VARIoT IoT vulnerabilities database
| VAR-202208-0387 | CVE-2022-24010 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cwmpd binary. (DoS) It may be in a state
| VAR-202208-0385 | CVE-2022-24007 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cfm binary. (DoS) It may be in a state
| VAR-202208-0393 | CVE-2022-24011 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the device_list binary. (DoS) It may be in a state
| VAR-202208-0392 | CVE-2022-24005 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the ap_steer binary. (DoS) It may be in a state
| VAR-202208-0394 | CVE-2022-24024 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the rtk_ate binary. (DoS) It may be in a state
| VAR-202208-0391 | CVE-2022-24026 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the telnet_ate_monitor binary. (DoS) It may be in a state
| VAR-202208-0398 | CVE-2022-24027 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the libcommon.so binary. (DoS) It may be in a state
| VAR-202208-0397 | CVE-2022-24017 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the miniupnpd binary. (DoS) It may be in a state
| VAR-202208-0401 | CVE-2022-24025 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the sntp binary. (DoS) It may be in a state
| VAR-202208-0400 | CVE-2022-24021 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the online_process binary. (DoS) It may be in a state
| VAR-202208-0395 | CVE-2022-24016 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the mesh_status_check binary. (DoS) It may be in a state
| VAR-202208-0396 | CVE-2022-24018 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the multiWAN binary. (DoS) It may be in a state
| VAR-202208-0390 | CVE-2022-24019 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the netctrl binary. (DoS) It may be in a state
| VAR-202208-0399 | CVE-2022-24028 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the libcommonprod.so binary. (DoS) It may be in a state
| VAR-202208-0402 | CVE-2022-24009 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the confsrv binary. (DoS) It may be in a state
| VAR-202208-0381 | CVE-2022-24008 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the confcli binary. (DoS) It may be in a state
| VAR-202208-0389 | CVE-2022-24012 | TCL Technology of linkhub mesh wifi ac1200 Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.6 Severity: CRITICAL |
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the fota binary. (DoS) It may be in a state
| VAR-202208-0609 | CVE-2022-36832 | Samsung's Cameralyzer Vulnerability in |
CVSS V2: - CVSS V3: 3.3 Severity: LOW |
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege. Samsung's Cameralyzer Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202208-0404 | CVE-2022-37434 | zlib Buffer error vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference). Bugs fixed (https://bugzilla.redhat.com/):
2142707 - CVE-2022-42920 Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing
5. Bugs fixed (https://bugzilla.redhat.com/):
2113814 - CVE-2022-32189 golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service
2124669 - CVE-2022-27664 golang: net/http: handle server errors after sending GOAWAY
2132867 - CVE-2022-2879 golang: archive/tar: unbounded memory consumption when reading headers
2132868 - CVE-2022-2880 golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters
2132872 - CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps
2148199 - CVE-2022-39278 Istio: Denial of service attack via a specially crafted message
2148661 - CVE-2022-3962 kiali: error message spoofing in kiali UI
2156729 - CVE-2021-4238 goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be
5. JIRA issues fixed (https://issues.jboss.org/):
OSSM-1977 - Support for Istio Gateway API in Kiali
OSSM-2083 - Update maistra/istio 2.3 to Istio 1.14.5
OSSM-2147 - Unexpected validation message on Gateway object
OSSM-2169 - Member controller doesn't retry on conflict
OSSM-2170 - Member namespaces aren't cleaned up when a cluster-scoped SMMR is deleted
OSSM-2179 - Wasm plugins only support OCI images with 1 layer
OSSM-2184 - Istiod isn't allowed to delete analysis distribution report configmap
OSSM-2188 - Member namespaces not cleaned up when SMCP is deleted
OSSM-2189 - If multiple SMCPs exist in a namespace, the controller reconciles them all
OSSM-2190 - The memberroll controller reconciles SMMRs with invalid name
OSSM-2232 - The member controller reconciles ServiceMeshMember with invalid name
OSSM-2241 - Remove v2.0 from Create ServiceMeshControlPlane Form
OSSM-2251 - CVE-2022-3962 openshift-istio-kiali-container: kiali: content spoofing [ossm-2.3]
OSSM-2308 - add root CA certificates to kiali container
OSSM-2315 - be able to customize openshift auth timeouts
OSSM-2324 - Gateway injection does not work when pods are created by cluster admins
OSSM-2335 - Potential hang using Traces scatterplot chart
OSSM-2338 - Federation deployment does not need router mode sni-dnat
OSSM-2344 - Restarting istiod causes Kiali to flood CRI-O with port-forward requests
OSSM-2375 - Istiod should log member namespaces on every update
OSSM-2376 - ServiceMesh federation stops working after the restart of istiod pod
OSSM-535 - Support validationMessages in SMCP
OSSM-827 - ServiceMeshMembers point to wrong SMCP name
6. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2022-10-27-6 Additional information for APPLE-SA-2022-10-24-3 macOS Monterey 12.6.1
macOS Monterey 12.6.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/HT213494.
