Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2023:1825 - Bug Fix Advisory
Issued:
2023-04-18
Updated:
2023-04-18

RHBA-2023:1825 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

RHBA: Submariner 0.14.3 - Bug fixes and enhancements

Type/Severity

Bug Fix Advisory

Topic

Submariner 0.14.3 packages that contain security fixes, bug fixes, and various enhancements that are now available for Red Hat Advanced Cluster Management for Kubernetes version 2.7

Description

Submariner enables direct networking between pods and services on different Kubernetes clusters that are either on-premises or in the cloud.

For more information about Submariner, see the Submariner open source community website at: https://submariner.io/.

This advisory contains bug fixes and enhancements to the Submariner container images.

Security fixes in base image:

  • CVE-2023-0286: openssl: X.400 address type confusion in X.509 GeneralName

Security

  • CVE-2022-4304: openssl: timing attack in RSA Decryption implementation
  • CVE-2023-0215: openssl: use-after-free following BIO_new_NDEF
  • CVE-2022-4450: openssl: double free after calling PEM_read_bio_ex
  • CVE-2023-23916: curl: HTTP multi-header compression denial of service

Jira issues addressed:

  • ACM-3751: ClusterIP service resolved before ready
  • ACM-4280: Support image-override in subctl diagnose command
  • ACM-4286: Build Submariner 0.14.3

Solution

For details on how to install Submariner, refer to:

https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/add-ons/add-ons-overview#deploying-submariner-console

and

https://submariner.io/getting-started/

Affected Products

  • Red Hat Advanced Cluster Management for Kubernetes 2 for RHEL 8 x86_64

Fixes

  • BZ - 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName
  • BZ - 2164487 - CVE-2022-4304 openssl: timing attack in RSA Decryption implementation
  • BZ - 2164492 - CVE-2023-0215 openssl: use-after-free following BIO_new_NDEF
  • BZ - 2164494 - CVE-2022-4450 openssl: double free after calling PEM_read_bio_ex
  • BZ - 2167815 - CVE-2023-23916 curl: HTTP multi-header compression denial of service
  • ACM-3751 - [Submariner 0.14.3] ClusterIP service resolved before ready
  • ACM-4280 - [Submariner 0.14.3] Support image-override in subctl diagnose command
  • ACM-4286 - [ACM 2.7.3] Build Submariner 0.14.3

CVEs

  • CVE-2023-23916

References

(none)

aarch64

rhacm2/lighthouse-agent-rhel8@sha256:7649658e142156f2e0ee7bda0ed89d09714737ad11bd7d08ee76aec0c63c3822
rhacm2/lighthouse-coredns-rhel8@sha256:349e9bd55693c5769c743d902f2a4cd09ce6b45732b5ffd72f371438ac20e42c
rhacm2/nettest-rhel8@sha256:445a685c1b052b49f21a0324e34405d1142e9056f4df955c1e81d3338c8b97aa
rhacm2/subctl-rhel8@sha256:347bd0f64553e4b1cc15a3b85bdc591f7c267c5ae4f0d8c0c767979e46943e4d
rhacm2/submariner-gateway-rhel8@sha256:964ecfde27c3296db712ee01d5014dff6d49432050c049b667351979f6371662
rhacm2/submariner-globalnet-rhel8@sha256:ca101602b6ec92343785b54c2dcaafe2d4d3a6e9330c8946fa851df7e30441ee
rhacm2/submariner-networkplugin-syncer-rhel8@sha256:8dcdc43f936c86aea8da2cabe7c5498ce3264c6c43843b1a9977821c1abfac7f
rhacm2/submariner-operator-bundle@sha256:d8d869b47d5a7ca758d350c12438979fe0e7f18c45e02d14ceba36801491abfc
rhacm2/submariner-rhel8-operator@sha256:7ba90a2db727afc9ac05fff35bcf792cce1de4dc831358d61fae77c31a1751a3
rhacm2/submariner-route-agent-rhel8@sha256:09dc096eda37cadfd3a5c6302ba11da90877f78a7bf3768ac2e30cf9167acdd6

