Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-44414

[4.15] OpenShift 4.14.40 downgrades libreswan to an older version with CVE exposure

XMLWordPrintable

    • None
    • False
    • Hide

      None

      Show
      None

      Fixing OCPBUGS-42952 via https://github.com/openshift/ovn-kubernetes/pull/2323 in OpenShift 4.14.40 pinned libreswan back from latest RHEL 9.2.z version to libreswan-4.5-1.el9 which image scanning has informed us introduced CVE exposure regressions listed below.

      The following known vulnerabilities exist for packages in this container:

      We need to unpin this package so that we don't regress on CVE fixes while addressing functional issues. In the set of customers that are known to be affected by the function issue we can work with them to help them decide the appropriate path forward.

              bbennett@redhat.com Ben Bennett
              rhn-support-sdodson Scott Dodson
              Anurag Saxena Anurag Saxena
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: