The vendor explicitly identifies these products as affected by this CVE.
- cpma.src as a component of Migration Toolkit for Containers
- rhmtc/openshift-migration-controller-rhel8 as a component of Migration Toolkit for Containers
- rhmtc/openshift-migration-velero-rhel8 as a component of Migration Toolkit for Containers
- odo.src as a component of OpenShift Developer Tools and Services
- servicemesh as a component of OpenShift Service Mesh 2.0
- servicemesh-istioctl as a component of OpenShift Service Mesh 2.0
- servicemesh-mixc as a component of OpenShift Service Mesh 2.0
- servicemesh-mixs as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-agent as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-discovery as a component of OpenShift Service Mesh 2.0
- servicemesh.src as a component of OpenShift Service Mesh 2.0
- rhacm2/multicluster-operators-subscription-release-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A broken cryptographic algorithm flaw was found in golang.org/x/crypto/ssh. This issue causes a client to fail authentication with RSA keys to servers that reject signature algorithms based on SHA-2, enabling an attacker to crash the server, resulting in a loss of availability.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