ppc64le

rhacm2/lighthouse-agent-rhel8@sha256:d2a493a9a021cf2678eb96d5e9b6e476171b8e61f1cf738defec2d063352a450
rhacm2/lighthouse-coredns-rhel8@sha256:6ec10ef19cb73a3d69ad051012e520196e8c6c28c1b677ac0a12e234863f71b5
rhacm2/nettest-rhel8@sha256:f7bf4ded95ff4da75a2d6d7a24091e01b60f998fe1ee5cf7a5c30644bda5670d
rhacm2/subctl-rhel8@sha256:02e45c21fa8879f6744e2ff8979a07c40ccc51c7e16a8d75f510066e1cab141b
rhacm2/submariner-gateway-rhel8@sha256:f6f686e9029c0c361e3cd20b3a566422118e376b4417b58eeb1b55884582d6c1
rhacm2/submariner-globalnet-rhel8@sha256:fafa31982e052191dc11643379a0f98f261e016dd13471ffbbb21d6cde9ccdea
rhacm2/submariner-networkplugin-syncer-rhel8@sha256:d5ec1996dae15998745804f871eae2f9070b2e578e156dfda2099289c9d8933f
rhacm2/submariner-operator-bundle@sha256:7702ffd5c258f3dff84152084378d07a60424816302acefbb7e6ecb8d377d0ec
rhacm2/submariner-rhel8-operator@sha256:47d3ae6666cb9d1fbc1b3ec39e9df45f5e978f0dd4fa7fb46bccbc628c349469
rhacm2/submariner-route-agent-rhel8@sha256:7285226ac21bafeb26f67567de6b0e94587f4ebe7267dab933a488c1373a9cec

s390x

rhacm2/lighthouse-agent-rhel8@sha256:ce0d3304a65b27c933e349df9d0395a3ba4acd3343c03beceedab39c2a5b4387
rhacm2/lighthouse-coredns-rhel8@sha256:a2464abda0222d7b6b96408526df3faea34da3c98a4abd4d96a7f4b5bd3b0fcc
rhacm2/nettest-rhel8@sha256:24a6ecaa02521cabe9a0579215d414116d5345ab956643389453b93ebe02591e
rhacm2/subctl-rhel8@sha256:745a0b024d9657b3f92bfb72379ead078832ace2f25b49952c2f0d539c3237ad
rhacm2/submariner-gateway-rhel8@sha256:97e097fdcea348b0d230c16bec46fa49714c18a0cb8ee16da1ab8f086617b2af
rhacm2/submariner-globalnet-rhel8@sha256:f6de5f2fe28afaf49536de9fd155f1e3b1699e9fbed36db8a4718a38f6f693a4
rhacm2/submariner-networkplugin-syncer-rhel8@sha256:6a44b3775bdbf371e3ce2ee87d9933cc65faf8e08911bfed9c39626f39de9bd0
rhacm2/submariner-operator-bundle@sha256:291d82fbb2c7972a92724a3a8e420485fa8bb2b42b8367c409165b200ccdb246
rhacm2/submariner-rhel8-operator@sha256:70ec7fe30308bd1dd7910691d2f30529efd9d1336b64343fa94da20c16802ab7
rhacm2/submariner-route-agent-rhel8@sha256:5e2d53cc114d20a8430780165474ffaec8ffbedcdf894cc4e47e6fdc64ac13c4

x86_64

rhacm2/lighthouse-agent-rhel8@sha256:0635b75f57269ed9aa1270dc419e827c31f6ce5369040a3eb83734c52f20f0b4
rhacm2/lighthouse-coredns-rhel8@sha256:a188b139bf24802a689c3a57caba2219ca50c7c8eed91a72c9956b8fe472c34f
rhacm2/nettest-rhel8@sha256:ba32647717cb0ef6656e523b5abcad2289f0e171b9a5af1dc0c9585a3468e7eb
rhacm2/subctl-rhel8@sha256:578e7a67e5c73a7596851af07f769c7235a2857f0872e5af836898c9b9cef1d2
rhacm2/submariner-gateway-rhel8@sha256:f232eb0e0a58efdd314d078e66dd35bccea309ffc15d1d73ef9048aa4de2de5d
rhacm2/submariner-globalnet-rhel8@sha256:8ba86206e8167c7792f1fbe5ee8aa0e192dc9478ed2498e1b6adcfecc10e5c57
rhacm2/submariner-networkplugin-syncer-rhel8@sha256:3506079e266884d2d3e8f987a9db896a49ef218d3fd0f8dfd0c3765f7d49463e
rhacm2/submariner-operator-bundle@sha256:d438c1938b6c5fdcee221b2806a94d2887babedd05663ca76017d77f8b5208cf
rhacm2/submariner-rhel8-operator@sha256:645a624e4f7b7c47a02ac2a5efc72ca65558afc7b4c7958509114d9dddf35e86
rhacm2/submariner-route-agent-rhel8@sha256:c557de0f65dd7ecd2e7b33f5f694e73d461dbeda25cfb3a2aaef8d4b9a1320da

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility