containernetworking-plugins-1.2.0-1.el9

エラータID: AXSA:2023-5584:01

Release date: 
Monday, May 29, 2023 - 05:36
Subject: 
containernetworking-plugins-1.2.0-1.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.

Security Fix(es):

* golang: net/[http:](http:) An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)
* golang: crypto/tls: session tickets lack random ticket_age_add (CVE-2022-30629)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9.2 Release Notes linked from the References section.

CVE-2022-30629
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
CVE-2022-41717
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. containernetworking-plugins-1.2.0-1.el9.src.rpm
    MD5: cbddbbc9f137d685ea24425854f0b828
    SHA-256: 0075833fe5f67d1a1b1d2541f20166c3cadac855d8e05bb1233381244e30c97e
    Size: 3.07 MB

Asianux Server 9 for x86_64
  1. containernetworking-plugins-1.2.0-1.el9.x86_64.rpm
    MD5: 57b39c71c10614c630f5a3d274828831
    SHA-256: e99d79a1347d3704efe8cbca372f81dfbf4c8d705054ee048bea72ab160ccd35
    Size: 8.57 MB