Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-4438

Published: 8 May 2024

The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

Notes

AuthorNote
rodrigo-zaiden
only affects etcd as distributed in RH OpenStack.

Priority

Medium

Status

Package Release Status
etcd
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(Red Hat OpenStack only)
focal Not vulnerable
(Red Hat OpenStack only)
jammy Not vulnerable
(Red Hat OpenStack only)
mantic Not vulnerable
(Red Hat OpenStack only)
noble Not vulnerable
(Red Hat OpenStack only)
upstream Not vulnerable
(Red Hat OpenStack only)
xenial Not vulnerable
(Red Hat OpenStack only)