Red Hat Security Advisory: OpenShift Container Platform 4.12.4 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products73
- Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:72771c29297542a88725042b93217e2a62d2413bdc5632aadd3528f54947a7f6_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:84530b3a6263ecc830664b1b0a66169692ccefa8b6782b44409ee0325e40d3c9_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:a8642b799958817ab8d71f152c44e1521510a1967ff4a50ea426d35e5db4a4a0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:c5fc25afc15ab434a0e20174c7effaa0c6026b9c054d6fcc2544c8f009f4a62c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:05b1be24b87c0d8d3d6dbb736b32044fcad3bd279941f2bb4f67abcc02882f95_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:9546804cdc3e65cce30454d435ac8e1f8f350195420bb1fdd6ca69a7143eebfb_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:aa3f96f626ae4f9506c390c6cb70a8a1c9751678e7aaec459dd19764794e770d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:cca9898ee21e4b70895dbe5b1bab1b7e47b70eeb917cde04232fa57eebab1d02_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:588ac55464f3db25117a8ed20a793ec3c76992aab7573c1c3fbaa9fc8c5d5b4f_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:97c8bf7268093a39fc8e62b96b55ce9a9650ebbdab452b694040401931ad9a88_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:9e9a7abfa50e2d0548b79bda27933eeb8d91b8e60bc96e1ec873b9956afcdfdf_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:f85469ba47a9ee6e36d92e2f94da886e0548858b36be2a215fa80a4506c8e574_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-samples-operator@sha256:932e91b0e2b78feb6d7cd504ac3cf204288c401da04c0496cf6aa7d147d6495d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-samples-operator@sha256:a87ed5ada883dd8f47f5046ad924318d4572970c3da4266d49f4b5660c44f349_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-samples-operator@sha256:f24208c9f4f20e8629cc18536c0e8f67cba063e66e0db49b25801a987948376f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-samples-operator@sha256:fed6e1d2cff5f1d7b42f8305399bd214d87ca2a0706ab51d7a758fb608738e14_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-driver-manila-rhel8-operator@sha256:1ca0a575d371e8a1e5ed6f907063f204e14cfc340ded15d31858dc921608a2d8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-driver-manila-rhel8-operator@sha256:a9779ba505bfd7075fd0ca4a7317e72806d21b70cb83112572750d67aef1c2e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-driver-nfs-rhel8@sha256:5b77f1a5b97cf1669162775bce0d17fcf17c9fa08aaecc52da3ec718b2673a44_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-driver-nfs-rhel8@sha256:ca5a46cfbea257ddb3803a921349bb406e26f2498d4f3bfd778d36d9286bdbb4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-hypershift-rhel8@sha256:2c0de48d3b4b3bafa1bce456b60086e3cdf65c1f7f1e3ea46c2cf052201ff3de_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-hypershift-rhel8@sha256:38d60e7ca124f74a61179c68f46f9adde20ee785bfaf531043fc8c642b8995ec_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-hypershift-rhel8@sha256:47329371db6a77967951bb526f9ed4d6a91217fc9e53f0d0488299a833ea7f19_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-hypershift-rhel8@sha256:5f9dd763425e75cfea871a0ff106b3eedf78e12b40d23624006df5cbd12659cc_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-installer-artifacts@sha256:441ea59de2756468d73f0d9a0f1c636352eab3863bd3eef1b873b394323d2711_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-installer-artifacts@sha256:45d2bbd6d99d2fcbba28efaf63583779db1762449a3d8fc8356f99321c187931_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-installer-artifacts@sha256:53c7d9d0d466b77889aec7c60b1d1190db51c216fceb4e10dab4144bdb3209f6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-installer-artifacts@sha256:950dbc4bc28446b76c5cdb1abcad9328ab4f3da4821f6d837702d9b6bd6b0f64_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-installer@sha256:5879ca08cd9098a2c3842ef59b928e5764577e6ab07c51aba28373a8525f824c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +43 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:bbf1f27e5942a2f7a0f298606029d10600ba0462a09ab654f006ce14d314cb2c (For s390x architecture) The image digest is sha256:12e389281c05ba0589197af676dd460f668da162181cb8f3edb8f27101d14c39 (For ppc64le architecture) The image digest is sha256:853c1577bcb33350c0c19a535c14965bdeee4c6a471dd988f08ae241b866c8fc (For aarch64 architecture) The image digest is sha256:2a7f99c2814704b2bbb1ba4c06ce87c50384f87fb120b71d02a2f6bca8c867c6 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2023:0769
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/OCPBUGS-4778
- externalhttps://issues.redhat.com/browse/OCPBUGS-6260
- externalhttps://issues.redhat.com/browse/OCPBUGS-6637
- externalhttps://issues.redhat.com/browse/OCPBUGS-6779
- externalhttps://issues.redhat.com/browse/OCPBUGS-6788
- externalhttps://issues.redhat.com/browse/OCPBUGS-6807
- externalhttps://issues.redhat.com/browse/OCPBUGS-6973
- externalhttps://issues.redhat.com/browse/OCPBUGS-7044
- externalhttps://issues.redhat.com/browse/OCPBUGS-7208
- externalhttps://issues.redhat.com/browse/OCPBUGS-7227
- externalhttps://issues.redhat.com/browse/OCPBUGS-7230
- externalhttps://issues.redhat.com/browse/OCPBUGS-7285
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0769.json