RHSA-2020:4264LowCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.3.40 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.3
- openshift4/ose-aws-machine-controllers@sha256:a8200ba725b924f909d807feb9fe5ec772516432b899100665f65596df8e4ac9_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-azure-machine-controllers@sha256:7d90f2c41fe3ce99984e9233b15eac03dcfd49fdfec23c7cdfbea6c9a280b761_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-baremetal-machine-controllers@sha256:b6d2dc08fa383cdb23c675d0f19595b38d143cb2ef168f57d2d8067b0311758b_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-baremetal-machine-controllers@sha256:f2c22b125ca4226417be231846918974aa4c79b80f8c7cf74d32b66bf447d92f_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-baremetal-machine-controllers@sha256:f61eceefb332e969d2fed96c3e0b462dc062b7379ddb7721ae1d2676f760c064_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cli-artifacts@sha256:0467adfa48ff2f3189cbffcf052dd4edbaa240e900a402c96b8a20c0aa63f045_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cli-artifacts@sha256:239edd014b5ac1987196b5ba993d0c4cdb6f69fbe3734ef0c9ba809446e14c11_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cli-artifacts@sha256:e20b1956f99b93ad3b4c2583d0083dae8904f0c3028f9c3fe8dd35c960282c27_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cli@sha256:4690dfce999a6955d5e94966227d5bc69b96e92c882f931fb8e95a5db06fda21_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cli@sha256:46b7b667830809bd238dd84ae236b6689e8c12a08f89dda4fe27957ccd7d83e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cli@sha256:69867061214ff75525dae0385e7db30c26921347cea5e25d4846e93381080e7d_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cloud-credential-operator@sha256:171a3ec76eecc8fb12e3eaf8dd877c3670e48eaa8154080eba18703366f9af76_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cloud-credential-operator@sha256:1ad0ed1b886931c3b8cfba1fa3f5ad590e42a70efd790afb41db56dab3ccc853_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cloud-credential-operator@sha256:9815c2d2136d035244e4a488254bfa9bd7f255b68342c1738e1ed6ee4d084ee2_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-authentication-operator@sha256:8577a69b7c94a7ae5c252f61abc0b1648ec0f315e38749402b162019ef9a0b36_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-authentication-operator@sha256:d6d8ac30aaf8397b726f871b3595708267df7ad3f35a41ab00948c4cc0b43714_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-authentication-operator@sha256:eb83bc972a170d6639a7b01ed5a2d405f36b80cc395f896753aac3c6f6256e47_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-autoscaler-operator@sha256:2667e1b5ca53f499d40a930159f328580275a125bb60b4cd3f5ad2a197f7e31f_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-autoscaler-operator@sha256:8f8e5f58839278b5790b17ab26a3eccd8c47e6a36916789f0cefe9decef1bd5f_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-autoscaler-operator@sha256:e27751817c500ebdff90457792b606df8ca26bddd7956992e000650bde5a632c_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-autoscaler@sha256:16d0f06ae2a97b777eada84160545b2b35a4d936653ea1616501d764a502d794_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-autoscaler@sha256:76c34f661c23cd0df72994df069e438059f1656b89fea8b78142d6ec24050fb3_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-autoscaler@sha256:825845ff31341da493698a04c3de6531258c38104822f063f20c2670d7136594_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-bootstrap@sha256:3e959714403248f4b4b970afcf9bbdcb36fca65d0903e1eb3c28c5d91304f208_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-bootstrap@sha256:88e64359d3bb6835438d34e6dacaa446f6d9fa8d9118ccadd17ce006149cb743_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-bootstrap@sha256:dbe26b1bb5272854e8d7ce5e980d57059f8fbad28ab63c1a6eef6482ffe002eb_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-config-operator@sha256:4267c403e3087da2895713e138c00ba38123efb094bf121a424d9a7e0dc62309_amd64 as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-config-operator@sha256:9d292cc3a06d3653df0cb033aa200559a779218622e77d46675ba4b75a7dfb9b_s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift4/ose-cluster-config-operator@sha256:f85fdb61230aef54ad84ad7bef0263f85f8c834efa694965df245ff08d6d5d16_ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster-cli.html.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2020:4264
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1836815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1849176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1874018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1874399
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879110
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4264.json