-podman
podman-docker
podman-help
podman-debugsource
python3-pypodman
podman-debuginfo
podman
golist
golang-github-prometheus-promu
prometheus-blackbox_exporter
prometheus-blackbox_exporter-debuginfo
golang-github-prometheus-alertmanager
qpid-proton (Red Hat package)
golang-github-lusitaniae-apache_exporter
system-user-grafana
system-user-prometheus
golang-github-lusitaniae-apache_exporter-debuginfo
containernetworking-plugins (Red Hat package)
zypp-plugin-spacewalk
python2-zypp-plugin-spacewalk
python3-zypp-plugin-spacewalk
runc (Red Hat package)
slirp4netns (Red Hat package)
runc
supportutils-plugin-salt
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
skupper-cli (Red Hat package)
crun (Red Hat package)
golang-github-prometheus-node_exporter
openshift-serverless-clients (Red Hat package)
golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter-debuginfo
fuse-overlayfs (Red Hat package)
skopeo (Red Hat package)
jsoncpp (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
golang-help
golang-devel
golang
golang-1.18-go (Ubuntu package)
golang-1.18-src (Ubuntu package)
golang-1.18 (Ubuntu package)
go1.18-race
go1.18-doc
go1.18
go-toolset-1.18 (Red Hat package)
go-toolset-1.18-golang (Red Hat package)
go-toolset (Red Hat package)
golang (Red Hat package)
go1.18-openssl-race
go1.18-openssl-doc
go1.18-openssl
go1.19-race
go1.19-doc
go1.19
dev-lang/go
buildah (Red Hat package)
cri-o (Red Hat package)
buildah
buildah-debuginfo
buildah-debugsource
containers-common (Red Hat package)
buildah-tests
containers-common
golang-github-cpuguy83-md2man (Red Hat package)
conmon (Red Hat package)
conmon
haproxy (Red Hat package)
python2-hwdata
python3-hwdata
skupper-router (Red Hat package)
ansible
ansible-doc
golang-github-prometheus-prometheus
container-selinux (Red Hat package)
container-selinux
git-lfs (Red Hat package)
git-lfs-doc
git-lfs
etcd (Red Hat package)
podman-remote
podman-plugins
podman-gvproxy
etcd
criu-libs
criu-devel
criu
crit
python3-criu
podman (Red Hat package)
libwebsockets (Red Hat package)
mgr-daemon
python2-uyuni-common-libs
python3-uyuni-common-libs
uyuni-proxy-systemd-services
python2-spacewalk-client-tools
python2-spacewalk-client-setup
spacewalk-check
spacewalk-client-setup
spacewalk-client-tools
python2-spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-check
python3-spacewalk-client-setup
spacecmd
libslirp
libslirp-devel
podman-catatonit
podman-tests
podmansh
openshift-clients (Red Hat package)
openshift-ansible (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift (Red Hat package)
openshift-kuryr (Red Hat package)
kernel-rt (Red Hat package)
kernel (Red Hat package)
mgr-push
python2-mgr-push
supportutils-plugin-susemanager-client
python2-rhnlib
python3-mgr-push
python3-rhnlib
python3-pyvmomi
grafana (Red Hat package)
grafana
grafana-debuginfo
libdns1605
libirs1601
bind-utils
bind-devel-32bit
libisccfg1600
libisccc1600-32bit-debuginfo
libdns1605-32bit-debuginfo
libns1604-32bit
libirs1601-32bit-debuginfo
libns1604-32bit-debuginfo
libdns1605-32bit
libisccfg1600-32bit
libbind9-1600-32bit
libisccc1600-32bit
libirs1601-32bit
libisc1606-32bit-debuginfo
libbind9-1600-32bit-debuginfo
libisc1606-32bit
libisccfg1600-32bit-debuginfo
libisccc1600
bind-doc
libisccc1600-debuginfo
libisccfg1600-debuginfo
libirs-devel
bind-chrootenv
bind-debugsource
libirs1601-debuginfo
libdns1605-debuginfo
libns1604-debuginfo
libbind9-1600-debuginfo
libisc1606-debuginfo
bind-devel
bind
bind-utils-debuginfo
bind-debuginfo
libbind9-1600
libisc1606
python3-bind
libisccc1600-64bit
libdns1605-64bit
libbind9-1600-64bit
libirs1601-64bit
libns1604
libisc1606-64bit
libisccfg1600-64bit
weldr-client (Red Hat package)
cockpit-composer
cockpit-composer (Red Hat package)
osbuild-composer (Red Hat package)
osbuild-composer
osbuild-composer-core
osbuild-composer-worker
