Synopsis
Moderate: containernetworking-plugins security update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.
Security Fix(es):
- golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)
- golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. (CVE-2023-45287)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.4 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
Fixes
-
BZ - 2253193
- CVE-2023-45287 golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.
-
BZ - 2253330
- CVE-2023-39326 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests
-
RHEL-3140
- cni-dhcp.service ExecStart points to nonexistent binary [rhel-9.4.0]
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
x86_64 |
containernetworking-plugins-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c2708b663acec0ac284ca7b5d3afadcd2da45f27e62b521d1bf736f23274b34c |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: 273775d9ff495e4354c40ce97bbeaf4f87a3136f3d96d364866c6534536055d3 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c96572bc84123a2a7eb9bf6994224b522602a0f6eff18a4c8bc6dadcdf160be7 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
x86_64 |
containernetworking-plugins-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c2708b663acec0ac284ca7b5d3afadcd2da45f27e62b521d1bf736f23274b34c |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: 273775d9ff495e4354c40ce97bbeaf4f87a3136f3d96d364866c6534536055d3 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c96572bc84123a2a7eb9bf6994224b522602a0f6eff18a4c8bc6dadcdf160be7 |
Red Hat Enterprise Linux Server - AUS 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
x86_64 |
containernetworking-plugins-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c2708b663acec0ac284ca7b5d3afadcd2da45f27e62b521d1bf736f23274b34c |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: 273775d9ff495e4354c40ce97bbeaf4f87a3136f3d96d364866c6534536055d3 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c96572bc84123a2a7eb9bf6994224b522602a0f6eff18a4c8bc6dadcdf160be7 |
Red Hat Enterprise Linux for IBM z Systems 9
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
s390x |
containernetworking-plugins-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: ddda7b1b05b5494f7b196bd9fb3144de85fe387d26c92362843c29944ddfca1b |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: 1a854a5c9ca49d180466008257d45da0882224dd1d7de7850ce98b92ba92b9c5 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: 61a3bb84182ab017dafe5cfbbb7ea3110b7ca766a3b7d090f5defad642749271 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
s390x |
containernetworking-plugins-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: ddda7b1b05b5494f7b196bd9fb3144de85fe387d26c92362843c29944ddfca1b |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: 1a854a5c9ca49d180466008257d45da0882224dd1d7de7850ce98b92ba92b9c5 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: 61a3bb84182ab017dafe5cfbbb7ea3110b7ca766a3b7d090f5defad642749271 |
Red Hat Enterprise Linux for Power, little endian 9
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
ppc64le |
containernetworking-plugins-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: 2ac2a01000308d123199db4e56e924cef22eb58cffb357a0abd618b30c3bc7f1 |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: 8abfee4983567cf96b617a00d24a6f00db7046b6cc576677c5a1e8bf3096a848 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: e6b35ac57d583db276befc2c46e6ab2928449677b5c5009b1050e3084f9bfa60 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
ppc64le |
containernetworking-plugins-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: 2ac2a01000308d123199db4e56e924cef22eb58cffb357a0abd618b30c3bc7f1 |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: 8abfee4983567cf96b617a00d24a6f00db7046b6cc576677c5a1e8bf3096a848 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: e6b35ac57d583db276befc2c46e6ab2928449677b5c5009b1050e3084f9bfa60 |
Red Hat Enterprise Linux for ARM 64 9
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
aarch64 |
containernetworking-plugins-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: e88f0996e49f39c221197aff9e0961d43c9ec4c841aae71e97eac0d991bdb304 |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: ed32109347ab9c2a76750a3d32e92745a0ad8dd936deff7cdf450f5574a25984 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: e9a37337fcdabba48d227a6cd0aba635f4ede197123255d772a1c85280db40d7 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
aarch64 |
containernetworking-plugins-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: e88f0996e49f39c221197aff9e0961d43c9ec4c841aae71e97eac0d991bdb304 |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: ed32109347ab9c2a76750a3d32e92745a0ad8dd936deff7cdf450f5574a25984 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: e9a37337fcdabba48d227a6cd0aba635f4ede197123255d772a1c85280db40d7 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
ppc64le |
containernetworking-plugins-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: 2ac2a01000308d123199db4e56e924cef22eb58cffb357a0abd618b30c3bc7f1 |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: 8abfee4983567cf96b617a00d24a6f00db7046b6cc576677c5a1e8bf3096a848 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.ppc64le.rpm
|
SHA-256: e6b35ac57d583db276befc2c46e6ab2928449677b5c5009b1050e3084f9bfa60 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
x86_64 |
containernetworking-plugins-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c2708b663acec0ac284ca7b5d3afadcd2da45f27e62b521d1bf736f23274b34c |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: 273775d9ff495e4354c40ce97bbeaf4f87a3136f3d96d364866c6534536055d3 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.x86_64.rpm
|
SHA-256: c96572bc84123a2a7eb9bf6994224b522602a0f6eff18a4c8bc6dadcdf160be7 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
aarch64 |
containernetworking-plugins-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: e88f0996e49f39c221197aff9e0961d43c9ec4c841aae71e97eac0d991bdb304 |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: ed32109347ab9c2a76750a3d32e92745a0ad8dd936deff7cdf450f5574a25984 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.aarch64.rpm
|
SHA-256: e9a37337fcdabba48d227a6cd0aba635f4ede197123255d772a1c85280db40d7 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4
SRPM |
containernetworking-plugins-1.4.0-2.el9_4.src.rpm
|
SHA-256: 82d2521efc8ce99ad021a7041834ca8fb8c448a524b3b0503461da7272c2e443 |
s390x |
containernetworking-plugins-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: ddda7b1b05b5494f7b196bd9fb3144de85fe387d26c92362843c29944ddfca1b |
containernetworking-plugins-debuginfo-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: 1a854a5c9ca49d180466008257d45da0882224dd1d7de7850ce98b92ba92b9c5 |
containernetworking-plugins-debugsource-1.4.0-2.el9_4.s390x.rpm
|
SHA-256: 61a3bb84182ab017dafe5cfbbb7ea3110b7ca766a3b7d090f5defad642749271 |