Red Hat Security Advisory: OpenShift Container Platform 4.10.53 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products95
- Red Hat OpenShift Container Platform 4.10
- openshift4/network-tools-rhel8@sha256:93dcc8c8f3488b2192713b2babfeb139c91085b93897a8046957ec93d438b19f_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/network-tools-rhel8@sha256:9d4baa4bf3c74337caad4a3f086a58c7918a78e2c98e52d729fca3622a314bf2_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/network-tools-rhel8@sha256:c0ff1faea9cb231c6f12fd9e8e19cb75dcc77037678fc99c9daf8ccea8e120c5_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/network-tools-rhel8@sha256:c84231cb0d2df3f57a077681d3bebbb47a21ac71a3b57b9954d66803d252ebaa_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-baremetal-installer-rhel8@sha256:82eb96e82fbcc21185884af843c81ee75bcef664cc0b76d79fac46e24ddf0984_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-baremetal-installer-rhel8@sha256:a104166e49a88838b66dd235758c8fda497e4153c1fbf10950bc19a6c814f641_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-baremetal-installer-rhel8@sha256:d54262bec04647efa94e6a174c57e990403cd0a55c8a6abae20f1230b8738814_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-baremetal-installer-rhel8@sha256:efee080077665dcdcd6c0086285357e32272290f4b6a8f7b1c675c67b2d9dcc2_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-cluster-image-registry-operator@sha256:190f105de509c02ec4f3c943c60deb5c198b7836ca7970c3d03f6c20e6309a07_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-cluster-image-registry-operator@sha256:6162407db0914afde72f4ec95d41a48976b758ea89b07a975acbf69b5f441318_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-cluster-image-registry-operator@sha256:68617d7e658432680aa01e588813fc85251092539981ebef13ba9753659f5eb8_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-cluster-image-registry-operator@sha256:9820e185150aa4e0290b3e5e07b76787c9bd03a32914d7b015a77b678e2f8e4d_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-console@sha256:01de26d162b02079dadbbf197a016a45f2ee08941e0e961b5a71037e5d83d26c_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-console@sha256:8345bad8e4adf449a63bda505de417d31fb3fa245a95ae8dbfec5aa7dd03d854_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-console@sha256:cf2151927a924613c5a1b64d3aa85adc8960c78d7daf2662b775c90ccd80a2f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-console@sha256:eae9114b14071c50a1996b95eccf6fad8df53c5cc689dce069dec466413430d4_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-csi-driver-manila-rhel8@sha256:2c110cdd58fcabd6d16cf9344c4caddb28145d8895c9c66f5f4d33db011265dc_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-csi-driver-manila-rhel8@sha256:69c96cebb34dacb5111cf609e6ffa204b624624044c6f10231063a6357c80f37_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-etcd@sha256:04e9f70a3796bd206e7b048fa00f00eb6d0026b1b5fb394d390b15a01de48756_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-etcd@sha256:449b8fc6893df653b49b07b36ba3dfbc55b439e674f68b73f1f236958c77fd0a_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-etcd@sha256:83c80bf5a8d81874e1da66b25a490847f6171f4e72de797d6e44a7d169ec67ee_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-etcd@sha256:cde757f68f909f7980764a9f13dafe364cdf811551e32e7add14a894219c2392_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-haproxy-router@sha256:136e95e6356a9d7e61b5b75b04717725474a46e519e89335f161816ee3f41f51_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-haproxy-router@sha256:5a6de45209e1bfb08e7b6a818bf0c965ef629b54402f404f67fc0675286d0acb_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-haproxy-router@sha256:c2734b7d6aec1af99a65b04ee83cdbb09547e76c4a69506b44c25b08c779705c_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-haproxy-router@sha256:e9929fa3b5e7acb47efd12397e920abccdd18dde3199d1a9dd53b966e9ffb0e7_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-image-customization-controller-rhel8@sha256:4c0387c16970cd9b001d6323cfff4520fecf36ac162758f5fa5e6d2e90c86dde_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-installer-artifacts@sha256:527f7f1fabd50ce3d6708b7db3ff0c93b5bbff78e6f2daf81a17194a416783b5_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/ose-installer-artifacts@sha256:60ef556085811ecb2f1bf8e5d5b708fa04b6709d8c5e4acc7308f6bc55940977_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- +65 more not shown
✅ Remediation
For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:0f683cf611bd6f2d3ab045b52df0fcda8adefa086e6ee80c5551275e5692cd8c (For s390x architecture) The image digest is sha256:1b9f19ab333e2b8d5d86e03dbfdbdfa731174fc07469e89bf1d009f9c07fab0e (For ppc64le architecture) The image digest is sha256:78a9d2dc1ed7bdfc844018f5c9fbe95659e6650353ea81cd628ee6d485b4c509 (For aarch64 architecture) The image digest is sha256:aaaffe6fde419d0b75c85742ba4adc1aa1698d0f4bad1149241a92ad5290f543 All OpenShift Container Platform 4.10 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:0899
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092895
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163037
- externalhttps://issues.redhat.com/browse/OCPBUGS-2013
- externalhttps://issues.redhat.com/browse/OCPBUGS-2731
- externalhttps://issues.redhat.com/browse/OCPBUGS-3656
- externalhttps://issues.redhat.com/browse/OCPBUGS-3943
- externalhttps://issues.redhat.com/browse/OCPBUGS-6697
- externalhttps://issues.redhat.com/browse/OCPBUGS-6911
- externalhttps://issues.redhat.com/browse/OCPBUGS-6933
- externalhttps://issues.redhat.com/browse/OCPBUGS-6972
- externalhttps://issues.redhat.com/browse/OCPBUGS-7012
- externalhttps://issues.redhat.com/browse/OCPBUGS-7315
- externalhttps://issues.redhat.com/browse/OCPBUGS-7533
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0899.json