The vendor explicitly identifies these products as affected by this CVE.
- custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8 as a component of Custom Metric Autoscaler operator for Red Hat Openshift
- custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8 as a component of Custom Metric Autoscaler operator for Red Hat Openshift
- deployment-validation-operator-container as a component of Deployment Validation Operator
- rhoai/odh-data-science-pipelines-argo-argoexec-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ml-pipelines-api-server-v2-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ml-pipelines-driver-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ml-pipelines-launcher-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8 as a component of Red Hat OpenShift AI (RHOAI)
- rhosdt/opentelemetry-operator-bundle as a component of Red Hat OpenShift distributed tracing 3
- rhosdt/opentelemetry-target-allocator-rhel8 as a component of Red Hat OpenShift distributed tracing 3
- Summary
- A flaw was found in Expr. This vulnerability allows excessive memory usage and potential out-of-memory (OOM) crashes via unbounded input strings, where a malicious or inadvertent large expression can cause the parser to construct an extremely large Abstract Syntax Tree (AST), consuming excessive memory.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
