Issued:
2024-08-19
Updated:
2024-08-19

RHSA-2024:5547 - Important: Red Hat OpenShift Data Foundation 4.16.1 bug fix and security update


Synopsis

Important: Red Hat OpenShift Data Foundation 4.16.1 bug fix and security update

Type/Severity

Security Advisory Important

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.16.1 on Red Hat Enterprise Linux 9 from Red Hat Container Registry.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3-compatible API.

Security Fix(es):

  • golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788)
  • golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)
  • go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
  • nodejs-ws: denial of service when handling a request with many HTTP headers (CVE-2024-37890)

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

ProductVersionArch
Red Hat OpenShift Data Foundation4x86_64
Red Hat OpenShift Data Foundation for RHEL 9 ARM4aarch64
Red Hat OpenShift Data Foundation for IBM Z and LinuxONE4s390x
Red Hat OpenShift Data Foundation for IBM Power, little endian4ppc64le

Fixes

CVEs

References


Additional information