[ALSA-2024:2272] Moderate: containernetworking-plugins security update
Type:
security
Severity:
moderate
Release date:
2024-05-07
Description:
The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): * golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326) * golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. (CVE-2023-45287) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 containernetworking-plugins-1.4.0-2.el9_4.aarch64.rpm 76114043bde9882615756240d2f6f46214b7bf1c0f177b9d54a5cc491c2a70d9
ppc64le containernetworking-plugins-1.4.0-2.el9_4.ppc64le.rpm a911a1ed478859b8781ed26e0179875950d7f949230eb5e37d78c8b948aae617
s390x containernetworking-plugins-1.4.0-2.el9_4.s390x.rpm fc936d003814d66424c98bb3e7f7cee45d4fa779a81af7b8499481cafb3d8649
x86_64 containernetworking-plugins-1.4.0-2.el9_4.x86_64.rpm 8d632432438d9107fe46003cfbce390842934f6769bdc835c0bf0cfed93cf8d8
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.