Security update for kubernetes1.23
This update for kubernetes1.23 fixes the following issues: - CVE-2021-25743: escape, meta and control sequences in raw data output to terminal not neutralized. (bsc#1194400) - CVE-2023-2727: bypass of policies imposed by the ImagePolicyWebhook admission plugin. (bsc#1211630) - CVE-2023-2728: bypass of the mountable secrets policy enforced by the ServiceAccount admission plugin. (bsc#1211631) - CVE-2023-39325: go1.20: excessive resource consumption when dealing with rapid stream resets. (bsc#1229869) - CVE-2023-44487: google.golang.org/grpc, kube-apiserver: HTTP/2 rapid reset vulnerability. (bsc#1229869) - CVE-2023-45288: golang.org/x/net: excessive CPU consumption when processing unlimited sets of headers. (bsc#1229869) - CVE-2024-0793: kube-controller-manager pod crash when processing malformed HPA v1 manifests. (bsc#1219964) - CVE-2024-3177: bypass of the mountable secrets policy enforced by the ServiceAccount admission plugin. (bsc#1222539) - CVE-2024-24786: github.com/golang/protobuf: infinite loop when unmarshaling invalid JSON. (bsc#1229867) Bug fixes: - Use -trimpath in non-DBG mode for reproducible builds. (bsc#1062303) - Fix multiple issues for successful `kubeadm init` run. (bsc#1214406) - Update go to version 1.22.5 in build requirements. (bsc#1229858)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for kubernetes1.23 fixes the following issues: - CVE-2021-25743: escape, meta and control sequences in raw data output to terminal not neutralized. (bsc#1194400) - CVE-2023-2727: bypass of policies imposed by the ImagePolicyWebhook admission plugin. (bsc#1211630) - CVE-2023-2728: bypass of the mountable secrets policy enforced by the ServiceAccount admission plugin. (bsc#1211631) - CVE-2023-39325: go1.20: excessive resource consumption when dealing with rapid stream resets. (bsc#1229869) - CVE-2023-44487: google.golang.org/grpc, kube-apiserver: HTTP/2 rapid reset vulnerability. (bsc#1229869) - CVE-2023-45288: golang.org/x/net: excessive CPU consumption when processing unlimited sets of headers. (bsc#1229869) - CVE-2024-0793: kube-controller-manager pod crash when processing malformed HPA v1 manifests. (bsc#1219964) - CVE-2024-3177: bypass of the mountable secrets policy enforced by the ServiceAccount admission plugin. (bsc#1222539) - CVE-2024-24786: github.com/golang/protobuf: infinite loop when unmarshaling invalid JSON. (bsc#1229867) Bug fixes: - Use -trimpath in non-DBG mode for reproducible builds. (bsc#1062303) - Fix multiple issues for successful `kubeadm init` run. (bsc#1214406) - Update go to version 1.22.5 in build requirements. (bsc#1229858)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1062303
- https://bugzilla.suse.com/1194400
- https://bugzilla.suse.com/1211630
- https://bugzilla.suse.com/1211631
- https://bugzilla.suse.com/1214406
- https://bugzilla.suse.com/1216109
- https://bugzilla.suse.com/1216123
- https://bugzilla.suse.com/1219964
- https://bugzilla.suse.com/1221400
- https://bugzilla.suse.com/1222539
- https://bugzilla.suse.com/1226136
- https://bugzilla.suse.com/1229858
- https://bugzilla.suse.com/1229867
- https://bugzilla.suse.com/1229869
- https://bugzilla.suse.com/1230323
- https://www.suse.com/security/cve/CVE-2021-25743
- https://www.suse.com/security/cve/CVE-2023-2727
- https://www.suse.com/security/cve/CVE-2023-2728
- https://www.suse.com/security/cve/CVE-2023-39325
- https://www.suse.com/security/cve/CVE-2023-44487
- https://www.suse.com/security/cve/CVE-2023-45288
- https://www.suse.com/security/cve/CVE-2024-0793
- https://www.suse.com/security/cve/CVE-2024-24786
- https://www.suse.com/security/cve/CVE-2024-3177
- https://www.suse.com/support/update/announcement/2024/suse-su-20243341-1/