Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 10 |
CVE-ID | CVE-2022-1706 CVE-2022-21698 CVE-2022-23772 CVE-2022-23773 CVE-2022-23806 CVE-2022-24675 CVE-2022-24921 CVE-2022-27191 CVE-2022-28327 CVE-2022-29162 |
CWE-ID | CWE-284 CWE-20 CWE-400 CWE-863 CWE-252 CWE-120 CWE-185 CWE-327 CWE-190 CWE-264 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #4 is available. |
Vulnerable software |
toolbox (Red Hat package) Operating systems & Components / Operating system package or component skopeo (Red Hat package) Operating systems & Components / Operating system package or component rust-bootupd (Red Hat package) Operating systems & Components / Operating system package or component rust-afterburn (Red Hat package) Operating systems & Components / Operating system package or component runc (Red Hat package) Operating systems & Components / Operating system package or component python-zipp (Red Hat package) Operating systems & Components / Operating system package or component python-zeroconf (Red Hat package) Operating systems & Components / Operating system package or component python-zake (Red Hat package) Operating systems & Components / Operating system package or component python-yappi (Red Hat package) Operating systems & Components / Operating system package or component python-wsme (Red Hat package) Operating systems & Components / Operating system package or component python-wrapt (Red Hat package) Operating systems & Components / Operating system package or component python-werkzeug (Red Hat package) Operating systems & Components / Operating system package or component python-webtest (Red Hat package) Operating systems & Components / Operating system package or component python-webob (Red Hat package) Operating systems & Components / Operating system package or component python-wcwidth (Red Hat package) Operating systems & Components / Operating system package or component python-warlock (Red Hat package) Operating systems & Components / Operating system package or component python-waitress (Red Hat package) Operating systems & Components / Operating system package or component python-voluptuous (Red Hat package) Operating systems & Components / Operating system package or component python-vine (Red Hat package) Operating systems & Components / Operating system package or component python-tooz (Red Hat package) Operating systems & Components / Operating system package or component python-tenacity (Red Hat package) Operating systems & Components / Operating system package or component python-tempita (Red Hat package) Operating systems & Components / Operating system package or component python-swiftclient (Red Hat package) Operating systems & Components / Operating system package or component python-sushy-oem-idrac (Red Hat package) Operating systems & Components / Operating system package or component python-sushy (Red Hat package) Operating systems & Components / Operating system package or component python-stevedore (Red Hat package) Operating systems & Components / Operating system package or component python-statsd (Red Hat package) Operating systems & Components / Operating system package or component python-sqlparse (Red Hat package) Operating systems & Components / Operating system package or component python-soupsieve (Red Hat package) Operating systems & Components / Operating system package or component python-six (Red Hat package) Operating systems & Components / Operating system package or component python-singledispatch (Red Hat package) Operating systems & Components / Operating system package or component python-simplejson (Red Hat package) Operating systems & Components / Operating system package or component python-simplegeneric (Red Hat package) Operating systems & Components / Operating system package or component python-scciclient (Red Hat package) Operating systems & Components / Operating system package or component python-routes (Red Hat package) Operating systems & Components / Operating system package or component python-rfc3986 (Red Hat package) Operating systems & Components / Operating system package or component python-retrying (Red Hat package) Operating systems & Components / Operating system package or component python-requestsexceptions (Red Hat package) Operating systems & Components / Operating system package or component python-repoze-lru (Red Hat package) Operating systems & Components / Operating system package or component python-redis (Red Hat package) Operating systems & Components / Operating system package or component python-pyrsistent (Red Hat package) Operating systems & Components / Operating system package or component python-pyperclip (Red Hat package) Operating systems & Components / Operating system package or component python-pynacl (Red Hat package) Operating systems & Components / Operating system package or component python-pycdlib (Red Hat package) Operating systems & Components / Operating system package or component python-pycadf (Red Hat package) Operating systems & Components / Operating system package or component python-prometheus_client (Red Hat package) Operating systems & Components / Operating system package or component python-proliantutils (Red Hat package) Operating systems & Components / Operating system package or component python-pint (Red Hat package) Operating systems & Components / Operating system package or component python-pexpect (Red Hat package) Operating systems & Components / Operating system package or component python-pecan (Red Hat package) Operating systems & Components / Operating system package or component python-pbr (Red Hat package) Operating systems & Components / Operating system package or component python-paste-deploy (Red Hat package) Operating systems & Components / Operating system package or component python-paste (Red Hat package) Operating systems & Components / Operating system package or component python-packaging (Red Hat package) Operating systems & Components / Operating system package or component python-osprofiler (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-versionedobjects (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-utils (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-upgradecheck (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-service (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-serialization (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-rootwrap (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-policy (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-middleware (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-metrics (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-messaging (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-log (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-i18n (Red Hat package) Operating systems & Components / Operating system package or component slirp4netns (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-db (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-context (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-config (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-concurrency (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-cache (Red Hat package) Operating systems & Components / Operating system package or component python-osc-lib (Red Hat package) Operating systems & Components / Operating system package or component python-os-traits (Red Hat package) Operating systems & Components / Operating system package or component python-os-service-types (Red Hat package) Operating systems & Components / Operating system package or component python-openstacksdk (Red Hat package) Operating systems & Components / Operating system package or component python-munch (Red Hat package) Operating systems & Components / Operating system package or component python-msgpack (Red Hat package) Operating systems & Components / Operating system package or component python-migrate (Red Hat package) Operating systems & Components / Operating system package or component python-memcached (Red Hat package) Operating systems & Components / Operating system package or component python-logutils (Red Hat package) Operating systems & Components / Operating system package or component python-kombu (Red Hat package) Operating systems & Components / Operating system package or component python-keystonemiddleware (Red Hat package) Operating systems & Components / Operating system package or component python-keystoneclient (Red Hat package) Operating systems & Components / Operating system package or component python-keystoneauth1 (Red Hat package) Operating systems & Components / Operating system package or component python-keyring (Red Hat package) Operating systems & Components / Operating system package or component python-kazoo (Red Hat package) Operating systems & Components / Operating system package or component python-jsonschema (Red Hat package) Operating systems & Components / Operating system package or component python-jsonpath-rw (Red Hat package) Operating systems & Components / Operating system package or component python-iso8601 (Red Hat package) Operating systems & Components / Operating system package or component python-ironic-prometheus-exporter (Red Hat package) Operating systems & Components / Operating system package or component python-ironic-lib (Red Hat package) Operating systems & Components / Operating system package or component python-importlib-metadata (Red Hat package) Operating systems & Components / Operating system package or component python-ifaddr (Red Hat package) Operating systems & Components / Operating system package or component python-hardware (Red Hat package) Operating systems & Components / Operating system package or component python-greenlet (Red Hat package) Operating systems & Components / Operating system package or component python-glanceclient (Red Hat package) Operating systems & Components / Operating system package or component python-futurist (Red Hat package) Operating systems & Components / Operating system package or component python-funcsigs (Red Hat package) Operating systems & Components / Operating system package or component python-flask (Red Hat package) Operating systems & Components / Operating system package or component python-fasteners (Red Hat package) Operating systems & Components / Operating system package or component python-editor (Red Hat package) Operating systems & Components / Operating system package or component python-dracclient (Red Hat package) Operating systems & Components / Operating system package or component python-dogpile-cache (Red Hat package) Operating systems & Components / Operating system package or component python-decorator (Red Hat package) Operating systems & Components / Operating system package or component python-debtcollector (Red Hat package) Operating systems & Components / Operating system package or component python-dataclasses (Red Hat package) Operating systems & Components / Operating system package or component python-construct (Red Hat package) Operating systems & Components / Operating system package or component python-colorama (Red Hat package) Operating systems & Components / Operating system package or component python-cliff (Red Hat package) Operating systems & Components / Operating system package or component python-cinderclient (Red Hat package) Operating systems & Components / Operating system package or component python-cachetools (Red Hat package) Operating systems & Components / Operating system package or component python-beautifulsoup4 (Red Hat package) Operating systems & Components / Operating system package or component python-bcrypt (Red Hat package) Operating systems & Components / Operating system package or component python-automaton (Red Hat package) Operating systems & Components / Operating system package or component python-appdirs (Red Hat package) Operating systems & Components / Operating system package or component python-amqp (Red Hat package) Operating systems & Components / Operating system package or component python-alembic (Red Hat package) Operating systems & Components / Operating system package or component python-SecretStorage (Red Hat package) Operating systems & Components / Operating system package or component pysnmp (Red Hat package) Operating systems & Components / Operating system package or component pyparsing (Red Hat package) Operating systems & Components / Operating system package or component podman (Red Hat package) Operating systems & Components / Operating system package or component ovn22.06 (Red Hat package) Operating systems & Components / Operating system package or component ovn22.03 (Red Hat package) Operating systems & Components / Operating system package or component openvswitch2.17 (Red Hat package) Operating systems & Components / Operating system package or component openstack-ironic-python-agent (Red Hat package) Operating systems & Components / Operating system package or component openstack-ironic-inspector (Red Hat package) Operating systems & Components / Operating system package or component openstack-ironic (Red Hat package) Operating systems & Components / Operating system package or component openshift-kuryr (Red Hat package) Operating systems & Components / Operating system package or component openshift-clients (Red Hat package) Operating systems & Components / Operating system package or component openshift-ansible (Red Hat package) Operating systems & Components / Operating system package or component openshift (Red Hat package) Operating systems & Components / Operating system package or component libsodium (Red Hat package) Operating systems & Components / Operating system package or component libslirp (Red Hat package) Operating systems & Components / Operating system package or component kata-containers (Red Hat package) Operating systems & Components / Operating system package or component ignition (Red Hat package) Operating systems & Components / Operating system package or component haproxy (Red Hat package) Operating systems & Components / Operating system package or component fuse-overlayfs (Red Hat package) Operating systems & Components / Operating system package or component crun (Red Hat package) Operating systems & Components / Operating system package or component criu (Red Hat package) Operating systems & Components / Operating system package or component cri-tools (Red Hat package) Operating systems & Components / Operating system package or component cri-o (Red Hat package) Operating systems & Components / Operating system package or component coreos-installer (Red Hat package) Operating systems & Components / Operating system package or component containers-common (Red Hat package) Operating systems & Components / Operating system package or component containernetworking-plugins (Red Hat package) Operating systems & Components / Operating system package or component container-selinux (Red Hat package) Operating systems & Components / Operating system package or component console-login-helper-messages (Red Hat package) Operating systems & Components / Operating system package or component conmon (Red Hat package) Operating systems & Components / Operating system package or component butane (Red Hat package) Operating systems & Components / Operating system package or component buildah (Red Hat package) Operating systems & Components / Operating system package or component atomic-openshift-service-idler (Red Hat package) Operating systems & Components / Operating system package or component Red Hat OpenShift Container Platform Client/Desktop applications / Software for system administration |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 10 vulnerabilities.
EUVDB-ID: #VU63493
Risk: Low
CVSSv4.0: 3.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-1706
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in ignition configs. A remote user on the local network can bypass implemented security restrictions and obtain sensitive information.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU61599
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-21698
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within method label cardinality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU62038
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-23772
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the Rat.SetString(0 function in math/big. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU62037
Risk: Low
CVSSv4.0: 2.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear]
CVE-ID: CVE-2022-23773
CWE-ID:
CWE-863 - Incorrect Authorization
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists within cmd/go, which can misinterpret branch names that falsely appear to be version tags. This can lead to a situation where an attacker can bypass implemented security restrictions and perform restricted actions, e.g. create tags when access was granted to create branches only.
Install updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU62036
Risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-23806
CWE-ID:
CWE-252 - Unchecked Return Value
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to unchecked return value within the Curve.IsOnCurve() function in crypto/elliptic. A remote attacker can force the application to incorrectly return true in situations with a big.Int value that is not a valid field element. As a result, an attacker can modify application flow, which can lead to unauthorized data modification or denial of service.
Install updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU64266
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-24675
CWE-ID:
CWE-120 - Buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the Golang's library encoding/pem. A remote attacker can send to victim a large (more than 5 MB) PEM input to cause a stack overflow in Decode and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU61227
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-24921
CWE-ID:
CWE-185 - Incorrect Regular Expression
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in regexp.Compile in Go. A remote attacker can pass specially crafted input to the application and perform regular expression denial of service (ReDoS) attack.
