Red Hat Security Advisory: OpenShift Container Platform 4.3.38 container image security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-8557 — kubernetes: Node disk DOS by writing to container /etc/hosts CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
🎯 Affected products7
- Red Hat OpenShift Container Platform 4.3
- openshift4/ose-hyperkube@sha256:35d765bfd0987735c36737ff604aa09e0d9b5184bcf8cdc5a057f891a8178522_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-hyperkube@sha256:8127897e9131efb5d35fdc0996849f7c549f2f0b4d3a6c0dc8683b106ab5a6ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-hyperkube@sha256:ba56afca75eb9ab0736e8247d89f600665a6a615fb5801e4e65a1138a59415be_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-sriov-dp-admission-controller@sha256:46586a08d423c95cc94c3830944cefbe60ee5a8d8952c1c13e9c30aea06c0120_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-sriov-dp-admission-controller@sha256:88ff0bdf89bd45df738be9f905b453edc1edae8d4a3fff9209f6f5164edf5dea_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-sriov-dp-admission-controller@sha256:e4fcb04f87b9ade6417003395a9848a1ccdd849f8910656cc8191478c541c9d3_s390x as a component of Red Hat OpenShift Container Platform 4.3
✅ Remediation
For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster-cli.html. Workaround: On OpenShift Container Platform (OCP) 3.11 and 4.x it's possible to set the allowPrivilegeEscalation Security Context Constraint to 'false' to prevent this. Note that this is set to 'true' by default, and setting it to false will prevent certain binaries which require setuid to stop working. On OCP 3.11 for example the 'ping' command will no longer work [1]. On OCP 4.x and later the 'ping' command will work with allowPrivilegeEscalation set to False, but other setuid binaries will not work. [1] https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:3809
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1835977
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3809.json