RHSA-2019:3906HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 3.11 HTTP/2 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth
🎯 Affected products99
- Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-1:3.11.154-1.git.1.fa68ced.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-1:3.11.154-1.git.1.fa68ced.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-1:3.11.154-1.git.1.fa68ced.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-svcat-1:3.11.154-1.git.1.fa68ced.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-svcat-1:3.11.154-1.git.1.fa68ced.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-cluster-autoscaler-0:3.11.154-1.git.1.532da7a.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-cluster-autoscaler-0:3.11.154-1.git.1.532da7a.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-cluster-autoscaler-0:3.11.154-1.git.1.532da7a.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-descheduler-0:3.11.154-1.git.1.1d31032.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-descheduler-0:3.11.154-1.git.1.1d31032.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-descheduler-0:3.11.154-1.git.1.1d31032.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-metrics-server-0:3.11.154-1.git.1.6a6b6ce.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-metrics-server-0:3.11.154-1.git.1.6a6b6ce.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-metrics-server-0:3.11.154-1.git.1.6a6b6ce.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-node-problem-detector-0:3.11.154-1.git.1.5e8e065.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-node-problem-detector-0:3.11.154-1.git.1.5e8e065.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-node-problem-detector-0:3.11.154-1.git.1.5e8e065.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-service-idler-0:3.11.154-1.git.1.f80fb86.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-service-idler-0:3.11.154-1.git.1.f80fb86.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-service-idler-0:3.11.154-1.git.1.f80fb86.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-web-console-0:3.11.154-1.git.1.f54cb18.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-web-console-0:3.11.154-1.git.1.f54cb18.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-web-console-0:3.11.154-1.git.1.f54cb18.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- cockpit-0:195-2.rhaos.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- cockpit-debuginfo-0:195-2.rhaos.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- cockpit-debuginfo-0:195-2.rhaos.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- cockpit-kubernetes-0:195-2.rhaos.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- cockpit-kubernetes-0:195-2.rhaos.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- csi-attacher-0:0.2.0-4.git27299be.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- +69 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2019:3906
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_3906.json