The vendor explicitly states that these products are not affected by this CVE.
- cert-manager-operator-container as a component of cert-manager Operator for Red Hat OpenShift
- costmanagement-metrics-operator-container as a component of Cost Management Metrics Operator
- cryostat-tech-preview/cryostat-rhel8-operator as a component of Cryostat 2
- custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8 as a component of Custom Metric Autoscaler operator for Red Hat Openshift
- openshift-logging/logging-loki-rhel9 as a component of Logging Subsystem for Red Hat OpenShift
- mta/mta-hub-rhel9 as a component of Migration Toolkit for Applications 6
- rhmtc/openshift-migration-velero-rhel8 as a component of Migration Toolkit for Containers
- migration-toolkit-virtualization/mtv-controller-rhel9 as a component of Migration Toolkit for Virtualization
- mirror-registry-container as a component of mirror registry for Red Hat OpenShift
- workload-availability/node-maintenance-rhel8-operator as a component of Node Maintenance Operator
- oadp/oadp-velero-rhel9 as a component of OpenShift API for Data Protection
- openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8 as a component of OpenShift Secondary Scheduler Operator
- Summary
- A flaw was found in golang. This flaw allows an attacker to craft a malformed TIFF image, which will consume a significant amount of memory when passed to DecodeConfig, leading to a denial of service.
- Remediation
- No remediation text is recorded.
