Red Hat Security Advisory: OpenShift Container Platform 4.11.42 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2018-17419 — dns: Denial of Service (DoS)
🎯 Affected products59
- Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:082150cc22007fe9c90019ca3ad7dac12b0ed8cab7d1c8c7ff5b155f59736f17_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:521365b0e122d6fbfd6167bb4f3cfdca4c40399c1c82f27196670ebda4282aae_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:63ac5d6b0c7f95086719d31f6ea8b595bbecd84647a8c75a76ee104915f38546_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:afa4538e91f4c9fb5b8ac62ef8ff9e2523f4ef16256220e265b75315006543ab_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:34b133627c417d9d9a5bacba793010e7247039878e4986a6086c4f926d387970_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:91c9d5a36ac6f03a0668384dcfa1c9a479498fe9688f9035167aaa07651e5815_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:be4b821ba60f99a0023adf4b9d1ecba7ffb571c65fd078b907a8c5bf71c52ca1_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:e0fa33f4202acaf40992d29ee689161af743c71129fdc7f4c52effc4e3323608_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:985981af01d868016ce9e1111c95b9f87b17fd82a2d0a983d1211b22799424f0_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d1a022fe93aa112cc506beb6f3a797d73b1bfe70b65bbd8c230923fe201c30be_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e2b1f55fe0c8d3a8b3a1c1171a1b65d96280bec144793c2509528352241bdc8b_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:ed3727e34119ae167f869dd0cb906af160a5dd31a70a3ec56269305b5f82e334_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cloud-credential-operator@sha256:171637f735e42aecaff116cf5809ad9a95aefc000f990a4226cbcd3f53e57577_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cloud-credential-operator@sha256:189e6f364a747b7dbfb3595109404793cee64cfe08c0c18256b262fe5a31cfbb_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cloud-credential-operator@sha256:7f91abc3b14e6f8d1366bc2d81d60a987ffb8d2c9c4295f06ad8a04858e38ed0_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cloud-credential-operator@sha256:c2ce285ea79f7b01d4e03c77775fe95caae9a2f3f44548f1efc6489f2334b9d8_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-node-tuning-operator@sha256:0d58a737dfb486318e1d149da484eac01e25bbba4fdd9f9b663fb0520772207e_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-node-tuning-operator@sha256:9346703015e564a579d4f0b5df68e1032bd94eca43fdc439efe8c55fa9c89055_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-node-tuning-operator@sha256:bf40eb8407f1cb14c549b6c253734d78e383f67bd3d02d297c410914fee06783_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-cluster-node-tuning-operator@sha256:e59aa8b3f756a00115d38c8480e98d83bc047dbb9483a168ed90c505c8548b13_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-console@sha256:33238b13c0ecfddbe31f6d451a2ec8260114cb65c5543e3784bb93ee4990f9ef_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-console@sha256:79a3fd4fcc7b27e4b77aa591667f220d8ba9d72231770a41f6afe773534d6130_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-console@sha256:a56f3224c528c2f5e8154361da24936b6fc6d76ec7fd917635d2d4b3c2dfa7d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-console@sha256:c6192b52d7608845166272f36806ab44cb085613cea47d31148c73fd4c8a7fb8_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-docker-builder@sha256:19768bb9cedef19e38d6bf9fbab7f2b20974bdb984e0dd45daba424feb9ddb59_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-docker-builder@sha256:415b376e7bc5c29c127c98c0d2a1d0fd2d6590e61d12bcf58413a72433acafcc_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-docker-builder@sha256:5cc332ee1a82d2a4da2df874d5e78d99ee54c235bd9a7d82cc813c1ba66e0cca_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-docker-builder@sha256:d2e4f258f1fe4cbbdaff197972229d8840c871665c5941d57ee2eb1400b20aa4_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-haproxy-router@sha256:0dfd7b5f4a111c6f4155735db42834d6649119cac3ee896c6344975720845ebb_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- +29 more not shown
✅ Remediation
For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:518177a34452837920f1e77944f6afa08864537260c9f742b8c88b6157e4f901 (For s390x architecture) The image digest is sha256:c8f1891f3d4a93104a209b96987e07e2077b685238a246da12a656bf69be88c3 (For ppc64le architecture) The image digest is sha256:19ad52422acbd24dde71ae5089471c541004e1c0bf4e13e081e5b65220600c15 (For aarch64 architecture) The image digest is sha256:d87fcd39ad6fad29454ff9137ce521d7049cda2b391ccbdd34554427d60bd27b All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2023:3309
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188523
- externalhttps://issues.redhat.com/browse/OCPBUGS-10276
- externalhttps://issues.redhat.com/browse/OCPBUGS-12231
- externalhttps://issues.redhat.com/browse/OCPBUGS-12254
- externalhttps://issues.redhat.com/browse/OCPBUGS-12263
- externalhttps://issues.redhat.com/browse/OCPBUGS-12279
- externalhttps://issues.redhat.com/browse/OCPBUGS-12284
- externalhttps://issues.redhat.com/browse/OCPBUGS-12959
- externalhttps://issues.redhat.com/browse/OCPBUGS-13730
- externalhttps://issues.redhat.com/browse/OCPBUGS-13746
- externalhttps://issues.redhat.com/browse/OCPBUGS-13792
- externalhttps://issues.redhat.com/browse/OCPBUGS-13822
- externalhttps://issues.redhat.com/browse/OCPBUGS-13864
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3309.json