AppleMobileFileIntegrity
Available for: macOS Monterey
Impact: An app may be able to modify protected parts of the file
system
Description: This issue was addressed by removing additional
entitlements.
CVE-2022-42825: Mickey Jin (@patch1t)
Audio
Available for: macOS Monterey
Impact: Parsing a maliciously crafted audio file may lead to
disclosure of user information
Description: The issue was addressed with improved memory handling.
CVE-2022-42798: Anonymous working with Trend Micro Zero Day
Initiative
Entry added October 27, 2022
Kernel
Available for: macOS Monterey
Impact: An app may be able to execute arbitrary code with kernel
privileges
Description: A memory corruption issue was addressed with improved
state management.
CVE-2022-32944: Tim Michaud (@TimGMichaud) of Moveworks.ai
Entry added October 27, 2022
Kernel
Available for: macOS Monterey
Impact: An app may be able to execute arbitrary code with kernel
privileges
Description: A race condition was addressed with improved locking.
CVE-2022-42803: Xinru Chi of Pangu Lab, John Aakerblom (@jaakerblom)
Entry added October 27, 2022
Kernel
Available for: macOS Monterey
Impact: An app may be able to execute arbitrary code with kernel
privileges
Description: A logic issue was addressed with improved checks.
CVE-2022-42801: Ian Beer of Google Project Zero
Entry added October 27, 2022
ppp
Available for: macOS Monterey
Impact: A buffer overflow may result in arbitrary code execution
Description: The issue was addressed with improved bounds checks.
CVE-2022-32941: an anonymous researcher
Entry added October 27, 2022
Ruby
Available for: macOS Monterey
Impact: A remote user may be able to cause unexpected app termination
or arbitrary code execution
Description: A memory corruption issue was addressed by updating Ruby
to version 2.6.10.
CVE-2022-28739
Sandbox
Available for: macOS Monterey
Impact: An app with root privileges may be able to access private
information
Description: This issue was addressed with improved data protection.
CVE-2022-32862: an anonymous researcher
zlib
Available for: macOS Monterey
Impact: A user may be able to cause unexpected app termination or
arbitrary code execution
Description: This issue was addressed with improved checks.
CVE-2022-37434: Evgeny Legerov
CVE-2022-42800: Evgeny Legerov
Entry added October 27, 2022
Additional recognition
Calendar
We would like to acknowledge an anonymous researcher for their
assistance.
macOS Monterey 12.6.1 may be obtained from the Mac App Store or
Apple's Software Downloads web site:
https://support.apple.com/downloads/
All information is also posted on the Apple Security Updates
web site: https://support.apple.com/en-us/HT201222. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: zlib security update
Advisory ID: RHSA-2022:7314-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2022:7314
Issue date: 2022-11-02
CVE Names: CVE-2022-37434
====================================================================
1. Summary:
An update for zlib is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64
3. Description:
The zlib packages provide a general-purpose lossless data compression
library that is used by many different programs.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Package List:
Red Hat Enterprise Linux AppStream (v. 9):
aarch64:
minizip-compat-debuginfo-1.2.11-32.el9_0.aarch64.rpm
zlib-debuginfo-1.2.11-32.el9_0.aarch64.rpm
zlib-debugsource-1.2.11-32.el9_0.aarch64.rpm
zlib-devel-1.2.11-32.el9_0.aarch64.rpm
ppc64le:
minizip-compat-debuginfo-1.2.11-32.el9_0.ppc64le.rpm
zlib-debuginfo-1.2.11-32.el9_0.ppc64le.rpm
zlib-debugsource-1.2.11-32.el9_0.ppc64le.rpm
zlib-devel-1.2.11-32.el9_0.ppc64le.rpm
s390x:
minizip-compat-debuginfo-1.2.11-32.el9_0.s390x.rpm
zlib-debuginfo-1.2.11-32.el9_0.s390x.rpm
zlib-debugsource-1.2.11-32.el9_0.s390x.rpm
zlib-devel-1.2.11-32.el9_0.s390x.rpm
x86_64:
minizip-compat-debuginfo-1.2.11-32.el9_0.i686.rpm
minizip-compat-debuginfo-1.2.11-32.el9_0.x86_64.rpm
zlib-debuginfo-1.2.11-32.el9_0.i686.rpm
zlib-debuginfo-1.2.11-32.el9_0.x86_64.rpm
zlib-debugsource-1.2.11-32.el9_0.i686.rpm
zlib-debugsource-1.2.11-32.el9_0.x86_64.rpm
zlib-devel-1.2.11-32.el9_0.i686.rpm
zlib-devel-1.2.11-32.el9_0.x86_64.rpm
Red Hat Enterprise Linux BaseOS (v. 9):
Source:
zlib-1.2.11-32.el9_0.src.rpm
aarch64:
minizip-compat-debuginfo-1.2.11-32.el9_0.aarch64.rpm
zlib-1.2.11-32.el9_0.aarch64.rpm
zlib-debuginfo-1.2.11-32.el9_0.aarch64.rpm
zlib-debugsource-1.2.11-32.el9_0.aarch64.rpm
ppc64le:
minizip-compat-debuginfo-1.2.11-32.el9_0.ppc64le.rpm
zlib-1.2.11-32.el9_0.ppc64le.rpm
zlib-debuginfo-1.2.11-32.el9_0.ppc64le.rpm
zlib-debugsource-1.2.11-32.el9_0.ppc64le.rpm
s390x:
minizip-compat-debuginfo-1.2.11-32.el9_0.s390x.rpm
zlib-1.2.11-32.el9_0.s390x.rpm
zlib-debuginfo-1.2.11-32.el9_0.s390x.rpm
zlib-debugsource-1.2.11-32.el9_0.s390x.rpm
x86_64:
minizip-compat-debuginfo-1.2.11-32.el9_0.i686.rpm
minizip-compat-debuginfo-1.2.11-32.el9_0.x86_64.rpm
zlib-1.2.11-32.el9_0.i686.rpm
zlib-1.2.11-32.el9_0.x86_64.rpm
zlib-debuginfo-1.2.11-32.el9_0.i686.rpm
zlib-debuginfo-1.2.11-32.el9_0.x86_64.rpm
zlib-debugsource-1.2.11-32.el9_0.i686.rpm
zlib-debugsource-1.2.11-32.el9_0.x86_64.rpm
Red Hat CodeReady Linux Builder (v. 9):
aarch64:
minizip-compat-debuginfo-1.2.11-32.el9_0.aarch64.rpm
zlib-debuginfo-1.2.11-32.el9_0.aarch64.rpm
zlib-debugsource-1.2.11-32.el9_0.aarch64.rpm
zlib-static-1.2.11-32.el9_0.aarch64.rpm
ppc64le:
minizip-compat-debuginfo-1.2.11-32.el9_0.ppc64le.rpm
zlib-debuginfo-1.2.11-32.el9_0.ppc64le.rpm
zlib-debugsource-1.2.11-32.el9_0.ppc64le.rpm
zlib-static-1.2.11-32.el9_0.ppc64le.rpm
s390x:
minizip-compat-debuginfo-1.2.11-32.el9_0.s390x.rpm
zlib-debuginfo-1.2.11-32.el9_0.s390x.rpm
zlib-debugsource-1.2.11-32.el9_0.s390x.rpm
zlib-static-1.2.11-32.el9_0.s390x.rpm
x86_64:
minizip-compat-debuginfo-1.2.11-32.el9_0.i686.rpm
minizip-compat-debuginfo-1.2.11-32.el9_0.x86_64.rpm
zlib-debuginfo-1.2.11-32.el9_0.i686.rpm
zlib-debuginfo-1.2.11-32.el9_0.x86_64.rpm
zlib-debugsource-1.2.11-32.el9_0.i686.rpm
zlib-debugsource-1.2.11-32.el9_0.x86_64.rpm
zlib-static-1.2.11-32.el9_0.i686.rpm
zlib-static-1.2.11-32.el9_0.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2022-37434
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/security/updates/classification#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY2K9ItzjgjWX9erEAQiHfxAAlO5bDXesPL2aHyX6C15K0NCSqYYSugpc
jh5XWHtBDSf0tFLDI7D0ru2cDe98WRoQ0MJNZA2HNwCx1tznW6jJX4cnYHlnCeC4
/thKFW1MfXV/n40Fu7Boq8BmrLCHixTwe/pGuz19YYIJeKexdDmN5mf5tYp01BXW
uDwCfC0VgwU0zFcG4TXvHZdI+CDTFr/azkC/aXpFCVyTMZAw5ZiTRgu1WL/UKyrU
prhsHcxXoICqJbJYu5gql3QGaXwGXYP/N7RMlfaSI60FL6trDE5+1f7eJTugsxwv
jyaarOy7AWlno/lEMrffQ7/9k9xUpowt8Qt0LDjuTP3tPlGULkyb1DYQOUkttniD
b4X4k/DY5PBwZTOeGsPBbFcvliwcwgMVqmGfZHZcsRc7VSsGzrGsyowVxvxJqasP
VPjOMOKeQVEf3Kpl0Nvfd5D2k24NlqgXpiLpSevwkJTi6c7VWUPrGGCTmL5XUy8T
4ISiB+bDwlmI5LxhqOyVdHLeVnNaeR6wxEfQ855CDCXMAeElHodi+KxGvqrWceVQ
pEinvfduBT1Y8HO8ztDWYJ6KM1r/9JOTiACpMoKGw5KqSQnSrPwCuoZIwlXK6fiE
C26HKcnaq3GK0IDkT+LaVUtl4k8Ja8V4Rv0OMwU1JgbwTUTI/iQweKDAldn8/cbA
NVQfk+Oscic=3u2M
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.11.12. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2022:7200
Space precludes documenting all of the container images in this advisory.