Install updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU62039
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-27191
CWE-ID:
CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in golang.org/x/crypto/ssh before 0.0.0-20220314234659-1baeb1ce4c0b, as used in Go programming language. A remote attacker can crash a server in certain circumstances involving AddHostKey.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU64269
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-28327
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to integer overflow in the Golang's library crypto/elliptic. A remote attacker can send a specially crafted scalar input longer than 32 bytes to cause P256().ScalarMult or P256().ScalarBaseMult to panic and perform a denial of service attack.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU63090
Risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-29162
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to containers are incorrectly started with non-empty inheritable Linux process capabilities, which leads to security restrictions bypass and privilege escalation.
MitigationInstall updates from vendor's website.
toolbox (Red Hat package): before 0.0.9-1.rhaos4.11.el8
skopeo (Red Hat package): before 1.5.2-3.rhaos4.11.el8
rust-bootupd (Red Hat package): before 0.2.5-3.rhaos4.11.el8
rust-afterburn (Red Hat package): before 5.3.0-1.rhaos4.11.el8
runc (Red Hat package): before 1.1.2-1.rhaos4.11.el8
python-zipp (Red Hat package): before 0.5.1-3.el8
python-zeroconf (Red Hat package): before 0.24.4-2.el8
python-zake (Red Hat package): before 0.2.2-19.el8
python-yappi (Red Hat package): before 1.0-3.el8
python-wsme (Red Hat package): before 0.11.0-0.20220216004816.80bda90.el8
python-wrapt (Red Hat package): before 1.11.2-4.el8
python-werkzeug (Red Hat package): before 2.0.3-1.el8
python-webtest (Red Hat package): before 2.0.33-5.el8
python-webob (Red Hat package): before 1.8.5-5.el8
python-wcwidth (Red Hat package): before 0.1.7-15.el8
python-warlock (Red Hat package): before 1.3.3-2.el8
python-waitress (Red Hat package): before 2.0.0-2.el8
python-voluptuous (Red Hat package): before 0.11.7-3.el8
python-vine (Red Hat package): before 1.3.0-5.el8
python-tooz (Red Hat package): before 2.11.1-0.20220509215238.96f91b9.el8
python-tenacity (Red Hat package): before 6.2.0-2.el8
python-tempita (Red Hat package): before 0.5.1-25.el8
python-swiftclient (Red Hat package): before 3.13.1-0.20220509204112.4989d94.el8
python-sushy-oem-idrac (Red Hat package): before 4.0.0-0.20220324125409.7b75e6e.el8
python-sushy (Red Hat package): before 4.1.1-0.20220302175405.c769149.el8
python-stevedore (Red Hat package): before 3.5.0-0.20220509195112.442f157.el8
python-statsd (Red Hat package): before 3.2.1-17.el8
python-sqlparse (Red Hat package): before 0.2.4-10.el8
python-soupsieve (Red Hat package): before 2.1.0-2.el8
python-six (Red Hat package): before 1.15.0-3.el8
python-singledispatch (Red Hat package): before 3.4.0.3-19.el8
python-simplejson (Red Hat package): before 3.17.0-2.el8
python-simplegeneric (Red Hat package): before 0.8.1-18.el8
python-scciclient (Red Hat package): before 0.11.1-0.20220216020832.a84332b.el8
python-routes (Red Hat package): before 2.4.1-12.el8
python-rfc3986 (Red Hat package): before 1.2.0-6.el8
python-retrying (Red Hat package): before 1.2.3-22.el8
python-requestsexceptions (Red Hat package): before 1.4.0-0.20220215231659.d7ac0ff.el8
python-repoze-lru (Red Hat package): before 0.7-7.el8
python-redis (Red Hat package): before 3.3.8-2.el8
python-pyrsistent (Red Hat package): before 0.16.0-4.el8
python-pyperclip (Red Hat package): before 1.6.4-7.el8
python-pynacl (Red Hat package): before 1.3.0-6.el8
