toolbox-0.0.99.3-10.el9

エラータID: AXSA:2023-6548:02

Release date: 
Thursday, October 26, 2023 - 11:36
Subject: 
toolbox-0.0.99.3-10.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The rhel9/toolbox container image can be used with Toolbox to obtain RHEL based containerized command line environments to aid with development and software testing. Toolbox is built on top of Podman and other standard container technologies from OCI.

This updates the rhel9/toolbox image in the Cybertrust Japan Co., Ltd. container registry.

To pull this container image, run one of the following commands:

podman pull registry.redhat.io/rhel9/toolbox (authenticated)
podman pull registry.access.redhat.com/ubi9/toolbox (unauthenticated)

CVE-2023-39325
A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. toolbox-0.0.99.3-10.el9.src.rpm
    MD5: a2b018418327a2f9bfe8832616d2fab3
    SHA-256: ee4d34dd1f9ac2b3cbb0a223eacbfdf4cb2cf5f558da4b8098984023da8db4f1
    Size: 2.20 MB

Asianux Server 9 for x86_64
  1. toolbox-0.0.99.3-10.el9.x86_64.rpm
    MD5: 3480d3f2358831809a38886854fde522
    SHA-256: 5ad7cc09f26fcf87068a9fe7af828334d7b03c793038d527112b72883c0e469b
    Size: 2.36 MB
  2. toolbox-tests-0.0.99.3-10.el9.x86_64.rpm
    MD5: 75f525e088c1e9305d68505100868b64
    SHA-256: 87a5202913e7d2ccc4f2b910dee60f4e90834c53f89eda51b77dc21291f3ace0
    Size: 32.71 kB