Moderate: Migration Toolkit for Containers (MTC) 1.7.1 security and bug fix update

Synopsis

Moderate: Migration Toolkit for Containers (MTC) 1.7.1 security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

The Migration Toolkit for Containers (MTC) 1.7.1 is now available.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

Description

The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.

Security Fix(es) from Bugzilla:

  • golang: net/http: Limit growth of header canonicalization cache (CVE-2021-44716)
  • golang: debug/macho: Invalid dynamic symbol table command can cause panic (CVE-2021-41771)
  • golang: archive/zip: Reader.Open panics on empty string (CVE-2021-41772)
  • golang: syscall: Don't close fd 0 on ForkExec error (CVE-2021-44717)
  • opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Affected Products

  • Red Hat Migration Toolkit 1 for RHEL 8 x86_64
  • Red Hat Migration Toolkit 1 for RHEL 7 x86_64

Fixes

  • BZ - 2020725 - CVE-2021-41771 golang: debug/macho: invalid dynamic symbol table command can cause panic
  • BZ - 2020736 - CVE-2021-41772 golang: archive/zip: Reader.Open panics on empty string
  • BZ - 2024938 - CVE-2021-41190 opencontainers: OCI manifest and index parsing confusion
  • BZ - 2030801 - CVE-2021-44716 golang: net/http: limit growth of header canonicalization cache
  • BZ - 2030806 - CVE-2021-44717 golang: syscall: don't close fd 0 on ForkExec error
  • BZ - 2040378 - Don't allow Storage class conversion migration if source cluster has only one storage class defined
  • BZ - 2057516 - [MTC UI] UI should not allow PVC mapping for Full migration
  • BZ - 2060244 - [MTC] DIM registry route need to be exposed to create inter-cluster state migration plans
  • BZ - 2060717 - [MTC] Registry pod goes in CrashLoopBackOff several times when MCG Nooba is used as the Replication Repository
  • BZ - 2061347 - [MTC] Log reader pod is missing velero and restic pod logs.
  • BZ - 2061653 - [MTC UI] Migration Resources section showing pods from other namespaces
  • BZ - 2062682 - [MTC] Destination storage class non-availability warning visible in Intra-cluster source to source state-migration migplan.
  • BZ - 2065837 - controller_config.yml.j2 merge type should be set to merge (currently using the default strategic)
  • BZ - 2071000 - Storage Conversion: UI doesn't have the ability to skip PVC
  • BZ - 2072036 - Migration plan for storage conversion cannot be created if there's no replication repository
  • BZ - 2072186 - Wrong migration type description
  • BZ - 2072684 - Storage Conversion: PersistentVolumeClaimTemplates in StatefulSets are not updated automatically after migration
  • BZ - 2073496 - Errors in rsync pod creation are not printed in the controller logs
  • BZ - 2079814 - [MTC UI] Intra-cluster state migration plan showing a warning on PersistentVolumes page