The vendor explicitly identifies these products as affected by this CVE.
- openshift-sandboxed-containers/osc-monitor-rhel9 as a component of Confidential Compute Attestation
- openshift-sandboxed-containers/osc-operator-bundle as a component of Confidential Compute Attestation
- openshift-sandboxed-containers/osc-podvm-builder-rhel9 as a component of Confidential Compute Attestation
- openshift-sandboxed-containers/osc-podvm-payload-rhel9 as a component of Confidential Compute Attestation
- openshift-sandboxed-containers/osc-rhel9-operator as a component of Confidential Compute Attestation
- clevis-pin-trustee.src as a component of Red Hat Enterprise Linux 10
- trustee-kbs as a component of Red Hat Enterprise Linux 10
- virt-firmware-rs.src as a component of Red Hat Enterprise Linux 10
- clevis-pin-trustee.src as a component of Red Hat Enterprise Linux 9
- kata-containers as a component of Red Hat OpenShift Container Platform 4
- kata-containers.src as a component of Red Hat OpenShift Container Platform 4
- openshift-update-service/openshift-update-service-rhel8 as a component of Red Hat OpenShift Update Service
- Summary
- A flaw was found in AWS-LC. This vulnerability, a timing discrepancy, allows an unauthenticated attacker to potentially determine the validity of an authentication tag. This information disclosure could be exploited through timing analysis.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