python-pycdlib (Red Hat package): before 1.11.0-4.el8
python-pycadf (Red Hat package): before 3.1.1-0.20220215232623.4179996.el8
python-prometheus_client (Red Hat package): before 0.7.1-3.el8
python-proliantutils (Red Hat package): before 2.13.2-0.20220509214147.8c7b6b1.el8
python-pint (Red Hat package): before 0.10.1-3.el8
python-pexpect (Red Hat package): before 4.6-3.el8
python-pecan (Red Hat package): before 1.3.2-10.el8
python-pbr (Red Hat package): before 5.5.1-2.el8
python-paste-deploy (Red Hat package): before 2.0.1-5.el8
python-paste (Red Hat package): before 3.2.4-2.el8
python-packaging (Red Hat package): before 20.4-2.el8
python-osprofiler (Red Hat package): before 3.4.3-0.20220509214403.3286301.el8
python-oslo-versionedobjects (Red Hat package): before 2.6.0-0.20220509202736.25d34d6.el8
python-oslo-utils (Red Hat package): before 4.13.0-0.20220509213520.de4429f.el8
python-oslo-upgradecheck (Red Hat package): before 1.5.0-0.20220509195112.1559e03.el8
python-oslo-service (Red Hat package): before 2.8.0-0.20220509203713.6552b9a.el8
python-oslo-serialization (Red Hat package): before 4.3.0-0.20220509195921.6910f75.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20220509204453.1b1b960.el8
python-oslo-policy (Red Hat package): before 3.12.1-0.20220509221328.9673a74.el8
python-oslo-middleware (Red Hat package): before 4.5.1-0.20220509203328.2f72b30.el8
python-oslo-metrics (Red Hat package): before 0.3.0-0.20220216012738.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.13.0-0.20220509210748.2d090b5.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20220216002407.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20220216011159.b031d17.el8
slirp4netns (Red Hat package): before 1.1.8-1.rhaos4.11.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20220216003829.be2cc6a.el8
python-oslo-context (Red Hat package): before 4.1.0-0.20220509205437.3400cc2.el8
python-oslo-config (Red Hat package): before 8.8.0-0.20220509202553.64c82a0.el8
python-oslo-concurrency (Red Hat package): before 4.5.1-0.20220509221157.145f060.el8
python-oslo-cache (Red Hat package): before 2.8.1-0.20220216000746.40946a9.el8
python-osc-lib (Red Hat package): before 2.5.0-0.20220509211843.78d276e.el8
python-os-traits (Red Hat package): before 2.7.0-0.20220509205801.3d1dbf0.el8
Red Hat OpenShift Container Platform: before 4.11.0
python-os-service-types (Red Hat package): before 1.7.0-0.20220215231659.0b2f473.el8
python-openstacksdk (Red Hat package): before 0.61.0-0.20220509201549.26c9bc2.el8
python-munch (Red Hat package): before 2.3.2-7.el8
python-msgpack (Red Hat package): before 0.6.2-2.el8
python-migrate (Red Hat package): before 0.13.0-2.el8
python-memcached (Red Hat package): before 1.58-12.el8
python-logutils (Red Hat package): before 0.3.5-7.1.el8
python-kombu (Red Hat package): before 4.6.6-8.el8
python-keystonemiddleware (Red Hat package): before 9.4.0-0.20220509211054.8a05709.el8
python-keystoneclient (Red Hat package): before 4.4.0-0.20220509200759.100253d.el8
python-keystoneauth1 (Red Hat package): before 4.5.0-0.20220509213157.8da0a63.el8
python-keyring (Red Hat package): before 21.0.0-2.el8
python-kazoo (Red Hat package): before 2.7.0-2.el8
python-jsonschema (Red Hat package): before 3.2.0-6.el8
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el8
python-iso8601 (Red Hat package): before 0.1.12-9.el8
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20220324125409.db1a824.el8
python-ironic-lib (Red Hat package): before 5.1.1-0.20220225151335.e205816.el8
python-importlib-metadata (Red Hat package): before 1.7.0-2.el8
python-ifaddr (Red Hat package): before 0.1.6-6.el8
python-hardware (Red Hat package): before 0.29.0-0.20220216015636.7662a1d.el8
