VDB
RHSA-2022%3A2216
RHSA-2022%3A2216
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in Netty's netty-codec due to size restrictions for decompressed data in the Bzip2Decoder. By sending a specially-crafted input, a remote attacker could cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/cluster-logging-rhel8-operator@sha256:04ebd764d8b535f11a6e9e6523a719d9a12000383bcf2c3e582ee9522901ed73_ppc64le as a component of RHOL 5.4 for RHEL 8 | *, openshift-logging/cluster-logging-rhel8-operator@sha256:04ebd764d8b535f11a6e9e6523a719d9a12000383bcf2c3e582ee9522901ed73_ppc64le |
| Red Hat | openshift-logging/opa-openshift-rhel8@sha256:69e854e2aee34946d9614fa031f7f7dda2708bed53fd7405a46e7aad24ef7545_amd64 as a component of RHOL 5.4 for RHEL 8 | openshift-logging/opa-openshift-rhel8@sha256:69e854e2aee34946d9614fa031f7f7dda2708bed53fd7405a46e7aad24ef7545_amd64, * |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:99b7cf5c324fc8af651db31f5b8fc3a7c1703ea2d91e372f7c0f643a70b8a647_ppc64le as a component of RHOL 5.4 for RHEL 8 | openshift-logging/log-file-metric-exporter-rhel8@sha256:99b7cf5c324fc8af651db31f5b8fc3a7c1703ea2d91e372f7c0f643a70b8a647_ppc64le, * |
| Red Hat | openshift-logging/elasticsearch-rhel8-operator@sha256:16b864acf4276f813cb4daa0597d2a7e978267bca4a67deed677cc3de69f282a_arm64 as a component of RHOL 5.4 for RHEL 8 | openshift-logging/elasticsearch-rhel8-operator@sha256:16b864acf4276f813cb4daa0597d2a7e978267bca4a67deed677cc3de69f282a_arm64, * |
| Red Hat | openshift-logging/logging-loki-rhel8@sha256:712763e5a37bff1359ac524a9a0b27512204666832bef5b45cddad6d05729a4b_arm64 as a component of RHOL 5.4 for RHEL 8 | openshift-logging/logging-loki-rhel8@sha256:712763e5a37bff1359ac524a9a0b27512204666832bef5b45cddad6d05729a4b_arm64, openshift-logging/logging-loki-rhel8@sha256:712763e5a37bff1359ac524a9a0b27512204666832bef5b45cddad6d05729a4b_arm64 |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:c72443902663a55aabab92e5915593914bb56300842e6309699a683856b88e1a_amd64 as a component of RHOL 5.4 for RHEL 8 | openshift-logging/log-file-metric-exporter-rhel8@sha256:c72443902663a55aabab92e5915593914bb56300842e6309699a683856b88e1a_amd64, openshift-logging/log-file-metric-exporter-rhel8@sha256:c72443902663a55aabab92e5915593914bb56300842e6309699a683856b88e1a_amd64 |
| Red Hat | openshift-logging/elasticsearch-operator-bundle@sha256:49dd833c9b58247cb2abb78d841551342edb29c430ba0e0b88229870e3dec340_amd64 as a component of RHOL 5.4 for RHEL 8 | openshift-logging/elasticsearch-operator-bundle@sha256:49dd833c9b58247cb2abb78d841551342edb29c430ba0e0b88229870e3dec340_amd64, openshift-logging/elasticsearch-operator-bundle@sha256:49dd833c9b58247cb2abb78d841551342edb29c430ba0e0b88229870e3dec340_amd64 |
| Red Hat | openshift-logging/eventrouter-rhel8@sha256:05a0fd03a2135557cb45c73b1c2c46efbf36f1b52a4becdfd7414b45f1002a8b_s390x as a component of RHOL 5.4 for RHEL 8 | *, openshift-logging/eventrouter-rhel8@sha256:05a0fd03a2135557cb45c73b1c2c46efbf36f1b52a4becdfd7414b45f1002a8b_s390x |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel8@sha256:7ab8aee7cddcea20f7124bdbb90eb8100c1deb5c3bc45a07b8f18fec4242c92c_ppc64le as a component of RHOL 5.4 for RHEL 8 | openshift-logging/elasticsearch-proxy-rhel8@sha256:7ab8aee7cddcea20f7124bdbb90eb8100c1deb5c3bc45a07b8f18fec4242c92c_ppc64le, * |
| Red Hat | openshift-logging/vector-rhel8@sha256:33cc1c4cbda1435a7a4c1fff01b237259296869c59f2529ac4896de78b650a4f_s390x as a component of RHOL 5.4 for RHEL 8 | *, * |
| Red Hat | openshift-logging/loki-rhel8-operator@sha256:0467dda173e8aa009433e7a8682f4ecef586e4709c42775bf57147990e6c6cd0_ppc64le as a component of RHOL 5.4 for RHEL 8 | *, * |
| Red Hat | openshift-logging/eventrouter-rhel8@sha256:05a0fd03a2135557cb45c73b1c2c46efbf36f1b52a4becdfd7414b45f1002a8b_s390x as a component of RHOL 5.4 for RHEL 8 | openshift-logging/eventrouter-rhel8@sha256:05a0fd03a2135557cb45c73b1c2c46efbf36f1b52a4becdfd7414b45f1002a8b_s390x, openshift-logging/eventrouter-rhel8@sha256:05a0fd03a2135557cb45c73b1c2c46efbf36f1b52a4becdfd7414b45f1002a8b_s390x |
