Resource exhaustion in Go programming language - CVE-2023-39325
Published: October 16, 2023 / Updated: March 28, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive consumption of internal resources when handling HTTP/2 requests. A remote attacker can bypass the http2.Server.MaxConcurrentStreams setting by creating new connections while the current connections are still being processed, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
SUSE Linux Enterprise Server 15 SP4 LTSS
Containers Module
openSUSE Leap
Ubuntu
openEuler
IBM Observability with Instana
IBM Cloud Pak for Data Scheduling
IBM Cloud Pak for Security
Fence Agents Remediation Operator
Machine Deletion Remediation Operator
IBM Concert Software
Run Once Duration Override Operator for Red Hat OpenShift
Service Binding Operator
Service Telemetry Framework
OpenShift Pipelines
cert-manager Operator for Red Hat OpenShift
Consul Enterprise
Consul
Traefik
Cryostat
IBM Cloud Transformation Advisor
Ansible Automation Platform
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat Satellite
Red Hat OpenStack
Netcool Operations Insight
DataPower Operator
IBM MQ Operator
IBM Spectrum Copy Data Management
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
Kube Descheduler Operator for Red Hat OpenShift
App Connect Enterprise Certified Container
Ceph
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Cost Management
Istio
Red Hat OpenShift GitOps
Loki
Boundary
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
Node Maintenance Operator
OpenShift Container Platform for Windows Containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
AdGuard Home
Cloud Pak for Data
Vault Enterprise
Vault
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
OpenShift Serverless Client
buildah
Red Hat OpenShift Container Platform
IBM Edge Application Manager
IBM DataPower Gateway
QRadar Suite
Splunk Enterprise
Intel In-Band Manageability
DB2 Data Management Console
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Fusion Data Foundation
Storage Ceph
IBM i Modernization Engine for Lifecycle Integration
Cloud Kubernetes Service
IBM Planning Analytics Workspace
Watson CP4D Data Stores
Storage Protect Server
Storage Protect Plus Container Agent
Storage Protect Plus Server
IBM Netezza for Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
OpenShift Developer Tools and Services
IBM CICS TX Advanced
IBM CICS TX Standard
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
golang-github-facebook-time
golang-github-tdewolff-argp
crun-wasm (Red Hat package)
yggdrasil-worker-forwarder (Red Hat package)
toolbox (Red Hat package)
foreman_ygg_worker (Red Hat package)
rhc (Red Hat package)
yggdrasil (Red Hat package)
rust-bootupd (Red Hat package)
golang-uber-mock
golang-github-nats-io-nkeys
rhc-worker-script (Red Hat package)
gmailctl
golang-github-google-dap
wasmedge (Red Hat package)
golang-x-mod
golang-x-text
golang-github-prometheus-promu (Red Hat package)
coreos-installer (Red Hat package)
butane (Red Hat package)
golang-x-net
golang-github-nats-io-streaming-server
golang-github-prometheus-alertmanager
pack
qpid-proton (Red Hat package)
containernetworking-plugins (Red Hat package)
collectd-libpod-stats (Red Hat package)
skopeo-debuginfo
containers-common
skopeo
skopeo-debugsource
dnsx
runc
runc (Red Hat package)
cni-plugins
containerd
xq
rubygem-foreman_maintain (Red Hat package)
python-octavia-tests-tempest (Red Hat package)
golang-github-prometheus-prom2json
pulpcore-selinux (Red Hat package)
tfm-rubygem-safemode (Red Hat package)
rubygem-safemode (Red Hat package)
receptor (Red Hat package)
skupper-cli (Red Hat package)
tfm-rubygem-rchardet (Red Hat package)
rubygem-rchardet (Red Hat package)
google-benchmark (Red Hat package)
openshift-gitops-kam (Red Hat package)
delve
node-exporter
crun (Red Hat package)
openshift-serverless-clients (Red Hat package)
openshift-pipelines-client (Red Hat package)
golang-github-rogpeppe-internal
skopeo (Red Hat package)
spdlog (Red Hat package)
gtest (Red Hat package)
golang
golang-devel
golang-help
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
tfm-rubygem-git (Red Hat package)
rubygem-git (Red Hat package)
go-toolset
go-toolset-1.19 (Red Hat package)
go-toolset (Red Hat package)
golang (Red Hat package)
golang-bin
golang-misc
golang-race
golang-docs
golang-src
golang-tests
go-toolset-1.19-golang (Red Hat package)
golang-1.20-src (Ubuntu package)
golang-1.20-go (Ubuntu package)
golang-1.20 (Ubuntu package)
dev-lang/go
golang-shared
go1.20-debuginfo
go1.20
go1.20-doc
go1.20-race
go1.20-openssl-doc
go1.20-openssl-debuginfo
go1.20-openssl
go1.20-openssl-race
golang-1.21-go (Ubuntu package)
golang-1.21 (Ubuntu package)
golang-1.21-src (Ubuntu package)
go1.21
go1.21-race
go1.21-doc
go1.21-openssl
go1.21-openssl-race
go1.21-openssl-doc
cri-tools-debuginfo
cri-tools-debugsource
cri-tools
cri-o-debuginfo
cri-o-debugsource
cri-o
kubernetes1.24-client-fish-completion
kubernetes1.24-proxy
kubernetes1.24-kubeadm
kubernetes1.24-client-common
kubernetes1.24-kubelet-common
kubernetes1.24-client-bash-completion
kubernetes1.24-scheduler
kubernetes1.24-client
kubernetes1.24-kubelet
kubernetes1.24-controller-manager
kubernetes1.24-apiserver
cri-o (Red Hat package)
kubernetes1.25-client
kubernetes1.25-kubelet-common
kubernetes1.25-proxy
kubernetes1.25-kubelet
kubernetes1.25-client-fish-completion
kubernetes1.25-kubeadm
kubernetes1.25-scheduler
kubernetes1.25-apiserver
kubernetes1.25-controller-manager
kubernetes1.25-client-bash-completion
kubernetes1.25-client-common
syncthing
buildah
buildah-debuginfo
buildah-debugsource
cri-tools (Red Hat package)
buildah (Red Hat package)
golang-github-nats-io
containers-common (Red Hat package)
rclone
ecs-init
doctl
amazon-cloudwatch-agent
python-werkzeug (Red Hat package)
conmon (Red Hat package)
nmstate (Red Hat package)
skupper-router (Red Hat package)
golang-github-nats-io-jwt-2
haproxy (Red Hat package)
golang-github-tdewolff-parse
nats-server
golang-github-onsi-ginkgo-2
ignition
ignition-debuginfo
ignition-debugsource
ignition-validate
ignition (Red Hat package)
golang-github-tdewolff-minify
gh
container-selinux (Red Hat package)
jenkins (Red Hat package)
kata-containers (Red Hat package)
foreman (Red Hat package)
python-gitpython (Red Hat package)
python-django (Red Hat package)
amazon-ssm-agent
exercism
catch (Red Hat package)
etcd (Red Hat package)
etcd
foreman-installer (Red Hat package)
python-pulpcore (Red Hat package)
podman (Red Hat package)
rubygem-katello (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
microshift (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
rust-afterburn (Red Hat package)
ceph-ansible (Red Hat package)
satellite (Red Hat package)
rubygem-foreman_rh_cloud (Red Hat package)
grafana (Red Hat package)
grafana
grafana-debuginfo
puppet-agent (Red Hat package)
gitleaks
fmt (Red Hat package)
rubygem-foreman_theme_satellite (Red Hat package)
openstack-ironic (Red Hat package)
ovn23.09 (Red Hat package)
docker
ostree (Red Hat package)
rpm-ostree (Red Hat package)
IBM Cloud Pak System
IBM DB2
IBM Storage Scale System
Red Hat Ceph Storage
How to mitigate CVE-2023-39325
Boundary - update to 0.14.1
Fence Agents Remediation Operator - update to 0.2.1
Machine Deletion Remediation Operator - update to 0.2.1
Node Health Check Operator - addressed in versions 0.4.1, 0.6.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
AdGuard Home - addressed in versions 0.107.39, 0.108.0-b.47
Vault Enterprise - addressed in versions 1.13.9, 1.14.5, 1.15.1
Red Hat OpenShift Serverless - update to 1.30.2
IBM Concert Software - update to 2.0.0
Run Once Duration Override Operator for Red Hat OpenShift - addressed in versions 1.0.1, 1.1.0
Vault - addressed in versions 1.13.9, 1.14.5, 1.15.1
Istio - addressed in versions 1.17.8, 1.18.5, 1.19.3
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.14, 1.3.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - addressed in versions 1.1.3, 1.2.0
Service Binding Operator - update to 1.4.1
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - addressed in versions 1.7.14, 1.8.1, 1.8.2
Red Hat OpenShift GitOps - addressed in versions 1.9.3, 1.10.1
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2, 1.12.1
QRadar Suite - update to 1.10.19.0
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
Consul Enterprise - addressed in versions 1.14.11, 1.15.7, 1.16.3
Consul - addressed in versions 1.14.11, 1.15.7, 1.16.3
OpenShift Serverless Client - update to 1.30.2
buildah - addressed in versions 1.32.0, 1.32.1, 1.32.2
Traefik - update to 2.10.5
Loki - update to 2.9.2
IBM Cloud Transformation Advisor - update to 3.10.2
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.3
OpenShift Service Mesh - addressed in versions 2.2.11, 2.2.12, 2.3.8, 2.4.4, 2.4.5
Ansible Automation Platform - update to 2.2.2
Migration Toolkit for Virtualization - addressed in versions 2.4.3, 2.5.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.8, 2.7.9, 2.8.3
Intel In-Band Manageability - update to 4.2.0
DB2 Data Management Console - update to 3.1.13.1
Guardium Data Security Center (GDSC) - update to 3.6.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.7, 4.0.5, 4.1.4, 4.1.5, 4.2.2
Cloud Pak for Data - update to 5.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Storage Fusion Data Foundation - update to 4.16z2
Red Hat OpenShift Container Platform - addressed in versions 4.11.52, 4.11.53, 4.11.54, 4.11.55, 4.11.56, 4.11.57, 4.11.58, 4.11.59, 4.12.39, 4.12.41, 4.12.42, 4.12.43, 4.12.44, 4.12.45, 4.12.46, 4.12.47, 4.12.48, 4.12.49, 4.12.50, 4.12.51, 4.12.54, 4.12.71, 4.12.72, 4.13.17, 4.13.18, 4.13.19, 4.13.21, 4.13.22, 4.13.23, 4.13.24, 4.13.25, 4.13.26, 4.13.27, 4.13.29, 4.13.31, 4.13.32, 4.13.33, 4.13.35, 4.13.36, 4.13.38, 4.13.54, 4.13.55, 4.14.0, 4.14.2, 4.14.4, 4.14.5, 4.14.6, 4.14.7, 4.14.8, 4.14.10, 4.14.11, 4.14.13, 4.14.14, 4.14.18, 4.14.21, 4.14.42, 4.15.0, 4.15.5, 4.15.9, 4.15.39
OpenShift Virtualization - addressed in versions 4.11.7, 4.12.8, 4.12.9, 4.13.5, 4.13.6, 4.14.0, 4.14.1
