Security update for kubernetes1.25
This update for kubernetes1.25 fixes the following issues: - CVE-2023-45288: golang.org/x/net: excessive CPU consumption when processing unlimited sets of headers. (bsc#1229869) - CVE-2023-44487: google.golang.org/grpc, kube-apiserver: HTTP/2 rapid reset vulnerability. (bsc#1229869) - CVE-2024-24786: github.com/golang/protobuf: infinite loop when unmarshaling invalid JSON. (bsc#1229867) Bug fixes: - Update go to version 1.22.5 in build requirements. (bsc#1229858)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for kubernetes1.25 fixes the following issues: - CVE-2023-45288: golang.org/x/net: excessive CPU consumption when processing unlimited sets of headers. (bsc#1229869) - CVE-2023-44487: google.golang.org/grpc, kube-apiserver: HTTP/2 rapid reset vulnerability. (bsc#1229869) - CVE-2024-24786: github.com/golang/protobuf: infinite loop when unmarshaling invalid JSON. (bsc#1229867) Bug fixes: - Update go to version 1.22.5 in build requirements. (bsc#1229858)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1216109
- https://bugzilla.suse.com/1216123
- https://bugzilla.suse.com/1221400
- https://bugzilla.suse.com/1226136
- https://bugzilla.suse.com/1229858
- https://bugzilla.suse.com/1229867
- https://bugzilla.suse.com/1229869
- https://bugzilla.suse.com/1230323
- https://www.suse.com/security/cve/CVE-2023-39325
- https://www.suse.com/security/cve/CVE-2023-44487
- https://www.suse.com/security/cve/CVE-2023-45288
- https://www.suse.com/security/cve/CVE-2024-24786
- https://www.suse.com/support/update/announcement/2024/suse-su-20243344-1/