Red Hat Enhancement Advisory: Red Hat build of MicroShift 4.18.1 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-21626 — runc: file descriptor leak
🎯 Affected products19
- Red Hat OpenShift Container Platform 4.18
- microshift-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.src as a component of Red Hat OpenShift Container Platform 4.18
- microshift-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-gateway-api-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-gateway-api-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-gateway-api-release-info-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
- microshift-greenboot-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
- microshift-low-latency-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
- microshift-multus-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-multus-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-multus-release-info-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
- microshift-networking-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-networking-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-olm-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-olm-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.18
- microshift-olm-release-info-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
- microshift-release-info-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
- microshift-selinux-0:4.18.1-202502201910.p0.g84f67ec.assembly.4.18.1.el9.noarch as a component of Red Hat OpenShift Container Platform 4.18
✅ Remediation
For MicroShift 4.18, read the following documentation for important instructions on how to install the latest RPMs and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/red_hat_build_of_microshift/4.18/html/red_hat_build_of_microshift_release_notes/index Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHEA-2024:6124
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2024-001
- externalhttps://issues.redhat.com/browse/OCPBUGS-38848
- externalhttps://issues.redhat.com/browse/OCPBUGS-38974
- externalhttps://issues.redhat.com/browse/OCPBUGS-39260
- externalhttps://issues.redhat.com/browse/OCPBUGS-41510
- externalhttps://issues.redhat.com/browse/OCPBUGS-45973
- externalhttps://issues.redhat.com/browse/OCPBUGS-47463
- externalhttps://issues.redhat.com/browse/OCPBUGS-48577
- externalhttps://issues.redhat.com/browse/OCPBUGS-49417
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhea-2024_6124.json