Node Maintenance Operator - addressed in versions 5.0.1, 5.2.1
OpenShift Logging - addressed in versions 5.5.17, 5.6.12, 5.7.7
Storage Ceph - update to 7.1z4
OpenShift Container Platform for Windows Containers - addressed in versions 6.0.3, 7.2.0, 8.1.0, 9.0.0, 10.15.0
Red Hat Migration Toolkit for Applications - addressed in versions 6.1.4, 6.2.1
Red Hat Satellite - addressed in versions 6.11.5.6, 6.12.5.2, 6.13.5, 6.14
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Red Hat OpenStack - addressed in versions 16.2.5, 17.1.1
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-github-facebook-time - addressed in versions 0^20240110git1649917-1.fc38, 0^20240110git1649917-1.fc39
golang-github-tdewolff-argp - addressed in versions 0-0.1.20240227git719bbce.fc38, 0-0.1.20240227git719bbce.fc39
crun-wasm (Red Hat package) - addressed in versions 0.0-3.rhaos4.14.el8, 1.8.5-3.rhaos4.14.el9
yggdrasil-worker-forwarder (Red Hat package) - addressed in versions 0.0.3-1.el7sat, 0.0.3-1.el8sat
toolbox (Red Hat package) - addressed in versions 0.0.99.3-4.el9_0, 0.0.99.3-10.el9_2, 0.1.2-1.rhaos4.14.el9, 0.1.2-1.rhaos4.15.el9
foreman_ygg_worker (Red Hat package) - addressed in versions 0.2.2-1.el7sat, 0.2.2-1.el8sat, 0.2.2-1.el9sat
rhc (Red Hat package) - update to 0.2.2-1.el9_2.2
yggdrasil (Red Hat package) - addressed in versions 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat
rust-bootupd (Red Hat package) - update to 0.2.17-1.el9
golang-uber-mock - update to 0.4.0-1.fc41
golang-github-nats-io-nkeys - addressed in versions 0.4.6-1.fc38, 0.4.6-1.fc39, 0.4.6-1.fc40
rhc-worker-script (Red Hat package) - update to 0.5-1.el7_9
gmailctl - addressed in versions 0.10.7-1.fc38, 0.10.7-1.fc39
golang-github-google-dap - addressed in versions 0.11.0-1.fc37, 0.11.0-1.fc38, 0.11.0-1.fc39
wasmedge (Red Hat package) - update to 0.12.1-2.rhaos4.14.el9
golang-x-mod - addressed in versions 0.14.0-1.el9, 0.14.0-1.fc38, 0.14.0-1.fc39
golang-x-text - addressed in versions 0.14.0-1.fc38, 0.14.0-1.fc39
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-15.1.gitd5383c5.el8
coreos-installer (Red Hat package) - addressed in versions 0.17.0-1.rhaos4.14.el8, 0.17.0-1.rhaos4.14.el9, 0.17.0-3.rhaos4.15.el9
butane (Red Hat package) - update to 0.19.0-1.1.rhaos4.14.el8
golang-x-net - addressed in versions 0.20.0-1.el9, 0.20.0-1.fc38, 0.20.0-1.fc39
golang-github-nats-io-streaming-server - addressed in versions 0.25.6-1.fc38, 0.25.6-1.fc39, 0.25.6-1.fc40
golang-github-prometheus-alertmanager - update to 0.27.0-1.fc41
pack - addressed in versions 0.32.0-1.fc37, 0.32.0-1.fc38
qpid-proton (Red Hat package) - addressed in versions 0.37.0-2.el8, 0.37.0-2.el9
containernetworking-plugins (Red Hat package) - update to 1.0.1-11.1.rhaos4.14.el8
collectd-libpod-stats (Red Hat package) - addressed in versions 1.0.4-5.el8ost, 1.0.5-6.el8ost, 1.0.5-6.el9ost
skopeo-debuginfo - addressed in versions 1.1.0-13, 1.8.0-7
containers-common - update to 1.1.0-13
skopeo - addressed in versions 1.1.0-13, 1.8.0-7
skopeo-debugsource - addressed in versions 1.1.0-13, 1.8.0-7
dnsx - update to 1.1.6-1.fc40
runc - update to 1.1.7-1
runc (Red Hat package) - addressed in versions 1.1.9-1.rhaos4.13.el8, 1.1.9-1.rhaos4.13.el9, 1.1.9-2.1.rhaos4.14.el8, 1.1.9-2.1.rhaos4.14.el9, 1.1.12-1.rhaos4.15.el9
cni-plugins - update to 1.2.0-1
containerd - update to 1.2.0-215
xq - update to 1.2.4-2.fc40
rubygem-foreman_maintain (Red Hat package) - update to 1.2.12-1.el8sat
python-octavia-tests-tempest (Red Hat package) - addressed in versions 1.3.0-1.20210528004838.0ae7f10.el8ost, 1.4.1-2.20230111145026.f7718ef.el8ost, 1.9.0-1.20230509101018.el9ost
golang-github-prometheus-prom2json - update to 1.3.3-1.fc40
pulpcore-selinux (Red Hat package) - update to 1.3.3-1.el8pc
tfm-rubygem-safemode (Red Hat package) - update to 1.3.8-0.1.el7sat
rubygem-safemode (Red Hat package) - addressed in versions 1.3.8-0.1.el8sat, 1.3.8-1.el8sat
receptor (Red Hat package) - addressed in versions 1.4.2-1.el8ap, 1.4.2-1.el9ap
skupper-cli (Red Hat package) - addressed in versions 1.4.3-4.el8, 1.4.3-4.el9
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.6
containerd - addressed in versions 1.4.13-6, 1.7.2-1, 1.7.11-1
Netcool Operations Insight - update to 1.6.12
tfm-rubygem-rchardet (Red Hat package) - update to 1.8.0-0.1.el7sat
rubygem-rchardet (Red Hat package) - update to 1.8.0-0.1.el8sat
DataPower Operator - update to 1.8.1
google-benchmark (Red Hat package) - update to 1.8.2-1.el9
Cloud Kubernetes Service - update to 1.8.4_5586_iks
openshift-gitops-kam (Red Hat package) - addressed in versions 1.8.6-10.el8, 1.9.3-32.el8, 1.10.1-22.el8
delve - update to 1.9.1-1.0.1
node-exporter - update to 1.9.1-2.el9
crun (Red Hat package) - addressed in versions 1.9.2-1.rhaos4.13.el8, 1.9.2-1.rhaos4.13.el9, 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9, 1.14-1.rhaos4.15.el9
openshift-serverless-clients (Red Hat package) - update to 1.9.2-4.el8
openshift-pipelines-client (Red Hat package) - addressed in versions 1.10.6-11031.el8, 1.11.2-11148.el8, 1.12.1-11260.el8
