Red Hat Security Advisory: OpenShift Container Platform 4.9.45 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-2403 — openshift: oauth-serving-cert configmap contains cluster certificate private key CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.9
- openshift4/driver-toolkit-rhel8@sha256:01c90721d3c753dd74fed8801e019a86d6411d944bb8ccdcfef5cbd9aaeaec25_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/driver-toolkit-rhel8@sha256:146050fc2dcc95b78ee1a3bdb6f0f66c14c0258e9c49b781de629c2c73f9200e_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/driver-toolkit-rhel8@sha256:af304c5db025bda03a8ddef449948d6e09ad1a55ab251daa650c0bb6ca428b9f_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/driver-toolkit-rhel8@sha256:e4847d5c2a8336cf887ac0701a9f57cd9076c2665809bc5857b076e88cf637e1_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/egress-router-cni-alt-rhel8@sha256:080ef277659ddeb3013a9565b9ca6473393cb12c2d3e0e3a4908087650f6cec5_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/egress-router-cni-rhel8@sha256:0755290c96c71787645027ccd4409550a832d94009ff5a2b90f3c1a41aedaa90_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/egress-router-cni-rhel8@sha256:8e099215617799bddc5cd7937b6e106ec37bbe8c13f8647c2fc13129cb4df662_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/egress-router-cni-rhel8@sha256:8edcfcd410f78d78fd07027efcece5cec43accd0a4c611dde09005cc77a6e908_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/egress-router-cni-rhel8@sha256:f2efebe714036489a96ac44d7407099b7acdec427b04393c0789cf14d002a693_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/network-tools-rhel8@sha256:31b5b0f8abf584a6a2711d61c3e994c44b532a73cb3e0bc065b8a78ab461c2a5_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/network-tools-rhel8@sha256:37e79d0ef98268e05fb84389ae6ff4518c8b559621b9ec4eb945d025e5a5d4cb_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/network-tools-rhel8@sha256:59ec6b62e6cf6d4920da7f3b3a2a464ab2b8fe1ea1f320ea87bbee67ce21d995_s390x as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/network-tools-rhel8@sha256:6591c91f9c9c11467b1fdd6bdfbd9433a86ba540d8eeb1ccc73222b83a3be2f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:f9153c62e3e102e5c8f417c4b9d21f10c2636c623e75561e82fa7da2f799fa8f_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:f9bc832c0269ab9f83dbde087de438bb84dc3099c231b6051cb757543b4551cc_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:6a93a46043338fc915fd2177a603b0adca74294e2c929d0aa0ad26f2c36c8954_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:c1575a60b36c7fa893eda0fabca9ce6cec790d5ec912dab8c9619dd91105f91c_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:31ad312cf71a98aca8790dd3801997db9fe98f081ff61584829acf702c510501_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:74d4ce97d3de39f2a884d355b2a6ebfba2825c89a6cad94c9f943cc028b70578_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-machine-controllers@sha256:e1a07a7e1337f64b3d0fc346cd52edba2372aaae9f113f7abe15b0f72131d57d_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-machine-controllers@sha256:ede10c2eba3a5b5ce11ac8801e82bf6ecec4d9fbbb0b679e0128519d29a37fd6_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:2ad38d48fb82ab4132f2b10c2a4674b493353359ea7ae155c1e021107f8aa74f_arm64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:978a7be9192d7b297676b8356b65ecbf271e65179d8cd9f168f274ec5e2d7cdd_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:71e6ac121f6586c674b7122e3a0d3a6dd815d1235122593507a82a592dd4409d_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:4c4b97edcc82fc78a1de0d9cafc99d5ee6656868c0df4673dfd0a3124d5e943c_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:18596ac4de291bb4aaecbe443a8cc2deab66418b44af439291bd0c0cd62d6b9a_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:02776b9266e75a31c2cc4b3861c115b52c09b686039a841b9b2058402b3fd95b_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-azure-machine-controllers@sha256:519cac10fdbbcd441a6e9f4ef7850740e042e0fb2777ac6195ee07ea7686e82e_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- openshift4/ose-baremetal-installer-rhel8@sha256:7189622ede28d9b41af701c13102378c8af3f26d8c7d146fca601c801044b696_amd64 as a component of Red Hat OpenShift Container Platform 4.9
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.9 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html Workaround: Removal of the private key from the ConfigMap, or modification of the RBAC permissions is not a sufficient mitigation on its own, as these will both be restored by the authentication-operator. This flaw can be mitigated by deploying a custom webhook which filters out the private key from the target ConfigMap, preventing it from being restored by the authentication-operator. An example of this can be found here: https://github.com/sfowl/configmap-cleaner After upgrading to a fixed version of OpenShift or applying the mitigation, all ingress certificates should be rotated: https://docs.openshift.com/container-platform/4.10/security/certificates/replacing-default-ingress-certificate.html#replacing-default-ingress
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2022:5879
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2009024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055494
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083554
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088539
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091806
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095320
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2097157
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2103982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105277
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105663
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2106655
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108538
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108619
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5879.json