The vendor explicitly identifies these products as affected by this CVE.
- rhai/assisted-installer-controller-rhel9 as a component of Assisted Installer for Red Hat OpenShift Container Platform 2
- rhai/assisted-installer-rhel9 as a component of Assisted Installer for Red Hat OpenShift Container Platform 2
- multicluster-engine/assisted-installer-agent-rhel8 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-installer-agent-rhel9 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-installer-controller-rhel8 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-installer-controller-rhel9 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-installer-rhel8 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-installer-rhel9 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-service-8-rhel8 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/assisted-service-9-rhel9 as a component of Multicluster Engine for Kubernetes
- multicluster-engine/cluster-api-provider-aws-rhel9 as a component of Multicluster Engine for Kubernetes
- rhacm2/acm-search-indexer-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A flaw was found in the DataRow.Decode function within the github.com/jackc/pgproto3/v2 component. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message containing a negative field length. This improper validation of field lengths leads to a "slice bounds out of range panic", resulting in a Denial of Service (DoS) for the affected application.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