golang-github-rogpeppe-internal - update to 1.11.0-1.fc40
skopeo (Red Hat package) - addressed in versions 1.11.2-10.1.rhaos4.14.el8, 1.11.2-10.1.rhaos4.14.el9, 1.11.2-21.1.rhaos4.15.el9
spdlog (Red Hat package) - update to 1.12.0-1.rhaos4.14.el9
gtest (Red Hat package) - update to 1.13.0-1.el9
golang - update to 1.15.7-36
golang-devel - update to 1.15.7-36
golang-help - update to 1.15.7-36
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.2
tfm-rubygem-git (Red Hat package) - update to 1.18.0-0.1.el7sat
rubygem-git (Red Hat package) - addressed in versions 1.18.0-0.1.el8sat, 1.18.0-1.el8sat
go-toolset - update to 1.19.13-1
golang - addressed in versions 1.19.13-1.el7, 1.20.10-2.fc38, 1.20.10-3.fc37, 1.21.3-1.fc39
go-toolset-1.19 (Red Hat package) - update to 1.19.13-1.el7_9
go-toolset (Red Hat package) - update to 1.19.13-1.el9_2
golang (Red Hat package) - update to 1.19.13-1.el9_2
golang-bin - addressed in versions 1.19.13-1.0.1, 1.20.10-1
golang-misc - addressed in versions 1.19.13-1.0.1, 1.20.10-1
golang-race - update to 1.19.13-1.0.1
golang-docs - addressed in versions 1.19.13-1.0.1, 1.20.10-1
golang - addressed in versions 1.19.13-1.0.1, 1.20.10-1
golang-src - addressed in versions 1.19.13-1.0.1, 1.20.10-1
golang-tests - addressed in versions 1.19.13-1.0.1, 1.20.10-1
go-toolset-1.19-golang (Red Hat package) - update to 1.19.13-2.el7_9
golang-1.20-src (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20-go (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20 (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
dev-lang/go - update to 1.20.10
golang-shared - update to 1.20.10-1
golang - update to 1.20.10-1.48
go1.20-debuginfo - update to 1.20.10-150000.1.29.1
go1.20 - update to 1.20.10-150000.1.29.1
go1.20-doc - update to 1.20.10-150000.1.29.1
go1.20-race - update to 1.20.10-150000.1.29.1
go1.20-openssl-doc - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-debuginfo - update to 1.20.11.1-150000.1.14.1
go1.20-openssl - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-race - update to 1.20.11.1-150000.1.14.1
golang-1.21-go (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21 (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-src (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
delve - addressed in versions 1.21.2-1.fc38, 1.21.2-1.fc39
go1.21 - update to 1.21.3-150000.1.12.1
go1.21-race - update to 1.21.3-150000.1.12.1
go1.21-doc - update to 1.21.3-150000.1.12.1
go1.21-openssl - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-race - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-doc - update to 1.21.4.1-150000.1.5.1
cri-tools-debuginfo - update to 1.22.0-5
cri-tools-debugsource - update to 1.22.0-5
cri-tools - update to 1.22.0-5
cri-o-debuginfo - update to 1.23.2-11
cri-o-debugsource - update to 1.23.2-11
cri-o - update to 1.23.2-11
kubernetes1.24-client-fish-completion - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-proxy - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-kubeadm - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client-common - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-kubelet-common - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client-bash-completion - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-scheduler - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-kubelet - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-controller-manager - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-apiserver - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
cri-o (Red Hat package) - addressed in versions 1.25.5-2.rhaos4.12.git0217273.el8, 1.26.4-5.1.rhaos4.13.git969e013.el8, 1.26.4-5.1.rhaos4.13.git969e013.el9, 1.27.1-8.1.rhaos4.14.git3fecb83.el8, 1.27.1-8.1.rhaos4.14.git3fecb83.el9, 1.27.1-13.1.rhaos4.14.git956c5f7.el8, 1.27.1-13.1.rhaos4.14.git956c5f7.el9, 1.28.3-14.rhaos4.15.git33aabd8.el9
kubernetes1.25-client - update to 1.25.16-150400.9.16.1
kubernetes1.25-kubelet-common - update to 1.25.16-150400.9.16.1
kubernetes1.25-proxy - update to 1.25.16-150400.9.16.1
kubernetes1.25-kubelet - update to 1.25.16-150400.9.16.1
kubernetes1.25-client-fish-completion - update to 1.25.16-150400.9.16.1
kubernetes1.25-kubeadm - update to 1.25.16-150400.9.16.1
kubernetes1.25-scheduler - update to 1.25.16-150400.9.16.1
kubernetes1.25-apiserver - update to 1.25.16-150400.9.16.1
kubernetes1.25-controller-manager - update to 1.25.16-150400.9.16.1
kubernetes1.25-client-bash-completion - update to 1.25.16-150400.9.16.1
kubernetes1.25-client-common - update to 1.25.16-150400.9.16.1
syncthing - addressed in versions 1.26.0-1.el9, 1.26.0-1.fc37, 1.26.0-1.fc38, 1.26.0-1.fc39
buildah - update to 1.26.1-4
buildah-debuginfo - update to 1.26.1-4
buildah-debugsource - update to 1.26.1-4
cri-tools (Red Hat package) - addressed in versions 1.27.0-2.1.el8, 1.27.0-2.1.el9, 1.28.0-3.el9
buildah (Red Hat package) - addressed in versions 1.29.1-10.1.rhaos4.14.el8, 1.29.1-10.1.rhaos4.14.el9, 1.29.1-20.2.rhaos4.15.el9
