- Issued:
- 2023-11-01
- Updated:
- 2023-11-01
RHSA-2023:6154 - Important: Secondary Scheduler Operator for Red Hat OpenShift 1.2.0
Synopsis
Important: Secondary Scheduler Operator for Red Hat OpenShift 1.2.0
Type/Severity
Security Advisory: Important
Topic
Secondary Scheduler Operator for Red Hat OpenShift 1.2.0
Description
The Secondary Scheduler Operator for Red Hat OpenShift is an optional operator that makes it possible to deploy a secondary scheduler by providing a scheduler image. You can run a scheduler with custom plugins without applying additional manifests, such as cluster roles and deployments.
Security Fix(es):
-
golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325)
-
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (CVE-2023-44487)
-
golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
-
golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
-
golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
-
golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Secondary Scheduler Operator for Red Hat OpenShift (OSSO) | 1 | x86_64 |
Fixes
- This content is not included.BZ - 2237773
- This content is not included.BZ - 2237776
- This content is not included.BZ - 2237777
- This content is not included.BZ - 2237778
- This content is not included.BZ - 2242803
- This content is not included.BZ - 2243296
- This content is not included.WRKLDS-779
CVEs
- This content is not included.CVE-2023-2602
- This content is not included.CVE-2023-2603
- This content is not included.CVE-2023-4527
- This content is not included.CVE-2023-4806
- This content is not included.CVE-2023-4813
- This content is not included.CVE-2023-4911
- CVE-2023-27536
- CVE-2023-28321
- This content is not included.CVE-2023-28484
- This content is not included.CVE-2023-29469
- This content is not included.CVE-2023-29491
- This content is not included.CVE-2023-39318
- This content is not included.CVE-2023-39319
- This content is not included.CVE-2023-39321
- This content is not included.CVE-2023-39322
- This content is not included.CVE-2023-39325
- This content is not included.CVE-2023-44487
References
- https://access.redhat.com/security/updates/classification/#important
- This content is not included.This content is not included.https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.