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.11.12-x86_64
The image digest is
sha256:0ca14e0f692391970fc23f88188f2a21f35a5ba24fe2f3cb908fd79fa46458e6
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.11.12-s390x
The image digest is
sha256:7b9b21e35286e67473a0c4c28c84e3d806eb30364682a6b072b79109c2d22c6b
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.11.12-ppc64le
The image digest is
sha256:c61315b1257695b5f86d2782a70909227e004cd7cd30236c6f94a9e4ecf24ecb
(For aarch64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.11.12-aarch64
The image digest is
sha256:c70dc68aef64280d3cba9a056af29438943b30c260a7156893e1bae5c6c5ce3f
All OpenShift Container Platform 4.11 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html
3. Solution:
For OpenShift Container Platform 4.11 see the following documentation,
which will be updated shortly for this release, for important instructions
on how to upgrade your cluster and fully apply this asynchronous errata
update:
https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html
4. Bugs fixed (https://bugzilla.redhat.com/):
2042826 - [SNO] the replicas of ingresscontroller/default is 2 on new installed SNO private cluster
2092839 - Downward API (annotations) is missing PCI information when using the tuning metaPlugin on SR-IOV Networks
2092918 - CVE-2022-30321 go-getter: unsafe download (issue 1 of 3)
2092923 - CVE-2022-30322 go-getter: unsafe download (issue 2 of 3)
2092925 - CVE-2022-30323 go-getter: unsafe download (issue 3 of 3)
2092928 - CVE-2022-26945 go-getter: command injection vulnerability
2099800 - Bump to kubernetes 1.24.6
2109487 - machine-controller is case sensitive which can lead to false/positive errors
5. JIRA issues fixed (https://issues.jboss.org/):
OCPBUGS-1099 - Missing $SEARCH domain in /etc/resolve.conf for OCP v4.9.31 cluster
OCPBUGS-1346 - OpenStack UPI scripts do not create server group for Computes
OCPBUGS-1658 - Whereabouts should allow non default interfaces to Pod IP list [backport 4.11]
OCPBUGS-1713 - Kuryr-Controller Restarting on KuryrPort with missing pod
OCPBUGS-1955 - [4.11] Dual stack cluster fails on installation when multi-path routing entries exist
OCPBUGS-1972 - [IPI on Baremetal] ipv6 support issue in metal3-httpd
OCPBUGS-1984 - Install Helm chart form doesn't allow the user select a specific version
OCPBUGS-2011 - [4.11] ironic clear_job_queue and reset_idrac pending issues
OCPBUGS-2014 - CI: Backend unit tests fails because devfile registry was updated (mock response)
OCPBUGS-2042 - [2102088] 4.11 CatalogSourcesUnhealthy error in subscription When upgrading ptp-operator
OCPBUGS-2046 - Remove policy/v1beta1 in 4.11 and later
OCPBUGS-2050 - [release-4.11] DNS operator does not reconcile the openshift-dns namespace
OCPBUGS-2092 - Use floating tags in golang imagestream
OCPBUGS-2112 - [release-4.11] Address e2e failures due to pod security
OCPBUGS-2113 - [4.11] etcd and kube-apiserver pods get restarted due to failed liveness probes while deleting/re-creating pods on SNO
OCPBUGS-2140 - member loses rights after some other user login in openid / group sync
OCPBUGS-2293 - CVO skips reconciling the installed optional resources in the 4.11 to 4.12 upgrade
OCPBUGS-2320 - [release-4.11] Remove namespace and name from gathered DVO metrics
OCPBUGS-2451 - e2e tests: Installs Red Hat Integration - 3scale operator test is failing due to change of Operator name
OCPBUGS-2528 - dns-default pod missing "target.workload.openshift.io/management:" annotation
OCPBUGS-2606 - [release-4.11] go.mod should beworking with golang-1.17 and golang-1.18
OCPBUGS-2616 - e2e-gcp-builds is permafailing
OCPBUGS-2626 - Worker creation fails within provider networks (as primary and secondary)