golang-github-nats-io - addressed in versions 1.31.0-1.fc39, 1.31.0-1.fc40, 1.31.0-2.fc38
containers-common (Red Hat package) - addressed in versions 1-36.rhaos4.12.el8, 1-36.rhaos4.13.el8, 1-36.rhaos4.13.el9, 1-51.rhaos4.14.el8
rclone - update to 1.70.3-1.el9
ecs-init - addressed in versions 1.77.0-1, 1.79.0-1
doctl - update to 1.101.0-2.fc40
amazon-cloudwatch-agent - update to 1.300032.3-1
python-werkzeug (Red Hat package) - update to 2.0.3-5.el9
IBM MQ Operator - addressed in versions 2.0.17, 3.0.0
IBM Planning Analytics Workspace - update to 2.0.93
conmon (Red Hat package) - addressed in versions 2.1.7-1.2.rhaos4.14.el9, 2.1.7-3.1.rhaos4.14.el8, 2.1.7-3.1.rhaos4.14.el9
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.14.el8
IBM Spectrum Copy Data Management - update to 2.2.22
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
skupper-router (Red Hat package) - addressed in versions 2.4.3-1.el8, 2.4.3-1.el9
golang-github-nats-io-jwt-2 - addressed in versions 2.5.3-1.fc38, 2.5.3-1.fc39, 2.5.3-1.fc40
haproxy (Red Hat package) - update to 2.6.13-1.rhaos4.14.el8
golang-github-tdewolff-parse - addressed in versions 2.7.12-1.fc38, 2.7.12-1.fc39
IBM Fusion HCI - update to 2.8.0
nats-server - addressed in versions 2.10.5-1.fc38, 2.10.5-1.fc39, 2.10.5-1.fc40
golang-github-onsi-ginkgo-2 - update to 2.13.2-3.fc40
ignition - update to 2.14.0-4
ignition-debuginfo - update to 2.14.0-4
ignition-debugsource - update to 2.14.0-4
ignition-validate - update to 2.14.0-4
ignition (Red Hat package) - addressed in versions 2.16.2-1.1.rhaos4.14.el9, 2.16.2-2.rhaos4.15.el9
golang-github-tdewolff-minify - addressed in versions 2.20.18-1.fc38, 2.20.18-1.fc39
gh - update to 2.39.1-1.fc40
container-selinux (Red Hat package) - addressed in versions 2.221.0-1.rhaos4.14.el8, 2.221.0-2.rhaos4.14.el9, 2.223.0-1.rhaos4.14.el8, 2.223.0-2.rhaos4.14.el9, 2.228.1-1.rhaos4.15.el9
jenkins (Red Hat package) - addressed in versions 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706516352-3.el8
kata-containers (Red Hat package) - addressed in versions 3.0.2-9.rhaos4.12.el8, 3.1.3-4.rhaos4.14.el9
foreman (Red Hat package) - addressed in versions 3.1.1.27-1.el7sat, 3.1.1.27-1.el8sat, 3.3.0.23-1.el8sat, 3.5.1.23-1.el8sat
python-gitpython (Red Hat package) - update to 3.1.32-1.el8pc
python-django (Red Hat package) - update to 3.2.21-1.el8pc
amazon-ssm-agent - update to 3.2.2222.0-1
exercism - addressed in versions 3.3.0-1.fc39, 3.3.0-1.fc40
catch (Red Hat package) - update to 3.3.2-1.el9
etcd (Red Hat package) - addressed in versions 3.3.23-15.el8ost, 3.4.26-3.el9ost
etcd - addressed in versions 3.4.14-9, 3.4.14-11, 3.4.14-12
foreman-installer (Red Hat package) - update to 3.5.2.4-1.el8sat
etcd - update to 3.5.13-1.fc41
Red Hat OpenShift Dev Spaces - update to 3.15.0
python-pulpcore (Red Hat package) - update to 3.21.18-1.el8pc
podman (Red Hat package) - addressed in versions 4.4.1-10.1.rhaos4.14.el8, 4.4.1-10.1.rhaos4.14.el9, 4.4.1-21.rhaos4.15.el9
rubygem-katello (Red Hat package) - update to 4.7.0.33-1.el8sat
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
openshift-clients (Red Hat package) - addressed in versions 4.11.0-202310131344.p0.g3470d04.assembly.stream.el8, 4.12.0-202310131144.p0.g7aa4009.assembly.stream.el8, 4.12.0-202310131144.p0.g7aa4009.assembly.stream.el9, 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el8, 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el9, 4.13.0-202310130726.p0.g717d4a5.assembly.stream.el8, 4.13.0-202310130726.p0.g717d4a5.assembly.stream.el9, 4.13.0-202311151332.p0.gc7c6eb2.assembly.stream.el8, 4.13.0-202311151332.p0.gc7c6eb2.assembly.stream.el9, 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el8, 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el9, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el8, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el9, 4.15.0-202402070507.p0.g48dcf59.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.11.0-202310140343.p0.gec2a592.assembly.stream.el8, 4.12.0-202310132326.p0.g20cda61.assembly.stream.el8, 4.12.0-202310132326.p0.g20cda61.assembly.stream.el9, 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el8, 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el9, 4.13.0-202310140746.p0.gc7606e7.assembly.stream.el8, 4.13.0-202310140746.p0.gc7606e7.assembly.stream.el9, 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el8, 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el9, 4.15.0-202402142009.p0.g6216ea1.assembly.stream.el9
jenkins-2-plugins (Red Hat package) - addressed in versions 4.11.1698299029-1.el8, 4.12.1698294000-1.el8, 4.13.1698292274-1.el8, 4.14.1706516441-1.el8
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202310130944.p0.g2d540c5.assembly.stream.el8, 4.13.0-202310130944.p0.g2d540c5.assembly.stream.el9, 4.14.0-202310062327.p0.gf781421.assembly.stream.el8, 4.14.0-202310062327.p0.gf781421.assembly.stream.el9, 4.15.0-202402162207.p0.g1c9b99e.assembly.stream.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
