Описание
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
A flaw was found in uuid. When external output buffers are used with UUID versions 3, 5, or 6, an attacker with local access may be able to cause unexpected data writes. This vulnerability could lead to low impact data integrity issues. UUID version 4 is not affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Cluster Operator | confidential-clusters-beta/attestation-key-register-rhel9 | Fix deferred | ||
| Confidential Cluster Operator | confidential-clusters-beta/buildroot-rhel9 | Fix deferred | ||
| Confidential Cluster Operator | confidential-clusters-beta/compute-pcrs-rhel9 | Fix deferred | ||
| Confidential Cluster Operator | confidential-clusters-beta/confidential-cluster-operator-bundle | Fix deferred | ||
| Confidential Cluster Operator | confidential-clusters-beta/confidential-cluster-rhel9-operator | Fix deferred | ||
| Confidential Cluster Operator | confidential-clusters-beta/registration-server-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-monitor-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-operator-bundle | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-pccs | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
2.8 Low
CVSS3
Связанные уязвимости
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
uuid before 14.0.0 can make unexpected writes when external output buf ...
EPSS
2.8 Low
CVSS3