Red Hat Security Advisory: OpenShift Container Platform 4.12.19 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2018-17419 — dns: Denial of Service (DoS)
🎯 Affected products87
- Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:052ff26099d12eeefb091886fb025b36134c5a71cd67b21623a2ee1a7093193f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:5fa3537e9a3e6d6e24567faeca0159a7d66ecf43d1ed42575d4ce214d1408444_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:a13de971e0ba038eb719284c54363083ba4698968dfd813d2fb313eb25a7d4e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:c3f8f489ce56ec03064a552bf4e85c9dab6c35b3c9f29c301e33c9ac8be03bf6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:222734de7fa3f5f05ffe52a5f768e2ed5f777b8b98d1c4e6d6e4a2eb26db3228_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:395685c02c01238b0683bb5c701b40a2cf29d7a85ff17bd9760e9fe297fef708_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:765f6f2218e07d77bd43c7f2b4d5e3c3e163b2de6f8b157d3e871ac6b1e945aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:a4345c7406f634a92336c5f0250144bb1e9eb002fb42c9d9b236c38c33be3b58_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:606c52e072f84cda327e09422f162df5d048649e7b14b809cd4a4c39b56102fd_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:7797f95c15da8c6f81c3d7664c329238cb0b5fdbdffb74d18ea03511f2feb3c4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:8d61d9e735404c2c89b900e74788bd9a6266ccd1d212c28466d13ceb7e837ccf_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:d6f42b96be3870ecbb649cd9cffa520b020fa54d355b2d2a6cbb31736cb90a98_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:61106eadd60b76fe1f8b8a701c3ef552439e8548313a1966ba54e4dd3f2c012a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:799571d70aaec06b9c705d281a635ad299dd7d771b9fa439a36aac9536aa503a_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:9cd216db0ce0517609c8c55d1f88b0edd1f6837db2b1ead283bd5bc530283aa6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-rhel8-operator@sha256:aacc7590ea3d3af9e641d6844585ef8bf3922c08a1fd8a638b7f9bbb327347b8_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cloud-credential-operator@sha256:200b3fe70359f82698e3206949cfb89677bc45caaa039bfd931cf899fddcc480_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cloud-credential-operator@sha256:2ee027a0c5335da2d34fe85a5ba841f086769731be732b4532c6d8d59682fbd6_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cloud-credential-operator@sha256:581bfb29847aa9e10a74a3bec6ee8e16a1c45fc63258c527ae20ea6a30da10fa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cloud-credential-operator@sha256:61e97ce98c720c9891b284c2e3da95a1e9fba7fb564401bd1043e4129b603642_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:0d5ded10f510225678c8e0b38c6fc9fc7722d1ebb260414fcea517a38be5bf7a_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:20929cd82fb9165e2b4a176c3482da263494bb7c7371a16eba56d18f65543a99_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:39cd459114207a561e80fc19605797cb7c2141febe86a66b799b17a42ccd8b0c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:3ed552879211e0e5195dcaff39f4208808e889471b74c11de5e73adad0d3cafa_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-storage-operator@sha256:222fa39abd2cf68693ad22e47718b3792aa33389429f97cc6b25c37c4f1c1b8d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-storage-operator@sha256:503cc9d2880e43d4c211a887cc5c67f1cd481c2553048aad74d4454e263a49e7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-storage-operator@sha256:c9f434f6a42842955acecb9413b3eea40235d604e3e46037a65fb07b9aad27dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-storage-operator@sha256:ff373ddb37ca3fac8f43c25e83974839e9492325e7dca9cdf473cc85e410082d_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-console-operator@sha256:009891cd53f05a978356a21700cd7acb95f23181579aad2544066d1c9759bd68_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- +57 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:41fd42cc8b9f86fc86cc8763dcf27e976299ff632a336d393b8e643bd8a5f967 (For s390x architecture) The image digest is sha256:13666e036043e0d2283890259861a8b8132e6afc818973a2f8bab28d9947cd94 (For ppc64le architecture) The image digest is sha256:00b61dd3ae8d8da28eb7a5385eb1c7f200efa73023e44b1c220a7d041ca1bad1 (For aarch64 architecture) The image digest is sha256:3d73e42724be8f53f8511df17ef900225305226d37397ffde3385cbc6c55a132 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2023:3287
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188523
- externalhttps://issues.redhat.com/browse/OCPBUGS-10275
- externalhttps://issues.redhat.com/browse/OCPBUGS-12787
- externalhttps://issues.redhat.com/browse/OCPBUGS-13530
- externalhttps://issues.redhat.com/browse/OCPBUGS-13599
- externalhttps://issues.redhat.com/browse/OCPBUGS-13719
- externalhttps://issues.redhat.com/browse/OCPBUGS-13739
- externalhttps://issues.redhat.com/browse/OCPBUGS-13743
- externalhttps://issues.redhat.com/browse/OCPBUGS-13750
- externalhttps://issues.redhat.com/browse/OCPBUGS-13757
- externalhttps://issues.redhat.com/browse/OCPBUGS-13760
- externalhttps://issues.redhat.com/browse/OCPBUGS-13821
- externalhttps://issues.redhat.com/browse/OCPBUGS-6848
- externalhttps://issues.redhat.com/browse/OCPBUGS-7439
- externalhttps://issues.redhat.com/browse/OCPBUGS-7619
- externalhttps://issues.redhat.com/browse/OCPBUGS-7924
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3287.json