openshift-kuryr (Red Hat package) - update to 4.14.0-202309272140.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - update to 4.14.0-202309272140.p0.gd2acdd5.assembly.stream.el8
microshift (Red Hat package) - addressed in versions 4.14.2-202311091609.p0.gd80d6de.assembly.4.14.2.el9, 4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - update to 4.15.0-202401231232.p0.gba252ab.assembly.stream.el9
kernel (Red Hat package) - addressed in versions 4.18.0-372.76.1.el8_6, 4.18.0-372.82.1.el8_6, 5.14.0-284.36.1.el9_2, 5.14.0-284.40.1.el9_2, 5.14.0-284.41.1.el9_2, 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.76.1.rt7.235.el8_6, 4.18.0-372.82.1.rt7.241.el8_6, 5.14.0-284.36.1.rt14.321.el9_2, 5.14.0-284.40.1.rt14.325.el9_2, 5.14.0-284.41.1.rt14.326.el9_2, 5.14.0-284.54.1.rt14.339.el9_2
IBM DB2 - update to 5.0
Kube Descheduler Operator for Red Hat OpenShift - update to 5.0.0
Watson CP4D Data Stores - update to 5.0.3
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
IBM Storage Scale System - update to 5.1.9.1
Red Hat Ceph Storage - addressed in versions 5.3, 6.1, 7.1
rust-afterburn (Red Hat package) - addressed in versions 5.4.3-1.rhaos4.14.el9, 5.4.3-2.rhaos4.15.el9
ceph-ansible (Red Hat package) - update to 6.0.28.8-1.el8cp
satellite (Red Hat package) - addressed in versions 6.11.5.6-1.el7sat, 6.11.5.6-1.el8sat, 6.12.5.2-1.el8sat, 6.13.5-1.el8sat
rubygem-foreman_rh_cloud (Red Hat package) - update to 7.0.48-1.el8sat
grafana (Red Hat package) - addressed in versions 7.3.6-6.el8_4, 7.5.11-4.el8_6, 7.5.11-6.el9_0, 7.5.15-5.el8_8, 9.0.9-4.el9_2
grafana - update to 7.5.15-5.0.1
grafana-debuginfo - update to 7.5.15-6
grafana - update to 7.5.15-6
puppet-agent (Red Hat package) - addressed in versions 7.26.0-3.el6sat, 7.26.0-3.el7sat, 7.26.0-3.el8sat, 7.26.0-3.el9sat
Storage Protect Server - update to 8.1.23
gitleaks - update to 8.18.2-1.fc40
fmt (Red Hat package) - update to 9.1.0-1.el9
IBM DataPower Gateway - addressed in versions 10.0.1.16, 10.5.0.8
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
rubygem-foreman_theme_satellite (Red Hat package) - update to 11.0.0.6-1.el8sat
IBM CICS TX Advanced - update to 11.1.0.0 ifix15
IBM CICS TX Standard - update to 11.1.0.0 ifix15
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Ceph - addressed in versions 16.2.10-266.el8cp, 16.2.10-266.el9cp
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19
openstack-ironic (Red Hat package) - update to 21.3.1-0.20231106145533.e53dc4f.el9
IBM Automation Decision Services - update to 23.0.2.0.2
ovn23.09 (Red Hat package) - update to 23.09.0-37.el9fdp
docker - update to 24.0.5-1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-14, 2023.2.1-3
ostree (Red Hat package) - update to 2023.8-3.el9
rpm-ostree (Red Hat package) - update to 2024.2-1.el9
External References
Related Security Bulletins
- Denial of service in Go programming language
- AdGuardHome update for Go programming language
- loki update for Go
- Traefik update for Go
- Red Hat Enterprise Linux 9 update for go-toolset and golang
- Red Hat Developer Tools update for go-toolset-1.19 and go-toolset-1.19-golang
- Denial of service when handling HTTP/2 requests in Istio
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- SUSE update for go1.21
- SUSE update for go1.20
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.3
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.2
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 7 update for rhc-worker-script
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9.0 Extended Update Support update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat Satellite
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh for 2.4
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabilities in Logging Subsystem 5.6 for Red Hat OpenShift
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Fedora 37 update for golang
- Fedora 39 update for golang
- Fedora 38 update for golang
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console
- Multiple vulnerabilities in Red Hat OpenStack Platform 17
- Denial of service in Red Hat OpenStack Platform 17
- Multiple vulnerabilities in Red Hat OpenStack Platform 17
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.1
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in Red Hat Satellite 6.11
- Multiple vulnerabilities in Red Hat Satellite 6.12
- Multiple vulnerabilities in Red Hat Satellite Client
- Red Hat Enterprise Linux 9.0 Extended Update Support update for toolbox
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.5
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.7
- Multiple vulnerabilities in Red Hat Node Maintenance Operator 5.2
- Multiple vulnerabilities in Red Hat Node Maintenance Operator 5.0
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.0
- Multiple vulnerabilities in Logging Subsystem 5.5 for Red Hat OpenShift
- Denial of service in OpenShift Container Platform 4.13
- Red Hat Enterprise Linux 9 update for toolbox
- Multiple vulnerabilities in IBM DataPower Gateway
