{"id":40547,"date":"2023-04-19T18:08:18","date_gmt":"2023-04-19T14:08:18","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/171929\/RHSA-2023-1817-01.txt"},"modified":"2023-04-19T19:25:28","modified_gmt":"2023-04-19T14:55:28","slug":"red-hat-security-advisory-2023-1817-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2023-1817-01\/","title":{"rendered":"Red Hat Security Advisory 2023-1817-01"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p>====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p>Synopsis: Moderate: Network observability 1.2.0 for Openshift<br \/>\nAdvisory ID: RHSA-2023:1817-01<br \/>\nProduct: NETOBSERV<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2023:1817<br \/>\nIssue date: 2023-04-18<br \/>\nCVE Names: CVE-2022-41717 CVE-2022-41724 CVE-2022-41725<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p>Network Observability 1.2.0 for OpenShift<\/p>\n<p>Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p>2. Description:<\/p>\n<p>Network Observability 1.2.0 is an OpenShift operator that provides a<br \/>\nmonitoring pipeline to collect and enrich network flows that are produced<br \/>\nby the Network observability eBPF agent.<\/p>\n<p>The operator provides dashboards, metrics, and keeps flows accessible in a<br \/>\nqueryable log store, Grafana Loki. When a FlowCollector is deployed, new<br \/>\ndashboards are available in the Console.<\/p>\n<p>This update contains bug fixes.<\/p>\n<p>Security Fix(es):<\/p>\n<p>* golang: net\/http: An attacker can cause excessive memory growth in a Go<br \/>\nserver accepting HTTP\/2 requests (CVE-2022-41717)<\/p>\n<p>* golang: crypto\/tls: large handshake records may cause panics<br \/>\n(CVE-2022-41724)<\/p>\n<p>* golang: net\/http, mime\/multipart: denial of service from excessive<br \/>\nresource consumption (CVE-2022-41725)<\/p>\n<p>For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p>3. Solution:<\/p>\n<p>Before applying this update, make sure all previously released errata<br \/>\nrelevant to your system have been applied.<\/p>\n<p>For details on how to apply this update, refer to:<\/p>\n<p>https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p>4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p>2161274 &#8211; CVE-2022-41717 golang: net\/http: An attacker can cause excessive memory growth in a Go server accepting HTTP\/2 requests<br \/>\n2178488 &#8211; CVE-2022-41725 golang: net\/http, mime\/multipart: denial of service from excessive resource consumption<br \/>\n2178492 &#8211; CVE-2022-41724 golang: crypto\/tls: large handshake records may cause panics<\/p>\n<p>5. JIRA issues fixed (https:\/\/issues.jboss.org\/):<\/p>\n<p>NETOBSERV-142 &#8211; Network Observability infra health<br \/>\nNETOBSERV-350 &#8211; Connection tracking<br \/>\nNETOBSERV-521 &#8211; Network Observability Operator Seamless Upgrades<br \/>\nNETOBSERV-617 &#8211; eBPF agent: Need to split huge GRPC payloads<br \/>\nNETOBSERV-658 &#8211; Histogram in NetFlow Table<br \/>\nNETOBSERV-684 &#8211; Watch TLS certs &amp; reload<br \/>\nNETOBSERV-696 &#8211; Reporter node behaves the opposite of what it says<br \/>\nNETOBSERV-755 &#8211; Duplicate flows between pods on different nodes<br \/>\nNETOBSERV-772 &#8211; FLP pods and console-plugin doesn&#8217;t restart on CACert name change<br \/>\nNETOBSERV-774 &#8211; Namespace change in CRD result in duplicated ebpf agents<br \/>\nNETOBSERV-785 &#8211; [Maintenance] bump to ubi9 \/ rhel9<br \/>\nNETOBSERV-793 &#8211; flowlogs-pipeline is stuck at ContainerCreating when CA cert is misconfigured<br \/>\nNETOBSERV-844 &#8211; Unable to have a working statusUrl in FlowCollector with Loki Operator 5.6<br \/>\nNETOBSERV-857 &#8211; After some time, it fails to retrieve flows<br \/>\nNETOBSERV-868 &#8211; Migrate ebpf agent to use cilium native golang struct<br \/>\nNETOBSERV-889 &#8211; Flows not observed in Single stack cluster<\/p>\n<p>6. References:<\/p>\n<p>https:\/\/access.redhat.com\/security\/cve\/CVE-2022-41717<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-41724<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-41725<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p>7. Contact:<\/p>\n<p>The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p>Copyright 2023 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p>iQIVAwUBZD7LGdzjgjWX9erEAQh6JA\/9G1Q3O\/6gRVD4As1VnJ+JdMe\/JBigYekX<br \/>\n\/HKyYR3\/eED9bom7Cv7TuHLHYaHYKe3g1hcbi1NQJWf+Mv9NtArcdDcszpFXXZHS<br \/>\n+j2G3wrlt36vaRB\/yHiZk6ZUn7BLxFEeWFnA2PG7\/wEr3JJd21aQ7I\/lvQs2sXoB<br \/>\n1kk2NYjBjxHKZ9mm7K3U8bNiprE1BKQHmpptOgCKl16cFLUcYZ+4LJ5awY+QbQz+<br \/>\n7koMph4zOCTLy8jWoqjyM\/xEOdaUoVH2oAmHrDlQmEuXUJXiUnEkFylD+3+1mHrK<br \/>\noDvO3dEwh0uZedgEQsBODpHK4I1XjkmOlc897qWPLQnFA3phhhV0Ut4U75Ybq0Kn<br \/>\nEnXjhBBm50fxwVGYe0Dx0t8845hoGPcE0gnAYcqQwWcf5p6F+vz+7WcH\/JpdYNf2<br \/>\nXSF\/sjxb8OdWu3x82zeUJo4VOMpt+Sf1Xd0hoHzNIZtu0E4hF8pZlO\/ry6clTYxR<br \/>\nF\/aSCtkC4CYxobU+w95eY23wevB7KL5tQo0EwrL088Ttr3DdeOcsbrErIzoRRhaC<br \/>\nqIOmslkFaJa\/kAt5h7T+bOSzndRC\/2wpPTyet\/eBL8bJ8qs+QD4pDd79uvt+R1Ur<br \/>\nE9cL7ysBOY4znysWwuJYyZuHqVUCsDzKbIzQMa4lQGBBkb517Yj\/HFsrp3W4O\/bA<br \/>\noMzUlJjo8vY=DWsU<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Network observability 1.2.0 for Openshift Advisory ID: RHSA-2023:1817-01 Product: NETOBSERV Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2023:1817 Issue date: 2023-04-18 CVE Names: CVE-2022-41717 CVE-2022-41724 CVE-2022-41725 ==================================================================== 1. Summary: Network Observability 1.2.0 for OpenShift Red Hat Product Security has rated this update as having a security impact &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-40547","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=40547"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40547\/revisions"}],"predecessor-version":[{"id":40548,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40547\/revisions\/40548"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=40547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=40547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=40547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}