ALT-BU-2024-10153-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-4467
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.
- http://www.openwall.com/lists/oss-security/2024/07/23/2
- RHSA-2024:4276
- RHSA-2024:4276
- RHSA-2024:4277
- RHSA-2024:4277
- RHSA-2024:4278
- RHSA-2024:4278
- RHSA-2024:4372
- RHSA-2024:4372
- RHSA-2024:4373
- RHSA-2024:4373
- RHSA-2024:4374
- RHSA-2024:4374
- RHSA-2024:4420
- RHSA-2024:4420
- RHSA-2024:4724
- RHSA-2024:4724
- RHSA-2024:4727
- RHSA-2024:4727
- https://access.redhat.com/security/cve/CVE-2024-4467
- https://access.redhat.com/security/cve/CVE-2024-4467
- RHBZ#2278875
- RHBZ#2278875
- https://security.netapp.com/advisory/ntap-20240822-0005/
Package kubernetes1.27 updated to version 1.27.16-alt1 for branch sisyphus in task 353169.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-5321
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
- http://www.openwall.com/lists/oss-security/2024/07/17/3
- https://github.com/kubernetes/kubernetes/issues/126161
- https://github.com/kubernetes/kubernetes/issues/126161
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
Package kubernetes1.28 updated to version 1.28.12-alt1 for branch sisyphus in task 353169.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-5321
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
- http://www.openwall.com/lists/oss-security/2024/07/17/3
- https://github.com/kubernetes/kubernetes/issues/126161
- https://github.com/kubernetes/kubernetes/issues/126161
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
Package kubernetes1.29 updated to version 1.29.7-alt1 for branch sisyphus in task 353169.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-5321
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
- http://www.openwall.com/lists/oss-security/2024/07/17/3
- https://github.com/kubernetes/kubernetes/issues/126161
- https://github.com/kubernetes/kubernetes/issues/126161
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
Package kubernetes1.30 updated to version 1.30.3-alt1 for branch sisyphus in task 353169.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-5321
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
- http://www.openwall.com/lists/oss-security/2024/07/17/3
- https://github.com/kubernetes/kubernetes/issues/126161
- https://github.com/kubernetes/kubernetes/issues/126161
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0
- https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0