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in IBM Cloud Kubernetes Service
- OpenShift Developer Tools and Services for OCP 4.13 update for jenkins and jenkins-2-plugins
- Red Hat Product OCP Tools 4.12 update for Openshift Jenkins
- Red Hat Product OCP Tools 4.11 update for Openshift Jenkins
- Service Interconnect 1 for RHEL 8 and Service Interconnect 1 for RHEL 9 update for skupper-cli and skupper-router
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Cost Management for RHEL 8
- Multiple vulnerabilities in Cryostat 2 on RHEL 8
- Multiple vulnerabilities in Red Hat OpenShift Pipelines Client
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.74
- Multiple vulnerabilities in Red Hat Openshift distributed tracing
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.0
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.2
- Multiple vulnerabilities in Service Binding Operator
- Multiple vulnerabilities in HashiCorp Consul
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Denial of service in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Denial of service in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Denial of service in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift 1.2
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Red Hat OpenShift Virtualization release 4.11
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift support for Windows Containers 8.1
- Red Hat OpenShift GitOps 1.10 update for openshift-gitops-kam
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Rapid Reset attack in HashiCorp Vault and Vault Enterprise
- Rapid Reset attack in Boundary
- Fedora 38 update for pack
- Fedora 37 update for pack
- Red Hat OpenShift GitOps 1.8 update for openshift-gitops-kam
- OpenShift-Pipelines-1.11-RHEL-8 update for openshift-pipelines-client
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift 1.1
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift
- Multiple vulnerabilities in Migration Toolkit for Applications 6.2
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless Client
- Rapid Reset attack in Red Hat OpenShift GitOps 1.8
- Multiple vulnerabilities in Red Hat Network Observability
- Rapid Reset attack in OpenShift Container Platform 4.13
- Rapid Reset attack in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Node Health Check Operator 0.6
- Multiple vulnerabilities in Node Health Check Operator 0.4
- Multiple vulnerabilities in Fence Agents Remediation Operator
- Fedora 38 update for syncthing
- Fedora 39 update for syncthing
- Fedora 37 update for syncthing
- Fedora EPEL 9 update for syncthing
- Multiple vulnerabilities in Migration Toolkit for Applications 6.1
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.11
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Rapid Reset attack in Red Hat Machine Deletion Remediation Operator
- Fedora 40 update for gh
- Fedora 40 update for dnsx
- SUSE update for go1.20-openssl
- SUSE update for go1.21-openssl
- Fedora 40 update for golang-github-nats-io, golang-github-nats-io-jwt-2, golang-github-nats-io-nkeys, golang-github-nats-io-streaming-server, nats-server
- Fedora 39 update for golang-github-nats-io, golang-github-nats-io-jwt-2, golang-github-nats-io-nkeys, golang-github-nats-io-streaming-server, nats-server
- Fedora 38 update for golang-github-nats-io, golang-github-nats-io-jwt-2, golang-github-nats-io-nkeys, golang-github-nats-io-streaming-server, nats-server
- Fedora 38 update for golang-github-google-dap
- Fedora 39 update for golang-github-google-dap
- Fedora 37 update for golang-github-google-dap
- Multiple vulnerabilities in Oracle Linux
- Red Hat OpenShift GitOps 1.9 update for openshift-gitops-kam
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.4
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift 1.12
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift 1.11
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Denial of service in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.9
- Denial of service in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Gentoo update for Go
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 9.0
- Multiple vulnerabilities in Red Hat Satellite 6.14
- Fedora 38 update for gmailctl
- Fedora 39 update for gmailctl
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Fedora 40 update for golang-github-prometheus-prom2json
- Amazon Linux AMI update for containerd
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 6.0
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12 for RHEL 9
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for Go
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.10
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in Red Hat OpenShift Pipelines Client tkn for 1.10.6
- Multiple vulnerabilities in IBM CICS TX Standard and Advanced
- Fedora 40 update for doctl
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 7.2
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat Ceph Storage 6.1
