Red Hat Security Advisory: OpenShift Container Platform 4.12.9 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS
🎯 Affected products116
- Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:685b0c6da28f96f444f9328f4fc9d4ecbf8e766501bb503b65fe0717a1f7695d_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:ccdb5e3417c1fc62b7cec3e22ade3d7bc52952d4721b1df1d5039a2b41303b4c_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:e8152529e313092e46d993d11f7a0170a936ab5fc482a1a4ab809fbb7fecc650_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:f99b9459e6df9ea63728701cf20c75a4b910ecec7fb6fc726bcbbacf24104c96_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:a316872b778970d8eb9a41d7a2464421fa3413bb819da4188755de92999fd33e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:b5cde9867e8daa8001617712277dd2f23f61b6fb893288d840a39d787885a535_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:be0bb04380d3aef1f7d11ed9bf74a319bfe2c362b4e8e3ca69193106232c3485_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:fd68e9ff6552e17155730e6e67f2b96a527e2018ff9f8191d17b324fdfa79bdf_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:695afedef52b9862838aa90a8375dbfa992a6ede922ba8bf6b5a6dadaa9c6597_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a271abfcc0dfa79344edb6accc02e3e9d45a51275b14b82139e969151c35b349_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e48d750744911f12b7f1392a07080f388e0b2d93250d37bd697b866d7f566742_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:fb547f4277d65c118c139e1b306de8fe9f857bd423e89387d1a46408adfd12a7_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:075180fac89ab5e6da473a6dab18081a5a2dd0c5e52f86c66838b9ac2eaac2d5_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:4d80fc6c740b3a7e5601bca57b6e83c64a36d235655a832d54137924e522433e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:b58794e6ea17f47f2284977a38c64261621c9de2fc655347e0e8f56f7b366bb1_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:c8dbc4e2d9302a4b224f9899eb22b19d47a22f88c798e613ac89c18c901432c8_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:62e9884bdbcafbcea5cd6b4d8afd988acd946cb7d5321bb417f8854c28ed3de5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:75c7097b9cfb9240ad52191a9d4a7012f1a41d2c5e755d27de4dfff6027c24a7_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:8c06fbeba942283e1ade75740872b6cc16793e6bc1386f7b232ef79c7188a033_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:fc2ae834a1183dcc691cf035f5283bba7b491e274cf41f9da6eb0288aefd8554_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:83b01ed020dc993861a93ee2bcf1c1ccdb7c5f92cd7d732918a7d77efbcdc5d4_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:87d626cb355352d17bc9e282d7bfaa543beb4235a5c648e4a5dabae1d13cc21f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:b729986b91a05c8cbc8756b0bd5c8c75907da240490b066bfd5d953d72b862a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:bd650a9ad784ee53bada9b2cc8d3c70cba0b9bdf9cc8935f83e8df3bf158fe22_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:134085b0d59cf9c68aa7b7abd17c133e34c768ab0401dc2504ef49a6b51771f8_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:acc858a82698dc0010b8b0e8088df9aba42c2900040e6d168a7d0c44fa03dd77_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:d4bd506304e29c305dc49a0a678985104b1fbd9b0ea594fd54c2288ac918553a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:e288e6b9bf3268953dce40f455b6b0828a4b4026dc6e515d915db7a9afdc771c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:06472af566439230b598baa2603000b06093ee7302d4f2d0b3549754b9ab5fe5_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- +86 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:96bf74ce789ccb22391deea98e0c5050c41b67cc17defbb38089d32226dba0b8 (For s390x architecture) The image digest is sha256:3212a1f7b5dd35e6fc1821d6479792d615fe7fb987c9c202b8bba6e310cb8234 (For ppc64le architecture) The image digest is sha256:82afa12a5c172ef53df9a9bb366c64210fdf164b03b1caf56e0f33ef3f2ad4d4 (For aarch64 architecture) The image digest is sha256:049dda19feec94ab7767e5426a46c24e40e15f8f6a3471f325bfcdd7977f90bb All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHSA-2023:1409
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971033
- externalhttps://issues.redhat.com/browse/OCPBUGS-10241
- externalhttps://issues.redhat.com/browse/OCPBUGS-10289
- externalhttps://issues.redhat.com/browse/OCPBUGS-10318
- externalhttps://issues.redhat.com/browse/OCPBUGS-10372
- externalhttps://issues.redhat.com/browse/OCPBUGS-10490
- externalhttps://issues.redhat.com/browse/OCPBUGS-10496
- externalhttps://issues.redhat.com/browse/OCPBUGS-10497
- externalhttps://issues.redhat.com/browse/OCPBUGS-10505
- externalhttps://issues.redhat.com/browse/OCPBUGS-10514
- externalhttps://issues.redhat.com/browse/OCPBUGS-10587
- externalhttps://issues.redhat.com/browse/OCPBUGS-2439
- externalhttps://issues.redhat.com/browse/OCPBUGS-6036
- externalhttps://issues.redhat.com/browse/OCPBUGS-676
- externalhttps://issues.redhat.com/browse/OCPBUGS-7445
- externalhttps://issues.redhat.com/browse/OCPBUGS-7469
- externalhttps://issues.redhat.com/browse/OCPBUGS-7481
- externalhttps://issues.redhat.com/browse/OCPBUGS-7650
- externalhttps://issues.redhat.com/browse/OCPBUGS-7800
- externalhttps://issues.redhat.com/browse/OCPBUGS-8014
- externalhttps://issues.redhat.com/browse/OCPBUGS-8015
- externalhttps://issues.redhat.com/browse/OCPBUGS-8339
- externalhttps://issues.redhat.com/browse/OCPBUGS-9927
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1409.json