概述
Important: opentelemetry-collector security update
类型/严重性
Security Advisory: Important
Red Hat Lightspeed patch analysis
标题
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
描述
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
- go-jose: Go JOSE's Parsing Vulnerable to Denial of Service (CVE-2025-27144)
- golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868)
- github.com/expr-lang/expr: Memory Exhaustion in Expr Parser with Unrestricted Input (CVE-2025-29786)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
受影响的产品
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.6 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x
修复
-
BZ - 2341751
- CVE-2024-45336 golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect
-
BZ - 2347423
- CVE-2025-27144 go-jose: Go JOSE's Parsing Vulnerable to Denial of Service
-
BZ - 2348366
- CVE-2025-22868 golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws
-
BZ - 2352914
- CVE-2025-29786 github.com/expr-lang/expr: Memory Exhaustion in Expr Parser with Unrestricted Input
注::
可能有这些软件包的更新版本。
点击软件包名称查看详情。
Red Hat Enterprise Linux for x86_64 9
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_5.x86_64.rpm
|
SHA-256: ff7d61f76e9f3fc9808e81f29af2cfe844ec651f4e5fd6c16127fbe9c42ded3d |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_5.x86_64.rpm
|
SHA-256: ff7d61f76e9f3fc9808e81f29af2cfe844ec651f4e5fd6c16127fbe9c42ded3d |
Red Hat Enterprise Linux Server - AUS 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_5.x86_64.rpm
|
SHA-256: ff7d61f76e9f3fc9808e81f29af2cfe844ec651f4e5fd6c16127fbe9c42ded3d |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| s390x |
|
opentelemetry-collector-0.107.0-8.el9_5.s390x.rpm
|
SHA-256: 93d850d8e5c6dcf513edd025172fc3633f8383c8a29a2640aea2378eb2ceb5e7 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| s390x |
|
opentelemetry-collector-0.107.0-8.el9_5.s390x.rpm
|
SHA-256: 93d850d8e5c6dcf513edd025172fc3633f8383c8a29a2640aea2378eb2ceb5e7 |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| ppc64le |
|
opentelemetry-collector-0.107.0-8.el9_5.ppc64le.rpm
|
SHA-256: 73e1c5d86e3b755495590673d383b0b95e2f1b6fa5656bc778fac38cdd9ef209 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| ppc64le |
|
opentelemetry-collector-0.107.0-8.el9_5.ppc64le.rpm
|
SHA-256: 73e1c5d86e3b755495590673d383b0b95e2f1b6fa5656bc778fac38cdd9ef209 |
Red Hat Enterprise Linux for ARM 64 9
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| aarch64 |
|
opentelemetry-collector-0.107.0-8.el9_5.aarch64.rpm
|
SHA-256: 5f4e2f819597ad73a6da92995f0943e8deb06cb9d659f5ab3997252c2e1f7146 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| aarch64 |
|
opentelemetry-collector-0.107.0-8.el9_5.aarch64.rpm
|
SHA-256: 5f4e2f819597ad73a6da92995f0943e8deb06cb9d659f5ab3997252c2e1f7146 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| ppc64le |
|
opentelemetry-collector-0.107.0-8.el9_5.ppc64le.rpm
|
SHA-256: 73e1c5d86e3b755495590673d383b0b95e2f1b6fa5656bc778fac38cdd9ef209 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_5.x86_64.rpm
|
SHA-256: ff7d61f76e9f3fc9808e81f29af2cfe844ec651f4e5fd6c16127fbe9c42ded3d |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| aarch64 |
|
opentelemetry-collector-0.107.0-8.el9_5.aarch64.rpm
|
SHA-256: 5f4e2f819597ad73a6da92995f0943e8deb06cb9d659f5ab3997252c2e1f7146 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_5.src.rpm
|
SHA-256: 0fc03d5df926faafd4017e38e699a4e8c6a2a312965eba556d76a5eaeab67526 |
| s390x |
|
opentelemetry-collector-0.107.0-8.el9_5.s390x.rpm
|
SHA-256: 93d850d8e5c6dcf513edd025172fc3633f8383c8a29a2640aea2378eb2ceb5e7 |