- Multiple vulnerabilities in IBM Storage Scale DAS
- Fedora 40 update for golang-github-rogpeppe-internal
- Fedora 39 update for delve
- Fedora 38 update for delve
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.5
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Fedora 40 update for golang-github-onsi-ginkgo-2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- IBM Cloud Pak System update for Go
- Fedora 39 update for golang-x-net
- Fedora 38 update for golang-x-net
- Fedora 38 update for golang-x-mod
- Fedora EPEL 9 update for golang-x-mod
- Fedora 39 update for golang-x-mod
- Fedora EPEL 9 update for golang-x-net
- Fedora 38 update for golang-x-text
- Fedora 39 update for golang-x-text
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Fedora 39 update for golang-github-facebook-time
- Fedora 38 update for golang-github-facebook-time
- Ubuntu update for golang-1.20
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Red Hat OpenShift Container Platform 4.12 update for golang
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Intel In-Band Manageability Framework
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Fedora 40 update for gitleaks
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Fedora 40 update for xq
- OpenShift Developer Tools and Services for OCP 4.14 update for jenkins and jenkins-2-plugins
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Fedora 39 update for golang-github-tdewolff-argp, golang-github-tdewolff-minify, golang-github-tdewolff-parse
- Fedora 38 update for golang-github-tdewolff-argp, golang-github-tdewolff-minify, golang-github-tdewolff-parse
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Fedora 39 update for exercism
- Fedora 40 update for exercism
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 10.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat build of MicroShift
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM i Modernization Engine for Lifecycle Integration
- openEuler update for golang
- openEuler update for grafana
- openEuler update for containerd
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- OpenShift Container Platform release 4.13 update for golang
- Resource exhaustion in IBM Cloud Pak for Data Scheduling
- Fedora 41 update for golang-uber-mock
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Kube Descheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- openEuler 22.03 LTS SP1 update for cri-tools
- openEuler 22.03 LTS SP2 update for cri-tools
- openEuler 22.03 LTS SP3 update for cri-tools
- openEuler 22.03 LTS SP3 update for ignition
- openEuler 22.03 LTS SP1 update for ignition
- openEuler 22.03 LTS SP2 update for ignition
- openEuler 22.03 LTS SP1 update for cri-o
- openEuler 22.03 LTS SP2 update for cri-o
- openEuler 22.03 LTS SP3 update for cri-o
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Fedora 41 update for golang-github-prometheus-alertmanager
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Fedora 41 update for etcd
- Multiple vulnerabilities in IBM Storage Fusion HCI
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat Ceph Storage 5
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Amazon Linux AMI update for amazon-ssm-agent
- Amazon Linux AMI update for containerd
- Amazon Linux AMI update for amazon-cloudwatch-agent
- Multiple vulnerabilities in Storage Protect Plus Server
- SUSE update for kubernetes1.23
- SUSE update for kubernetes1.24
- SUSE update for kubernetes1.24
- SUSE update for kubernetes1.25
- Multiple vulnerabilities in IBM Watson CP4D Data Stores
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Ubuntu update for golang-1.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- openEuler 22.03 LTS SP4 update for buildah
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Ubuntu update for golang-1.17
- Amazon Linux AMI update for golang
- Amazon Linux AMI update for docker
- Amazon Linux AMI update for runc
- Amazon Linux AMI update for containerd
- Amazon Linux AMI update for cni-plugins
- Amazon Linux AMI update for oci-add-hooks
- Amazon Linux AMI update for ecs-init
- Amazon Linux AMI update for ecs-init
- openEuler 20.03 LTS SP4 update for etcd
- openEuler 22.03 LTS SP4 update for etcd
- openEuler 22.03 LTS SP3 update for etcd
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for grafana
- Anolis OS update for golang
- IBM Storage Fusion Data Foundation update for Golang Go
- Multiple vulnerabilities in Red Hat Ceph Storage 6
- IBM Cloud Pak for Data System update for http2 package
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Fedora EPEL 9 update for node-exporter
- Fedora EPEL 9 update for rclone
- Multiple vulnerabilities in IBM Concert Software
- openEuler 22.03 LTS SP4 update for skopeo
- openEuler 22.03 LTS SP3 update for skopeo
- openEuler 20.03 LTS SP4 update for skopeo
- Multiple vulnerabilities in IBM Edge Application Manager
- IBM Storage Ceph update for Golang
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
- Red Hat Enterprise Linux 9 update for rhc