OCPBUGS-2640 - prometheus-k8s-0 ends in CrashLoopBackOff with evel=error err="opening storage failed: /prometheus/chunks_head/000002: invalid magic number 0" on SNO after hard reboot tests
OCPBUGS-2658 - [4.11] VPA E2Es fail due to CSV name mismatch
OCPBUGS-2766 - 'oc login' should be robust in the face of gather failures
OCPBUGS-2780 - Import: Advanced option sentence is splited into two parts and headlines has no padding
OCPBUGS-449 - KubeDaemonSetRolloutStuck alert using incorrect metric in 4.9 and 4.10
OCPBUGS-526 - Prerelease report bug link should be updated to JIRA instead of Bugzilla
OCPBUGS-668 - Prefer local dns does not work expectedly on OCPv4.11
OCPBUGS-673 - crio occasionally fails to start during deployment
OCPBUGS-689 - [2112237] [ Cluster storage Operator 4.x(10/11) ] DefaultStorageClassController report fake message "No default StorageClass for this platform" on Alicloud, IBM
OCPBUGS-744 - [4.11] Spoke BMH stuck ?provisioning? after changing a BIOS attribute via the converged workflow
OCPBUGS-947 - [4.11] Rebase openshift/etcd 4.11 onto 3.5.5
OCPBUGS-955 - [2087981] PowerOnVM_Task is deprecated use PowerOnMultiVM_Task for DRS ClusterRecommendation
6. Summary:
OpenShift API for Data Protection (OADP) 1.1.1 is now available. Description:
OpenShift API for Data Protection (OADP) enables you to back up and restore
application resources, persistent volume data, and internal container
images to external backup storage. OADP enables both file system-based and
snapshot-based backups for persistent volumes. Bugs fixed (https://bugzilla.redhat.com/):
2064702 - CVE-2022-27191 golang: crash in a golang.org/x/crypto/ssh server
2107386 - CVE-2022-30632 golang: path/filepath: stack exhaustion in Glob
2107388 - CVE-2022-30635 golang: encoding/gob: stack exhaustion in Decoder.Decode
2124668 - CVE-2022-32190 golang: net/url: JoinPath does not strip relative path components in all circumstances
2124669 - CVE-2022-27664 golang: net/http: handle server errors after sending GOAWAY
5. JIRA issues fixed (https://issues.jboss.org/):
OADP-1002 - DataMover: Backup partially fails for a namespace without PVC
OADP-1016 - DataMover: Restore randomly fails with "secrets vsr-lttsv-secret already exists" error
OADP-1020 - DataMover: restore partiallyFailed with "Plugin Panicked" error
OADP-1027 - DataMover: VSB fails with error "cannot obtain source volumesnapshot"
OADP-608 - Data mover restic secret does not support GCP
OADP-609 - Data mover VSR validation for default volumesnapshotclass and storageclass
OADP-611 - Data mover VSR resources are sometimes created multiple times with multiple PVCs
OADP-612 - Data mover Backup & Restore needs to fail if a validation check fails
OADP-642 - OADP CRD descriptions should use the same capitalization as yaml fields
OADP-645 - Data mover performance on restore blocks restore process
OADP-662 - VSB/VSR needs to fail if backup/restore partially fails or fails
OADP-724 - Setting an excludedNamespace and includedNamespace in the same backup crashes velero
OADP-725 - DC Restic Post Restore Script handle restore name longer than 63 characters
OADP-731 - Backup partiallyFails with data mover if a stale snapshot is encountered
OADP-741 - Data Mover VSB/VSR CRs do not include status on error
OADP-774 - OADP must-gather is getting stuck
OADP-794 - Second restore of CSI volume fails due to dataSource doesn't match dataSourceRef
OADP-825 - CSI Volumesnapshot Deletion fails with nil pointer execption bug
OADP-849 - DataMover: restore PartiallyFails randomly with "ReplicationDestination.volsync.backube xxxx not found" error
OADP-927 - DataMover backup fails with nil pointer issue
6.