osbuild (Red Hat package)
osbuild
python3-osbuild
osbuild-selinux
osbuild-ostree
cockpit-podman
watsonx.data
Red Hat Ceph Storage
AMQ Broker
IBM Security Verify Access
How to mitigate CVE-2022-41715
Submariner - update to 0.14.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
OpenShift API for Data Protection (OADP) - update to 1.1.2
Migration Toolkit for Containers - addressed in versions 1.7.7, 1.7.8, 1.7.10
containerd - addressed in versions 1.5.14, 1.7.0
QRadar Suite - update to 1.10.18.0
OpenShift Service Mesh - addressed in versions 2.2.7, 2.3.1, 2.4.0
IBM Cloud Pak System - update to 2.3.3.6
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Storage Fusion Data Foundation - update to 4.13
Red Hat OpenShift Container Platform - addressed in versions 4.11.28, 4.11.44, 4.12.0, 4.12.3, 4.12.4, 4.12.22
OpenShift Logging - addressed in versions 5.5.5, 5.6.0
Red Hat Migration Toolkit for Applications - update to 6.1.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
moby - update to 20.10.19
golang-1.13 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.13-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.13-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.16 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
golang-1.16-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
golang-1.16-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.1.1-3.rhaos4.12.el8
firewalld-prometheus-config - addressed in versions 0.1-150000.3.47.2, 0.1-150000.3.53.1, 0.1-150100.4.17.1, 0.1-150100.4.20.1, 0.1-159000.6.33.1
dracut-saltboot - addressed in versions 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1
kiwi-desc-saltboot - update to 0.1.1687520761.cefb248-4.15.2
udica - update to 0.2.6-21
golang-github-QubitProducts-exporter_exporter - addressed in versions 0.4.0-4.6.2, 0.4.0-159000.4.6.1
wire - update to 0.5.0-150000.1.12.3
wire-debuginfo - update to 0.5.0-150000.1.12.3
prometheus-postgres_exporter - addressed in versions 0.10.1-1.11.5, 0.10.1-1.17.2, 0.10.1-3.6.4, 0.10.1-150000.1.11.4, 0.10.1-150000.1.17.1, 0.10.1-159000.3.6.1
python3-podman - update to 0.10.1-10
podman-docker - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-help - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-debugsource - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
python3-pypodman - update to 0.10.1-10
podman-debuginfo - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
golist - update to 0.10.1-11
golang-github-prometheus-promu - addressed in versions 0.14.0-1.12.1, 0.14.0-4.12.2, 0.14.0-150000.3.12.2
prometheus-blackbox_exporter - addressed in versions 0.19.0-1.17.1, 0.19.0-150000.1.17.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1
prometheus-blackbox_exporter-debuginfo - addressed in versions 0.19.0-1.17.1, 0.24.0-3.6.3
golang-github-prometheus-alertmanager - addressed in versions 0.23.0-1.18.3, 0.26.0-1.24.2, 0.26.0-4.12.4
qpid-proton (Red Hat package) - addressed in versions 0.37.0-2.el8ai, 0.37.0-2.el9ai
golang-github-lusitaniae-apache_exporter - addressed in versions 1.0.0-1.21.2, 1.0.0-4.12.4, 1.0.0-150000.1.20.1, 1.0.0-159000.4.12.1
system-user-grafana - update to 1.0.0-3.7.2
system-user-prometheus - update to 1.0.0-3.7.2
golang-github-lusitaniae-apache_exporter-debuginfo - addressed in versions 1.0.0-150000.1.20.1, 1.0.0-159000.4.12.1
containernetworking-plugins (Red Hat package) - addressed in versions 1.0.1-6.rhaos4.12.el8, 1.0.1-7.rhaos4.12.el8
zypp-plugin-spacewalk - addressed in versions 1.0.14-30.42.1, 1.0.14-150000.3.35.1
python2-zypp-plugin-spacewalk - update to 1.0.14-30.42.1
python3-zypp-plugin-spacewalk - update to 1.0.14-150000.3.35.1
runc (Red Hat package) - addressed in versions 1.1.4-2.rhaos4.12.el8, 1.1.6-4.rhaos4.12.el8
slirp4netns (Red Hat package) - update to 1.1.8-2.rhaos4.12.el8
runc - update to 1.1.12-1.0.1
