Red Hat Security Advisory: OpenShift Container Platform 4.11.25 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS
🎯 Affected products83
- Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:26b313d5fc339ab5db74d68e8cac3ef7b84161cb825a428533692017113c8f64_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:527f895c4e48592d4e356a05dfd99d153d26dc46e7cc62616277c0d32ace29f3_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d8d5fc4a9325795373425427b0f904e262baa02e0615e1d47c57743eb9d3b763_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:dadfa7419d1456c3b69b1723fa87ebb5e1201b5f83cfd050e85979cec8f50e3b_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-baremetal-installer-rhel8@sha256:5a6a734d32fa55532b9496b7df5d91d8748f9af569f2cc123d3da36c0c1329b8_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-baremetal-installer-rhel8@sha256:6afdc12181634e7b9a6c0361188ccc73dd706805eb4d44f1966a5f62478d3373_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-baremetal-installer-rhel8@sha256:c6505ff796946128e664d07945738890f39a2d3a18032179a8f20ab93b846120_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-baremetal-installer-rhel8@sha256:fc469ef21f3a28c9e8b4d0ea59b43c3f5fc7b2f7ee9d606122e31fa87055edba_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:6c19b5be304596c6f2b79c8fdfdef18f1aa07613a46db31ed97fa9df5d8590d9_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:78ddf33c48f084ed56c381f1d699daa8ac40a3dc93b9f6518d96fbcf8e85c296_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:9c9ece0d29eb90c7b90e683f1750eca3be0e918f17c68d11c6745018a008387b_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:f2dae961099b8ed5469a4f5ed9c8442797b5afb5aaf9e49917f23a0ea85910e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-apiserver-operator@sha256:40a4215452a30e5d10467548bd0dffe936c586df1b886dd6b7a89d126512e734_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-apiserver-operator@sha256:7dfac01ec0e59405bf6e0758ab0d155a8383f4b6057f477e526fe9bdfa26d6c9_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-apiserver-operator@sha256:a0354ea8152c3fcfe78685c2793a5e3daf135a5c2375ad160ed69a0f6e47cf87_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-apiserver-operator@sha256:af4b7637bedc7e14fc0d0198a1769bc067f474f1f8bedb10b0e34b861283b1e9_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:084bb9dcd33b0f4bcc34d075f6e61a1df937a707d2d7e2664602ae0a86050551_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:66f0f5b534a4afd8cff947fbb7b03abb9dfedfbe59116b7408126ec276fb7059_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:755b1faec329bb7f7b6c7754997bef86ec4ff41971f19679dbce221d2a53eee0_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:ef884d0d4d9ad20f7aa49b7839ac0e47a97b17a9a4a68f32a9480162a6b09241_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-scheduler-operator@sha256:ccb55bff35ed797f96e7bf5072b4943c33baebbad51952ff14826e25e6f28ec8_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-scheduler-operator@sha256:d0eb081880a3a2e6c2ed0da7e23890b56a5130a1db1d224fbced556fb14baa0f_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-scheduler-operator@sha256:f208047e07b173cef2c54c532dc3c4dc7c7b7f74f3a4343c3404c3830700e94f_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-kube-scheduler-operator@sha256:f2519c3919357807b682d9115e15f4c0c402c360e56b54de7e51113874a02321_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-network-operator@sha256:1f9eead6783ed8e9ae6aa8cfa5a75c735f0bbad6fa0ed4e73b4e9f6a24a9ec98_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-network-operator@sha256:566dddfb02efe90db92a1a0a513f2be8bd6597641f8da0b8f0165c7f9adf9a14_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-network-operator@sha256:8ad39c5242f27af74e5a3da476c40fc8cb685503aacb6c6325b8baf4d1c98357_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-network-operator@sha256:d61cb17ea28e535298e2cda446fc0648bc0c9b618fb37b5b0d927f1544999dae_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-node-tuning-operator@sha256:4c931bc4e500abc6d3a11458ab1276ccff4e3ab995123768ff96dc2d72ee915b_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- +53 more not shown
✅ Remediation
For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: +Before applying this update, make sure all previously released errata +relevant to your system have been applied. -https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html +For details on how to apply this update, refer to: -You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. - -The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags - -The sha values for the release are: - -(For x86_64 architecture) - The image digest is sha256:2adcf72e10e67ace02ade32467ff7e75680ec1c71545a038196e569dc3149ad0 - -(For s390x architecture) - The image digest is sha256:145501ab2a579a1a02557585d1fb931f77ac10474c49aa051aa7c73b642801bc - -(For ppc64le architecture) - The image digest is sha256:7ec8a170161786b61e29405872bf896b3ca0342b969e2884c1238b444b1dab9f - -(For aarch64 architecture) - The image digest is sha256:75b7b1f10d5b19f91ff7fbf73288b8e6d57447a4cfa3ed134392da95fd7c300b - -All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html +https://access.redhat.com/articles/11258
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2023:0245
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100495
- externalhttps://issues.redhat.com/browse/OCPBUGS-1727
- externalhttps://issues.redhat.com/browse/OCPBUGS-2105
- externalhttps://issues.redhat.com/browse/OCPBUGS-3971
- externalhttps://issues.redhat.com/browse/OCPBUGS-4301
- externalhttps://issues.redhat.com/browse/OCPBUGS-4304
- externalhttps://issues.redhat.com/browse/OCPBUGS-4446
- externalhttps://issues.redhat.com/browse/OCPBUGS-4551
- externalhttps://issues.redhat.com/browse/OCPBUGS-4685
- externalhttps://issues.redhat.com/browse/OCPBUGS-4945
- externalhttps://issues.redhat.com/browse/OCPBUGS-5472
- externalhttps://issues.redhat.com/browse/OCPBUGS-5787
- externalhttps://issues.redhat.com/browse/OCPBUGS-5790
- externalhttps://issues.redhat.com/browse/OCPBUGS-998
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0245.json