Bug Fix(es):
* Cloning a Block DV to VM with Filesystem with not big enough size comes
to endless loop - using pvc api (BZ#2033191)
* Restart of VM Pod causes SSH keys to be regenerated within VM
(BZ#2087177)
* Import gzipped raw file causes image to be downloaded and uncompressed to
TMPDIR (BZ#2089391)
* [4.11] VM Snapshot Restore hangs indefinitely when backed by a
snapshotclass (BZ#2098225)
* Fedora version in DataImportCrons is not 'latest' (BZ#2102694)
* [4.11] Cloned VM's snapshot restore fails if the source VM disk is
deleted (BZ#2109407)
* CNV introduces a compliance check fail in "ocp4-moderate" profile -
routes-protected-by-tls (BZ#2110562)
* Nightly build: v4.11.0-578: index format was changed in 4.11 to
file-based instead of sqlite-based (BZ#2112643)
* Unable to start windows VMs on PSI setups (BZ#2115371)
* [4.11.1]virt-launcher cannot be started on OCP 4.12 due to PodSecurity
restricted:v1.24 (BZ#2128997)
* Mark Windows 11 as TechPreview (BZ#2129013)
* 4.11.1 rpms (BZ#2139453)
This advisory contains the following OpenShift Virtualization 4.11.1
images.
RHEL-8-CNV-4.11
virt-cdi-operator-container-v4.11.1-5
virt-cdi-uploadserver-container-v4.11.1-5
virt-cdi-apiserver-container-v4.11.1-5
virt-cdi-importer-container-v4.11.1-5
virt-cdi-controller-container-v4.11.1-5
virt-cdi-cloner-container-v4.11.1-5
virt-cdi-uploadproxy-container-v4.11.1-5
checkup-framework-container-v4.11.1-3
kubevirt-tekton-tasks-wait-for-vmi-status-container-v4.11.1-7
kubevirt-tekton-tasks-create-datavolume-container-v4.11.1-7
kubevirt-template-validator-container-v4.11.1-4
virt-handler-container-v4.11.1-5
hostpath-provisioner-operator-container-v4.11.1-4
virt-api-container-v4.11.1-5
vm-network-latency-checkup-container-v4.11.1-3
cluster-network-addons-operator-container-v4.11.1-5
virtio-win-container-v4.11.1-4
virt-launcher-container-v4.11.1-5
ovs-cni-marker-container-v4.11.1-5
hyperconverged-cluster-webhook-container-v4.11.1-7
virt-controller-container-v4.11.1-5
virt-artifacts-server-container-v4.11.1-5
kubevirt-tekton-tasks-modify-vm-template-container-v4.11.1-7
kubevirt-tekton-tasks-disk-virt-customize-container-v4.11.1-7
libguestfs-tools-container-v4.11.1-5
hostpath-provisioner-container-v4.11.1-4
kubevirt-tekton-tasks-disk-virt-sysprep-container-v4.11.1-7
kubevirt-tekton-tasks-copy-template-container-v4.11.1-7
cnv-containernetworking-plugins-container-v4.11.1-5
bridge-marker-container-v4.11.1-5
virt-operator-container-v4.11.1-5
hostpath-csi-driver-container-v4.11.1-4
kubevirt-tekton-tasks-create-vm-from-template-container-v4.11.1-7
kubemacpool-container-v4.11.1-5
hyperconverged-cluster-operator-container-v4.11.1-7
kubevirt-ssp-operator-container-v4.11.1-4
ovs-cni-plugin-container-v4.11.1-5
kubevirt-tekton-tasks-cleanup-vm-container-v4.11.1-7
kubevirt-tekton-tasks-operator-container-v4.11.1-2
cnv-must-gather-container-v4.11.1-8
kubevirt-console-plugin-container-v4.11.1-9
hco-bundle-registry-container-v4.11.1-49
3. Bugs fixed (https://bugzilla.redhat.com/):
2033191 - Cloning a Block DV to VM with Filesystem with not big enough size comes to endless loop - using pvc api
2064857 - CVE-2022-24921 golang: regexp: stack exhaustion via a deeply nested expression
2070772 - When specifying pciAddress for several SR-IOV NIC they are not correctly propagated to libvirt XML
2077688 - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode
2077689 - CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar
2087177 - Restart of VM Pod causes SSH keys to be regenerated within VM
2089391 - Import gzipped raw file causes image to be downloaded and uncompressed to TMPDIR
2091856 - ?Edit BootSource? action should have more explicit information when disabled
2092793 - CVE-2022-30629 golang: crypto/tls: session tickets lack random ticket_age_add