supportutils-plugin-salt - addressed in versions 1.2.2-9.9.2, 1.2.2-159000.5.9.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
ObjectScale - update to 1.4.0
Red Hat Application Interconnect - update to 1.4
containernetworking-plugins - update to 1.4.0-2.0.1
skupper-cli (Red Hat package) - addressed in versions 1.4.1-2.el8, 1.4.1-2.el9
crun (Red Hat package) - addressed in versions 1.4.2-2.rhaos4.12.el8, 1.4.2-3.rhaos4.12.el9
golang-github-prometheus-node_exporter - addressed in versions 1.5.0-1.24.4, 1.5.0-4.15.4
WebSphere Automation - update to 1.5.2
openshift-serverless-clients (Red Hat package) - update to 1.6.1-1.el8
golang-github-boynux-squid_exporter - addressed in versions 1.6-4.9.2, 1.6-159000.4.9.1
Netcool Operations Insight - update to 1.6.9
golang-github-boynux-squid_exporter-debuginfo - update to 1.6-159000.4.9.1
Dell EMC Streaming Data Platform - update to 1.7.0
fuse-overlayfs (Red Hat package) - update to 1.9-2.rhaos4.12.el8
skopeo (Red Hat package) - addressed in versions 1.9.4-2.rhaos4.12.el8, 1.9.4-2.rhaos4.12.el9, 1.9.4-3.rhaos4.12.el9, 1.9.4-3.1.rhaos4.12.el8
jsoncpp (Red Hat package) - update to 1.9.4-3.el9
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang-help - update to 1.15.7-21
golang-devel - update to 1.15.7-21
golang - update to 1.15.7-21
golang-1.18-go (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang-1.18-src (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang-1.18 (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang - addressed in versions 1.18.7-1.fc36, 1.18.9-1.el7, 1.19.2-1.fc37
go1.18-race - update to 1.18.7-150000.1.34.1
go1.18-doc - update to 1.18.7-150000.1.34.1
go1.18 - update to 1.18.7-150000.1.34.1
go-toolset-1.18 (Red Hat package) - update to 1.18.9-1.el7_9
go-toolset-1.18-golang (Red Hat package) - update to 1.18.9-1.el7_9
go-toolset (Red Hat package) - update to 1.18.9-1.el9_1
golang (Red Hat package) - update to 1.18.9-1.el9_1
go1.18-openssl-race - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-doc - update to 1.18.10.1-150000.1.9.1
go1.18-openssl - update to 1.18.10.1-150000.1.9.1
go1.19-race - update to 1.19.2-150000.1.12.1
go1.19-doc - update to 1.19.2-150000.1.12.1
go1.19 - update to 1.19.2-150000.1.12.1
golang - update to 1.19.3-2
dev-lang/go - update to 1.20.10
buildah (Red Hat package) - addressed in versions 1.23.4-4.rhaos4.12.el8, 1.23.4-4.rhaos4.12.el9, 1.23.4-5.rhaos4.12.el9, 1.23.4-5.1.rhaos4.12.el8
cri-o (Red Hat package) - update to 1.25.2-6.rhaos4.12.git3c4e50c.el8
buildah - update to 1.26.1-4
buildah-debuginfo - update to 1.26.1-4
buildah-debugsource - update to 1.26.1-4
Red Hat OpenShift Serverless - update to 1.27.0
OpenShift Serverless Client - update to 1.27.0
containers-common (Red Hat package) - update to 1-33.rhaos4.12.el8
buildah-tests - update to 1.33.7-1
buildah - update to 1.33.7-1
containers-common - update to 1-81.0.1
watsonx.data - update to 2.0.1
golang-github-cpuguy83-md2man (Red Hat package) - update to 2.0.2-4.el9
conmon (Red Hat package) - addressed in versions 2.1.2-3.rhaos4.12.el8, 2.1.2-4.rhaos4.12.el8, 2.1.2-4.rhaos4.12.el9, 2.1.2-5.rhaos4.12.el9
conmon - update to 2.1.10-1
haproxy (Red Hat package) - update to 2.2.24-2.el8
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
python2-hwdata - update to 2.3.5-15.12.2
python3-hwdata - update to 2.3.5-159000.5.13.1
skupper-router (Red Hat package) - addressed in versions 2.4.1-2.el8, 2.4.1-2.el9
ansible - update to 2.9.27-159000.3.9.1
ansible-doc - update to 2.9.27-159000.3.9.1
golang-github-prometheus-prometheus - addressed in versions 2.37.6-1.44.3, 2.37.6-150000.3.47.2, 2.37.6-150100.4.17.1, 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1, 2.45.6-150100.4.20.1
container-selinux (Red Hat package) - update to 2.188.0-2.rhaos4.12.el8
container-selinux - update to 2.229.0-2
git-lfs (Red Hat package) - addressed in versions 3.2.0-1.el9, 3.2.0-2.el8
