- Issued:
- 2023-05-10
- Updated:
- 2023-05-10
RHSA-2023:2029 - Security Advisory
Synopsis
Moderate: OpenShift Security Profiles Operator bug fix update
Type/Severity
Security Advisory: Moderate
Topic
An updated Security Profiles Operator image that fixes various bugs is now available for the Red Hat OpenShift Enterprise 4 catalog.
Description
The OpenShift Security Profiles Operator v0.7.0 is now available. See the documentation for bug fix information:
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to:
https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html
Affected Products
- Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
- Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.8 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.7 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.6 for RHEL 8 x86_64
Fixes
- BZ - 2170844 - CVE-2023-0475 go-getter: go-getter vulnerable to denial of service via malicious compressed archive
- BZ - 2174485 - CVE-2023-25173 containerd: Supplementary groups are not set up properly
- OCPBUGS-10045 - The spod pods crash with rhel9 os due to "error parsing semanage configuration file"
- OCPBUGS-12879 - selinux: Allow using other container-selinux policy templates than container
x86_64
compliance/openshift-security-profiles-operator-bundle@sha256:389d0d29b3a17ccd0906ef63e6839ae87467d2a8c104f705fb50eed0ed782556 |
compliance/openshift-security-profiles-rhel8-operator@sha256:fd4a8edef02bd72f270cd18b9b054591357234e406f18d6acefc0fec7153da0f |
compliance/openshift-selinuxd-rhel8@sha256:c1de264053dbe3b2753c05db9b5361ed2699c1b0b8a5d6ff43c5f9ecde1fa48b |
compliance/openshift-selinuxd-rhel9@sha256:7a160f493cc043096cdb149a4d71c523e3cf521407b9574b5eb4ba0f27d28465 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.