| Red Hat | openshift-logging/lokistack-gateway-rhel8@sha256:4575e2f98bab47dd02b244baaca20050843aa8f11c8aba913b70ba8446a2a4b7_arm64 as a component of RHOL 5.4 for RHEL 8 | openshift-logging/lokistack-gateway-rhel8@sha256:4575e2f98bab47dd02b244baaca20050843aa8f11c8aba913b70ba8446a2a4b7_arm64, openshift-logging/lokistack-gateway-rhel8@sha256:4575e2f98bab47dd02b244baaca20050843aa8f11c8aba913b70ba8446a2a4b7_arm64 |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel8@sha256:31642653e7ece566609f8546e2ae48c55380f035d965e67194f70b2f0cd9c9a7_s390x as a component of RHOL 5.4 for RHEL 8 | *, openshift-logging/elasticsearch-proxy-rhel8@sha256:31642653e7ece566609f8546e2ae48c55380f035d965e67194f70b2f0cd9c9a7_s390x |
| Red Hat | openshift-logging/logging-curator5-rhel8@sha256:ca02f9b58428cb51129721cdad182918e3fad94c27e9a82e47199214ef6c032d_s390x as a component of RHOL 5.4 for RHEL 8 | *, * |
| Red Hat | openshift-logging/vector-rhel8@sha256:35b3f1c7671a4d9265a0b397b82838870735b186fc4d543d7c568de6901ad1e8_ppc64le as a component of RHOL 5.4 for RHEL 8 | openshift-logging/vector-rhel8@sha256:35b3f1c7671a4d9265a0b397b82838870735b186fc4d543d7c568de6901ad1e8_ppc64le, * |
| Red Hat | openshift-logging/lokistack-gateway-rhel8@sha256:4575e2f98bab47dd02b244baaca20050843aa8f11c8aba913b70ba8446a2a4b7_arm64 as a component of RHOL 5.4 for RHEL 8 | *, openshift-logging/lokistack-gateway-rhel8@sha256:4575e2f98bab47dd02b244baaca20050843aa8f11c8aba913b70ba8446a2a4b7_arm64 |
| Red Hat | openshift-logging/fluentd-rhel8@sha256:cb4c7926d4f1db746adcf8e86bfa45c5c0264c999787e92223b7ef86eeed80dd_ppc64le as a component of RHOL 5.4 for RHEL 8 | openshift-logging/fluentd-rhel8@sha256:cb4c7926d4f1db746adcf8e86bfa45c5c0264c999787e92223b7ef86eeed80dd_ppc64le, openshift-logging/fluentd-rhel8@sha256:cb4c7926d4f1db746adcf8e86bfa45c5c0264c999787e92223b7ef86eeed80dd_ppc64le |
| Red Hat | openshift-logging/cluster-logging-rhel8-operator@sha256:48e2848133b60700361402d5a8e704bf9fb191ddcd4c1e833942121ece82c663_s390x as a component of RHOL 5.4 for RHEL 8 | openshift-logging/cluster-logging-rhel8-operator@sha256:48e2848133b60700361402d5a8e704bf9fb191ddcd4c1e833942121ece82c663_s390x, openshift-logging/cluster-logging-rhel8-operator@sha256:48e2848133b60700361402d5a8e704bf9fb191ddcd4c1e833942121ece82c663_s390x |
| Red Hat | openshift-logging/lokistack-gateway-rhel8@sha256:3781e0fb7614ff4dd6b2fa7bc9466543ab67b31e17700674fb720f6914da91bd_s390x as a component of RHOL 5.4 for RHEL 8 | *, openshift-logging/lokistack-gateway-rhel8@sha256:3781e0fb7614ff4dd6b2fa7bc9466543ab67b31e17700674fb720f6914da91bd_s390x |
…and 98 more
Timeline
- May 11, 2022 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2022:2216 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2004133 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2004135 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2031958 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2045880 issue
- https://issues.redhat.com/browse/LOG-2437 advisory
- https://issues.redhat.com/browse/LOG-2442 advisory
- https://issues.redhat.com/browse/LOG-2448 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_2216.json advisory
- https://access.redhat.com/security/cve/CVE-2021-37136 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-37136 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-37136 advisory
- https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv advisory
- https://access.redhat.com/security/cve/CVE-2021-37137 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-37137 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-37137 advisory
- https://access.redhat.com/security/cve/CVE-2021-43797 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-43797 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-43797 advisory
…and 5 more