git-lfs-doc - update to 3.2.0-2.0.1
git-lfs - update to 3.2.0-2.0.1
etcd (Red Hat package) - update to 3.3.23-12.el8ost
podman-remote - addressed in versions 3.4.4-5, 4.9.4-13
podman-plugins - addressed in versions 3.4.4-5, 4.9.4-13
podman-gvproxy - addressed in versions 3.4.4-5, 4.9.4-13
etcd - update to 3.4.14-11
IBM Cloud Pak for Watson AIOps - update to 3.6.2
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman (Red Hat package) - addressed in versions 4.2.0-5.rhaos4.12.el9, 4.2.0-6.1.rhaos4.12.el8, 4.2.0-7.rhaos4.12.el9
libwebsockets (Red Hat package) - addressed in versions 4.3.1-1.el8ai, 4.3.1-1.el9ai
mgr-daemon - addressed in versions 4.3.7-1.41.1, 4.3.7-150000.1.41.1, 4.3.8-1.44.2, 4.3.8-150000.1.44.1
python2-uyuni-common-libs - addressed in versions 4.3.8-1.33.1, 5.0.1-3.33.3
python3-uyuni-common-libs - addressed in versions 4.3.8-150000.1.33.1, 5.0.1-159000.3.33.1
uyuni-proxy-systemd-services - addressed in versions 4.3.10-150000.1.15.1, 5.0.1-159000.3.9.1
python2-spacewalk-client-tools - update to 4.3.18-52.95.2
python2-spacewalk-client-setup - update to 4.3.18-52.95.2
spacewalk-check - addressed in versions 4.3.18-52.95.2, 4.3.18-150000.3.86.2, 5.0.1-159000.6.48.1
spacewalk-client-setup - addressed in versions 4.3.18-52.95.2, 4.3.18-150000.3.86.2, 5.0.1-159000.6.48.1
spacewalk-client-tools - addressed in versions 4.3.18-52.95.2, 4.3.18-150000.3.86.2, 5.0.1-159000.6.48.1
python2-spacewalk-check - update to 4.3.18-52.95.2
python3-spacewalk-client-tools - addressed in versions 4.3.18-150000.3.86.2, 5.0.1-159000.6.48.1
python3-spacewalk-check - addressed in versions 4.3.18-150000.3.86.2, 5.0.1-159000.6.48.1
python3-spacewalk-client-setup - addressed in versions 4.3.18-150000.3.86.2, 5.0.1-159000.6.48.1
spacecmd - addressed in versions 4.3.21-38.121.1, 4.3.21-150000.3.98.1, 4.3.26-38.136.2, 4.3.26-150000.3.113.1, 5.0.1-41.42.3, 5.0.1-159000.6.42.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
IBM Decision Optimization for Cloud Pak for Data - update to 4.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.3
python3-podman - update to 4.9.0-1
podman-gvproxy - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-13
podmansh - update to 4.9.4-13
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202301312133.p0.gb05f7d4.assembly.stream.el8, 4.12.0-202301312133.p0.gb05f7d4.assembly.stream.el9, 4.12.0-202306090942.p0.g3c01edd.assembly.stream.el8, 4.12.0-202306090942.p0.g3c01edd.assembly.stream.el9
openshift-ansible (Red Hat package) - update to 4.12.0-202306090942.p0.g74dc7b3.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - update to 4.12.0-202306090942.p0.gd2acdd5.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.12.0-202306121916.p0.g8c21020.assembly.stream.el8, 4.12.0-202306121916.p0.g8c21020.assembly.stream.el9
openshift-kuryr (Red Hat package) - update to 4.12.0-202306140156.p0.g31dd228.assembly.stream.el8
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
OpenShift Virtualization - update to 4.13.0
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.43.1.rt7.200.el8_6, 4.18.0-372.59.1.rt7.217.el8_6
kernel (Red Hat package) - update to 4.18.0-372.59.1.el8_6
mgr-push - addressed in versions 5.0.1-4.21.4, 5.0.1-159000.4.21.1
python2-mgr-push - update to 5.0.1-4.21.4
supportutils-plugin-susemanager-client - addressed in versions 5.0.1-9.15.2, 5.0.1-159000.6.15.1
python2-rhnlib - update to 5.0.1-24.30.3
python3-mgr-push - update to 5.0.1-159000.4.21.1
python3-rhnlib - update to 5.0.1-159000.6.30.1
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.0.0
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
python3-pyvmomi - update to 6.7.3-159000.3.6.1
grafana (Red Hat package) - addressed in versions 7.5.15-4.el8, 9.0.9-2.el9
grafana - update to 7.5.15-4.0.2
AMQ Broker - update to 7.12.0
