The vendor explicitly identifies these products as affected by this CVE.
- custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8 as a component of Custom Metric Autoscaler operator for Red Hat Openshift
- lvms4/topolvm-rhel8 as a component of Logical Volume Manager Storage
- mta/mta-hub-rhel9 as a component of Migration Toolkit for Applications 6
- openshift-serverless-1/eventing-mtping-rhel8 as a component of OpenShift Serverless
- rhceph/rhceph-5-dashboard-rhel8 as a component of Red Hat Ceph Storage 5
- rhceph/rhceph-6-dashboard-rhel9 as a component of Red Hat Ceph Storage 6
- openshift-selinuxd-container as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-contour-rhel8 as a component of Red Hat OpenShift Container Platform 4
- ocs4/cephcsi-rhel8 as a component of Red Hat Openshift Container Storage 4
- rhods/odh-ml-pipelines-cache-rhel8 as a component of Red Hat OpenShift Data Science (RHODS)
- rhods/odh-operator-base-rhel8 as a component of Red Hat OpenShift Data Science (RHODS)
- devspaces/devspaces-rhel8-operator as a component of Red Hat OpenShift Dev Spaces
- Summary
- A vulnerability was found in how Envoy Proxy implements the HTTP/2 codec. There are insufficient limitations placed on the amount of CONTINUATION frames that can be sent within a single stream. This issue could allow an unauthenticated remote attacker to send packets to vulnerable servers, which could use up compute resources to cause a Denial of Service.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
