The vendor explicitly identifies these products as affected by this CVE.
- rhai/assisted-installer-agent-rhel9 as a component of Assisted Installer for Red Hat OpenShift Container Platform 2
- rhai/assisted-installer-controller-rhel9 as a component of Assisted Installer for Red Hat OpenShift Container Platform 2
- rhai/assisted-installer-rhel9 as a component of Assisted Installer for Red Hat OpenShift Container Platform 2
- openshift-builds/openshift-builds-controller-rhel9 as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-git-cloner-rhel9 as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-image-bundler-rhel9 as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-image-processing-rhel9 as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-operator-bundle as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-rhel9-operator as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-shared-resource-rhel9 as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-shared-resource-webhook-rhel9 as a component of Builds for Red Hat OpenShift
- openshift-builds/openshift-builds-waiters-rhel9 as a component of Builds for Red Hat OpenShift
- Summary
- A race condition has been discovered in the golang filepath.Walk and filepath.WalkDir functions. This race condition exists where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