grafana - addressed in versions 9.5.1-1.48.1, 9.5.1-150000.1.48.5, 9.5.8-1.60.1, 9.5.8-4.21.2, 9.5.8-150000.1.60.2, 9.5.8-159000.4.24.1
grafana-debuginfo - addressed in versions 9.5.1-150000.1.48.5, 9.5.8-150000.1.60.2, 9.5.8-159000.4.24.1
libdns1605 - update to 9.16.6-150000.12.65.1
libirs1601 - update to 9.16.6-150000.12.65.1
bind-utils - update to 9.16.6-150000.12.65.1
bind-devel-32bit - update to 9.16.6-150000.12.65.1
libisccfg1600 - update to 9.16.6-150000.12.65.1
libisccc1600-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libdns1605-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libns1604-32bit - update to 9.16.6-150000.12.65.1
libirs1601-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libns1604-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libdns1605-32bit - update to 9.16.6-150000.12.65.1
libisccfg1600-32bit - update to 9.16.6-150000.12.65.1
libbind9-1600-32bit - update to 9.16.6-150000.12.65.1
libisccc1600-32bit - update to 9.16.6-150000.12.65.1
libirs1601-32bit - update to 9.16.6-150000.12.65.1
libisc1606-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libbind9-1600-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libisc1606-32bit - update to 9.16.6-150000.12.65.1
libisccfg1600-32bit-debuginfo - update to 9.16.6-150000.12.65.1
libisccc1600 - update to 9.16.6-150000.12.65.1
bind-doc - update to 9.16.6-150000.12.65.1
libisccc1600-debuginfo - update to 9.16.6-150000.12.65.1
libisccfg1600-debuginfo - update to 9.16.6-150000.12.65.1
libirs-devel - update to 9.16.6-150000.12.65.1
bind-chrootenv - update to 9.16.6-150000.12.65.1
bind-debugsource - update to 9.16.6-150000.12.65.1
libirs1601-debuginfo - update to 9.16.6-150000.12.65.1
libdns1605-debuginfo - update to 9.16.6-150000.12.65.1
libns1604-debuginfo - update to 9.16.6-150000.12.65.1
libbind9-1600-debuginfo - update to 9.16.6-150000.12.65.1
libisc1606-debuginfo - update to 9.16.6-150000.12.65.1
bind-devel - update to 9.16.6-150000.12.65.1
bind - update to 9.16.6-150000.12.65.1
bind-utils-debuginfo - update to 9.16.6-150000.12.65.1
bind-debuginfo - update to 9.16.6-150000.12.65.1
libbind9-1600 - update to 9.16.6-150000.12.65.1
libisc1606 - update to 9.16.6-150000.12.65.1
python3-bind - update to 9.16.6-150000.12.65.1
libisccc1600-64bit - update to 9.16.6-150000.12.65.1
libdns1605-64bit - update to 9.16.6-150000.12.65.1
libbind9-1600-64bit - update to 9.16.6-150000.12.65.1
libirs1601-64bit - update to 9.16.6-150000.12.65.1
libns1604 - update to 9.16.6-150000.12.65.1
libisc1606-64bit - update to 9.16.6-150000.12.65.1
libisccfg1600-64bit - update to 9.16.6-150000.12.65.1
IBM Security Verify Access - update to 10.0.9
IBM Spectrum Protect Plus - update to 10.1.14
IBM CICS TX Advanced - update to 11.1.0.0 ifix7
IBM CICS TX Standard - update to 11.1.0.0 ifix7
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
EMC Cloud Tiering Appliance - update to 13.2.0.2.24
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.4
weldr-client (Red Hat package) - addressed in versions 35.9-1.el9, 35.9-2.el8
cockpit-composer - update to 45-1
cockpit-composer (Red Hat package) - addressed in versions 45-1.el8_8, 45-1.el9_2
osbuild-composer (Red Hat package) - addressed in versions 75-1.el8, 76-2.el9_2
osbuild-composer - update to 76-2.0.1
osbuild-composer-core - update to 76-2.0.1
osbuild-composer-worker - update to 76-2.0.1
osbuild (Red Hat package) - addressed in versions 81-1.el8, 81-1.el9
osbuild - update to 81-1.0.1
python3-osbuild - update to 81-1.0.1
osbuild-selinux - update to 81-1.0.1
osbuild-ostree - update to 81-1.0.1
cockpit-podman - update to 84.1-1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-4
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-4
Operations Dashboard - update to 2022.2.1-6-lts
External References
Related Security Bulletins
- Multiple vulnerabilities in Go
- Moby update for go
