-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Security Profiles Operator bug fix update Advisory ID: RHSA-2023:2029-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:2029 Issue date: 2023-05-10 CVE Names: CVE-2023-0475 CVE-2023-25173 ===================================================================== 1. Summary: An updated Security Profiles Operator image that fixes various bugs is now available for the Red Hat OpenShift Enterprise 4 catalog. 2. Description: The OpenShift Security Profiles Operator v0.7.0 is now available. See the documentation for bug fix information: https://docs.openshift.com/container-platform/4.12/security/security_profiles_operator/spo-release-notes.html 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html 4. Bugs fixed (https://bugzilla.redhat.com/): 2170844 - CVE-2023-0475 go-getter: go-getter vulnerable to denial of service via malicious compressed archive 2174485 - CVE-2023-25173 containerd: Supplementary groups are not set up properly 5. JIRA issues fixed (https://issues.jboss.org/): OCPBUGS-10045 - The spod pods crash with rhel9 os due to "error parsing semanage configuration file" OCPBUGS-12879 - selinux: Allow using other container-selinux policy templates than container 6. References: https://access.redhat.com/security/cve/CVE-2023-0475 https://access.redhat.com/security/cve/CVE-2023-25173 https://access.redhat.com/security/updates/classification/#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZFvaFNzjgjWX9erEAQhspw//Vw4vFa+ense7upZcydeEMMR2DRxw9Ht7 m4NkteViLRKBXUSp44JgH5FGHzpLrZZJ9XDsGMvum9utI+v7WwBaGiIjmDGual7f ZfHtpBCb2/h3r6CwUq+NQuK4optyLlUM9wo4z2FcZQLdrey0r7lDvywNUrBUzzd3 qPgRLdd1nOHepvG2uyqyAPb5gknjPDkWnp3CGbR6SHj97zmknAAfQbgIHbwFfakl QcjfKQYmo1fS8NnqdDt9VqYz96C0N9yGnSUOqZ2Gq8JKuR+u7VvYC0tuxTHvIacN I4qvwpEIKees3gmfYyw7XnNqJqztFGh9qGa4VHq20jIfsx4tywjNfxff5GfPDa9k pQshq/sRQBu9/yF5twwvjTtmOpDltJSVANBOqOIF4FG+L9xo1m4kDJ2DQ6OiKILa RExhThcYrBEJf/xUsP/y5fFUQGwwUpbdvi7ZKRarZExqDO+UpmrxKZ/2QhzfunvF EcEDA6zDXt+IhsIsppdmxBGVFe5LWeA0mLxXEpM2sv6gwvNxDF/8kgBEVLUOnXP2 PGYRLg1SoPD9+7xowmB5ElFU+j5eZgYlnSmTZ8Pgao4LGSb8qJzrF8btje2pfOAM FBfQq0uUFizjkEdC1j5evcHiINrOUL4ub6JWCuX3O93uIZpe5J8RGhV8XhcbpXJW lKkmxPiEFkM= =Fvhj -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce