The vendor explicitly identifies these products as affected by this CVE.
- cryostat-tech-preview/cryostat-rhel8-operator as a component of Cryostat 2
- cli as a component of OpenShift Serverless
- rhacm2/config-policy-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- advanced-cluster-security/rhacs-main-rhel8 as a component of Red Hat Advanced Cluster Security 3
- advanced-cluster-security/rhacs-roxctl-rhel8 as a component of Red Hat Advanced Cluster Security 3
- advanced-cluster-security/rhacs-scanner-db-rhel8 as a component of Red Hat Advanced Cluster Security 3
- advanced-cluster-security/rhacs-scanner-rhel8 as a component of Red Hat Advanced Cluster Security 3
- advanced-cluster-security/rhacs-scanner-slim-rhel8 as a component of Red Hat Advanced Cluster Security 3
- rhc as a component of Red Hat Enterprise Linux 7
- rhc.src as a component of Red Hat Enterprise Linux 7
- skopeo.src as a component of Red Hat Enterprise Linux 7
- toolbox-tests (container-tools:3.0) as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
