[Apollo] Advisories Red Hat Advisories Statistics light light Login

RHSA-2024:4379

Security
Issued at: 2024-07-08
launch
Open original
Override

Synopsis

Important: gvisor-tap-vsock security update



Description

A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor and is used to provide networking for podman-machine virtual machines. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding.

Security Fix(es):

* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Red Hat Enterprise Linux for ARM 64 - 9 Red Hat Enterprise Linux for IBM z Systems - 9 Red Hat Enterprise Linux for Power, little endian - 9 Red Hat Enterprise Linux for x86_64 - 9

Fixes

2262921

CVEs

CVE-2024-1394

Affected packages

gvisor-tap-vsock-6:0.7.3-4.el9_4.aarch64 gvisor-tap-vsock-6:0.7.3-4.el9_4.ppc64le gvisor-tap-vsock-6:0.7.3-4.el9_4.s390x gvisor-tap-vsock-6:0.7.3-4.el9_4.src gvisor-tap-vsock-6:0.7.3-4.el9_4.x86_64 gvisor-tap-vsock-debuginfo-6:0.7.3-4.el9_4.aarch64 gvisor-tap-vsock-debuginfo-6:0.7.3-4.el9_4.ppc64le gvisor-tap-vsock-debuginfo-6:0.7.3-4.el9_4.s390x gvisor-tap-vsock-debuginfo-6:0.7.3-4.el9_4.x86_64 gvisor-tap-vsock-debugsource-6:0.7.3-4.el9_4.aarch64 gvisor-tap-vsock-debugsource-6:0.7.3-4.el9_4.ppc64le gvisor-tap-vsock-debugsource-6:0.7.3-4.el9_4.s390x gvisor-tap-vsock-debugsource-6:0.7.3-4.el9_4.x86_64