CVE-2023-3089
published 2023-07-05CVE-2023-3089: A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.52%
40.8th percentile
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wj5p-x3cr-46w8: A compliance problem was found in the Red Hat OpenShift Container Platform
ghsa_unreviewed·2023-07-05
CVE-2023-3089 [HIGH] CWE-521 GHSA-wj5p-x3cr-46w8: A compliance problem was found in the Red Hat OpenShift Container Platform
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
Red Hat
openshift: OCP & FIPS mode
vendor_redhat·2023-07-05·CVSS 7.0
CVE-2023-3089 [HIGH] CWE-327 openshift: OCP & FIPS mode
openshift: OCP & FIPS mode
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
Statement: https://access.redhat.com/security/vulnerabilities/RHSB-2023-001
The static scanning tool (to verify your system is once again compliant with FIPS) is available here https://github.com/openshift/check-payload
Mitigation: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update th
No detection rules found.
No public exploits indexed.
Wiz
EKS Security Best Practices | Wiz
blogs_wiz·2026-02-25
EKS Security Best Practices | Wiz
## What is Amazon EKS?
Amazon Elastic Kubernetes Service (EKS) is a managed Kubernetes service from AWS that operates the control plane—including the Kubernetes API server and etcd—within an AWS-managed virtual private cloud (VPC). AWS automatically scales, patches, and updates these components, allowing customers to interact with the control plane via Kubernetes and AWS APIs without the overhead of provisioning or managing the infrastructure themselves.
The shared responsibility model shapes the security posture of EKS:
AWS secures the underlying infrastructure and control plane.
Customers secure the upper layers by hardening nodes, protecting workloads, and configuring network, identity, and policy controls.
While AWS delivers automation and resiliency, teams manage configuration, c
Wiz
EKS Security Best Practices | Wiz
blogs_wiz·2026-02-25
EKS Security Best Practices | Wiz
## What is Amazon EKS?
Amazon Elastic Kubernetes Service (EKS) is a managed Kubernetes service from AWS that operates the control plane—including the Kubernetes API server and etcd—within an AWS-managed virtual private cloud (VPC). AWS automatically scales, patches, and updates these components, allowing customers to interact with the control plane via Kubernetes and AWS APIs without the overhead of provisioning or managing the infrastructure themselves.
The shared responsibility model shapes the security posture of EKS:
- AWS secures the underlying infrastructure and control plane.
- Customers secure the upper layers by hardening nodes, protecting workloads, and configuring network, identity, and policy controls.
While AWS delivers automation and resiliency, teams manage configuration
Bugzilla
CVE-2023-54034 kernel: Kernel (iommufd): Information Disclosure via uninitialized memory padding
bugzilla·2025-12-24
CVE-2023-54034 [MEDIUM] CVE-2023-54034 kernel: Kernel (iommufd): Information Disclosure via uninitialized memory padding
CVE-2023-54034 kernel: Kernel (iommufd): Information Disclosure via uninitialized memory padding
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Make sure to zero vfio_iommu_type1_info before copying to user
Missed a zero initialization here. Most of the struct is filled with
a copy_from_user(), however minsz for that copy is smaller than the
actual struct by 8 bytes, thus we don't fill the padding.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122438-CVE-2023-54034-3089@gregkh/T
2023-07-05
Published