2098225 - [4.11] VM Snapshot Restore hangs indefinitely when backed by a snapshotclass
2100495 - CVE-2021-38561 golang: out-of-bounds read in golang.org/x/text/language leads to DoS
2102694 - Fedora version in DataImportCrons is not 'latest'
2109407 - [4.11] Cloned VM's snapshot restore fails if the source VM disk is deleted
2110562 - CNV introduces a compliance check fail in "ocp4-moderate" profile - routes-protected-by-tls
2112643 - Nightly build: v4.11.0-578: index format was changed in 4.11 to file-based instead of sqlite-based
2115371 - Unable to start windows VMs on PSI setups
2119613 - GiB changes to B in Template's Edit boot source reference modal
2128554 - The storageclass of VM disk is different from quick created and customize created after changed the default storageclass
2128872 - [4.11]Can't restore cloned VM
2128997 - [4.11.1]virt-launcher cannot be started on OCP 4.12 due to PodSecurity restricted:v1.24
2129013 - Mark Windows 11 as TechPreview
2129235 - [RFE] Add "Copy SSH command" to VM action list
2134668 - Cannot edit ssh even vm is stopped
2139453 - 4.11.1 rpms
5. This software, such as Apache HTTP Server, is
common to multiple JBoss middleware products, and is packaged under Red Hat
JBoss Core Services to allow for faster distribution of updates, and for a
more consistent update experience.
This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.51
Service Pack 1 serves as a replacement for Red Hat JBoss Core Services
Apache HTTP Server 2.4.51, and includes bug fixes and enhancements, which
are documented in the Release Notes document linked to in the References. Bugs fixed (https://bugzilla.redhat.com/):
2064319 - CVE-2022-23943 httpd: mod_sed: Read/write beyond bounds
2064320 - CVE-2022-22721 httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody
2081494 - CVE-2022-1292 openssl: c_rehash script allows command injection
2094997 - CVE-2022-26377 httpd: mod_proxy_ajp: Possible request smuggling
2095000 - CVE-2022-28330 httpd: mod_isapi: out-of-bounds read
2095002 - CVE-2022-28614 httpd: Out-of-bounds read via ap_rwrite()
2095006 - CVE-2022-28615 httpd: Out-of-bounds read in ap_strcmp_match()
2095015 - CVE-2022-30522 httpd: mod_sed: DoS vulnerability
2095020 - CVE-2022-31813 httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism
2097310 - CVE-2022-2068 openssl: the c_rehash script allows command injection
2099300 - CVE-2022-32206 curl: HTTP compression denial of service
2099305 - CVE-2022-32207 curl: Unpreserved file permissions
2099306 - CVE-2022-32208 curl: FTP-KRB bad message verification
2116639 - CVE-2022-37434 zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra field
2120718 - CVE-2022-35252 curl: control code in cookie denial of service
2130769 - CVE-2022-40674 expat: a use-after-free in the doContent function in xmlparse.c
2135411 - CVE-2022-32221 curl: POST following PUT confusion
2135413 - CVE-2022-42915 curl: HTTP proxy double-free
2135416 - CVE-2022-42916 curl: HSTS bypass via IDN
2136266 - CVE-2022-40303 libxml2: integer overflows with XML_PARSE_HUGE
2136288 - CVE-2022-40304 libxml2: dict corruption caused by entity reference cycles
5
| VAR-202208-0306 | CVE-2022-34993 | TOTOLINK of a3600r Vulnerability related to use of hardcoded credentials in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample. TOTOLINK of a3600r A vulnerability exists in the firmware regarding the use of hardcoded credentials.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK A3600R is a 6-antenna 1200M wireless router from China TOTOLINK.
The TOTOLINK A3600R Firmware V4.1.2cu.5182_B20201102 version has a security vulnerability, which is caused by including the root password in /etc/shadow.sample. An attacker could exploit this vulnerability to obtain sensitive information