python-greenlet (Red Hat package): before 0.4.14-6.el8
python-glanceclient (Red Hat package): before 3.6.0-0.20220509212414.626c500.el8
python-futurist (Red Hat package): before 2.4.1-0.20220509215250.159d752.el8
python-funcsigs (Red Hat package): before 1.0.2-17.el8
python-flask (Red Hat package): before 1.1.1-2.el8
python-fasteners (Red Hat package): before 0.14.1-21.el8
python-editor (Red Hat package): before 1.0.4-5.el8
python-dracclient (Red Hat package): before 8.0.0-0.20220509201613.9c7499c.el8
python-dogpile-cache (Red Hat package): before 1.1.2-2.el8
python-decorator (Red Hat package): before 4.4.0-6.el8
python-debtcollector (Red Hat package): before 2.5.0-0.20220509211533.a6b46c5.el8
python-dataclasses (Red Hat package): before 0.8-3.el8
python-construct (Red Hat package): before 2.10.56-2.el8
python-colorama (Red Hat package): before 0.4.1-2.el8
python-cliff (Red Hat package): before 3.10.1-0.20220509200732.a04a48f.el8
python-cinderclient (Red Hat package): before 8.3.0-0.20220509212734.ee59b68.el8
python-cachetools (Red Hat package): before 3.1.0-3.el8
python-beautifulsoup4 (Red Hat package): before 4.9.3-2.el8
python-bcrypt (Red Hat package): before 3.1.6-3.el8
python-automaton (Red Hat package): before 2.5.0-0.20220509195848.aaca110.el8
python-appdirs (Red Hat package): before 1.4.0-8.el8
python-amqp (Red Hat package): before 2.5.2-8.el8
python-alembic (Red Hat package): before 1.4.2-6.el8
python-SecretStorage (Red Hat package): before 2.3.1-9.el8
pysnmp (Red Hat package): before 4.4.8-3.el8
pyparsing (Red Hat package): before 2.3.1-2.el8
podman (Red Hat package): before 4.0.2-6.rhaos4.11.el8
ovn22.06 (Red Hat package): before 22.06.0-27.el8fdp
ovn22.03 (Red Hat package): before 22.03.0-37.el8fdp
openvswitch2.17 (Red Hat package): before 2.17.0-22.el8fdp
openstack-ironic-python-agent (Red Hat package): before 8.6.1-0.20220623075054.1d50c23.el8
openstack-ironic-inspector (Red Hat package): before 10.12.1-0.20220513095437.6dd37e5.el8
openstack-ironic (Red Hat package): before 20.2.1-0.20220628175043.b5ed57a.el8
openshift-kuryr (Red Hat package): before 4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8
openshift-clients (Red Hat package): before 4.11.0-202207291716.p0.g7075089.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.11.0-202206240216.p0.g9de1722.assembly.stream.el8
openshift (Red Hat package): before 4.11.0-202207082037.p0.g9546431.assembly.stream.el8
libsodium (Red Hat package): before 1.0.16-5.el8
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
kata-containers (Red Hat package): before 2.4.2-1.el8
ignition (Red Hat package): before 2.14.0-3.rhaos4.11.el8
haproxy (Red Hat package): before 2.2.24-1.el8
fuse-overlayfs (Red Hat package): before 1.9-1.rhaos4.11.el8
crun (Red Hat package): before 1.4.2-1.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
cri-tools (Red Hat package): before 1.24.2-4.1.el8
cri-o (Red Hat package): before 1.24.1-11.rhaos4.11.gitb0d2ef3.el8
coreos-installer (Red Hat package): before 0.15.0-2.rhaos4.11.el8
containers-common (Red Hat package): before 1-21.rhaos4.11.el8
containernetworking-plugins (Red Hat package): before 1.0.1-5.rhaos4.11.el8
container-selinux (Red Hat package): before 2.188.0-1.rhaos4.11.el8
console-login-helper-messages (Red Hat package): before 0.20.3-2.rhaos4.11.el8
conmon (Red Hat package): before 2.1.2-2.rhaos4.11.el8
butane (Red Hat package): before 0.15.0-1.rhaos4.11.el8
buildah (Red Hat package): before 1.23.4-2.el8
atomic-openshift-service-idler (Red Hat package): before 4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8
CPE2.3https://access.redhat.com/errata/RHSA-2022:5068
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.