ALAS2NITRO-ENCLAVES-2023-029

Related Vulnerabilities: CVE-2022-41723  

http2/hpack: avoid quadratic complexity in hpack decoding (CVE-2022-41723)

ALAS2NITRO-ENCLAVES-2023-029


Amazon Linux 2 Security Advisory: ALASNITRO-ENCLAVES-2023-029
Advisory Release Date: 2023-08-31 22:44 Pacific
Advisory Updated Date: 2023-09-06 20:30 Pacific
Severity: Important

Issue Overview:

http2/hpack: avoid quadratic complexity in hpack decoding (CVE-2022-41723)


Affected Packages:

amazon-ecr-credential-helper


Issue Correction:
Run yum update amazon-ecr-credential-helper to update your system.

New Packages:
aarch64:
    amazon-ecr-credential-helper-0.7.1-1.amzn2.aarch64
    amazon-ecr-credential-helper-debuginfo-0.7.1-1.amzn2.aarch64

src:
    amazon-ecr-credential-helper-0.7.1-1.amzn2.src

x86_64:
    amazon-ecr-credential-helper-0.7.1-1.amzn2.x86_64
    amazon-ecr-credential-helper-debuginfo-0.7.1-1.amzn2.x86_64