RHSA-2023:1326HighCVSS 7.8

Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update

Published
May 17, 2023
Last Modified
August 23, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2021-4235 — go-yaml: Denial of Service in go-yaml CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2022-23525 — helm: Denial of service through through repository index file CVE-2022-23526 — helm: Denial of service through schema file CVE-2022-27191 — golang: crash in a golang.org/x/crypto/ssh server CVE-2022-41316 — vault: insufficient certificate revocation list checking CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-41721 — x/net/http2/h2c: request smuggling CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2022-41724 — golang: crypto/tls: large handshake records may cause panics CVE-2022-41725 — golang: net/http, mime/multipart: denial of service from excessive resource consumption CVE-2022-46146 — exporter-toolkit: authentication bypass via cache poisoning CVE-2023-0620 — vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File CVE-2023-0665 — hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata CVE-2023-25000 — hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations CVE-2023-25165 — helm: getHostByName Function Information Disclosure CVE-2023-25173 — containerd: Supplementary groups are not set up properly CVE-2023-25809 — runc: Rootless runc makes /sys/fs/cgroup writable CVE-2023-27561 — runc: volume mount race condition (regression of CVE-2019-19921) CVE-2023-28642 — runc: AppArmor can be bypassed when /proc inside the container is symlinked with a specific mount configuration CVE-2023-30841 — baremetal-operator: plain-text username and hashed password readable by anyone having a cluster-wide read-access

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:46d268ff30d7e1d7c7288a6fda90d7177949d1be35a88c7b410daf40b34acb87_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:852e868322d78354e0e3497bd90e71b5e12bffdff2b0197c1c5779c5c068272d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:cc2efc3ec75a2b36b7e37a37ec224d674402c117eaff6656bd65b0179b5f8cb9_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:dd8921a864fd09a7125936f58dda6470941f3f3bcbff8ffc7bb8553c3bc36ba1_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:287a8cd5b789d73e8621c858499f65732099c55aea22cc4f2e9fc4f8f06d667e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:9d19bba25f4b598774e7a8bde385e26d40760a6e2e07e4882d1c8541c981ceba_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:a7af1e954999da184042db8646c703030fb15b299de3a067c3d4d0880af0d389_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:f28ea90f5ea10a591f83cec5cd55e520abd7e4171d284d584381c5dacf1692ae_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:4d282ea8837b4c8da08af1a0f53cc4cf01cee5be5df7a19ae059600cbe283180_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:60de1ecf642c5ed2c22597ade0cbc33653ec3d15282a8db5c1e9651de7e51321_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:8e525dbee2977254346f74c3c2e748e33b78743c609ca82bd517499380c87df1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:a0eae4a05685c7e19af3565b486141a7b1f63f09b0bdccb71f6352808bb23f30_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:236c4aef340426cc3c0ec9196902c03033bd25d5426d16cc49f17973e02ba487_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:2e64b1238f73554c80cb24dbde31c1c83a876948d41ffef7ffd89ce6954dfa31_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:795fcf81145116cabb7169229e9d36d068bf36ff2f9531b0fd361099f1c545b8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:a1bfc274eb04718a68e3bf6bd47aef37207d68608432732a3642614124334f62_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:192eff7fbedb953f35743cbb77412a3e14d3051304c0fcd1536c8ef077e29d50_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:79432595b5d8ffad893dfc747348af5084e0bdeb171f4ec584e537b93841faf3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:ba503a2b617242a720ffc86e95f5631bf6b084e20ec016162f46e6d41093e9c0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:fb539eea87a15ab87a1edfb1a9cf8edfc3e32859be33c781d88b1421ece77b6b_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/oc-mirror-plugin-rhel8@sha256:6389a4c878a823106ddba960f49ff74350283a21e307247ecce6dba0856a9b84_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:0b325e6dcc24bb1ad8ab57bc35bd970070d4c1143d0af4ead2728ac2e0d158bb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:8f55c0ac97172d70dee7032cda626fdf4af35ae3e79211db032906f29b7c5405_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:ac9ae0b0b9be554c02cfcd9d5f0d110c9e656c13f301585f68bc9a4745c9da38_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:b5529f169f3a9212f26f5be5312b018c06d378cec3ccf663137cc78b09ae0c7c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:0a1f7a9357bf2408e2efd598952f314158e7fac1703f055b4dc614e562c508d2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:1d73cf64abffab71dc2e995c22158fcffdd2484131290cbc3fd520c4037d3929_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:dc4a8245993eee1cd928fbc4a45bf94a5b9147dbdd1af20e58040f86057d6f57_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:e8ea11352375a8bd53ebe8a98f18fd0d00e0d676645743d4529bc8b6fbd5d63d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:74b23ed4bbb593195a721373ed6693687a9b444c97065ce8ac653ba464375711 (For s390x architecture) The image digest is sha256:a32d509d960eb3e889a22c4673729f95170489789c85308794287e6e9248fb79 (For ppc64le architecture) The image digest is sha256:bca0e4a4ed28b799e860e302c4f6bb7e11598f7c136c56938db0bf9593fb76f8 (For aarch64 architecture) The image digest is sha256:e07e4075c07fca21a1aed9d7f9c165696b1d0fa4940a219a000894e5683d846c All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Condition 1: Unshare the cgroup namespace ((docker|podman|nerdctl) run --cgroupns=private). This is the default behavior of Docker/Podman/nerdctl on cgroup v2 hosts. Condition 2 (very rare): add /sys/fs/cgroup to maskedPaths Workaround: Avoid using an untrusted container image.

🔗 References (911)