- SUSE update for go1.18
- SUSE update for go1.19
- Multiple vulnerabilities in containerd
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 9 update for go-toolset and golang
- Red Hat Developer Tools update for go-toolset-1.18 and go-toolset-1.18-golang
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Resource exhaustion in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in IBM Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Resource exhaustion in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Resource exhaustion in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in OpenShift Serverless Client
- Multiple vulnerabilities in IBM Decision Optimization in IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in containerd
- Red Hat OpenStack Platform update for etcd
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in Service Telemetry Framework
- Multiple vulnerabilities in IBM WebSphere Automation
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Ubuntu update for golang-1.18
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Red Hat Enterprise Linux 9 update for golang-github-cpuguy83-md2man
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for Image Builder
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- SUSE update for SUSE Manager Client Tools
- SUSE update for SUSE Manager Client Tools
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 8 update for golang
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift Virtualization 4.13 images
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- SUSE update for go1.18-openssl
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabilities in Red Hat Ceph Storage
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.4
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.2
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.11
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.12
- SUSE update for SUSE Manager Client Tools
- SUSE update for SUSE Manager Client Tools
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- OpenShift Container Platform 4.12 update for golang
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell Streaming Data Platform
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Red Hat Application Interconnect
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Gentoo update for Go
- Ubuntu update for golang-1.13
- SUSE update for Security Beta update for SUSE Manager Client Tools and Salt
- SUSE update for Security Beta update for SUSE Manager Client Tools
- Multiple vulnerabilities in IBM QRadar Suite Software
- SUSE update for SUSE Manager Client Tools
- SUSE update for SUSE Manager Client Tools
- SUSE update for golang-github-prometheus-prometheus
- openEuler update for golang
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4 for RHEL 9
- Red Hat Enterprise Linux 8 update for the container-tools:3.0 module
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in AMQ Broker 7.12
- Amazon Linux AMI update for golist
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- SUSE update for golang-github-prometheus-prometheus
- Fedora 37 update for golang
- Fedora 36 update for golang
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- openEuler 22.03 LTS SP4 update for buildah
- openEuler 22.03 LTS SP3 update for podman
- openEuler 24.03 LTS SP1 update for podman
- openEuler 22.03 LTS SP4 update for podman
- openEuler 24.03 LTS update for podman
- openEuler 20.03 LTS SP4 update for podman
- Multiple vulnerabilities in IBM Security Verify Access
- openEuler 20.03 LTS SP4 update for etcd
- Anolis OS update for git-lfs
- Anolis OS update for grafana
- Anolis OS update for multiple packages
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM Storage Fusion Data Foundation
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data