Red Hat Security Advisory: OpenShift Container Platform 4.13.3 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-25173 — containerd: Supplementary groups are not set up properly CVE-2023-26054 — buildkit: Data disclosure in provenance attestation describing a build
🎯 Affected products170
- Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:393604d959c1d7a501abfa8890594ce92ae2938741c48767d4b866fb49bdc481_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:8a98c5324a9ce23955fbea3b65a797ab8be78aee5f2379b346296cb5b5fbd7c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:993050cfa37f09c1a302faab1a12a1d3f70ad01008e9c0c3ddfaecf63a438918_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:b6a56357c202111ae442ea6fab721e745ccc9e572dce61dc8c4782eabc1f12ec_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:0ac2bbd059b2c6a130bda04ec48076dea7b8263bd6c4a42861f4d642e2ec55b8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:1466ac0808b3ad037567bbcb05e370409d8336d781d1e4573a09437512f93134_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cd24d548e117b3ca550cb91a06233e071f9bc5ae47480ce0c92e3c8efca7d2e3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:e05f2b5b6e35f5e0262efc8648aa60ce911a37a387a1f2f876f252a180a54403_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:66bd5abc231f2e9dbf6727b11ef7b2c8b0f18e78eb009ed255a60e83117d3259_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:193d7eff82c963055fe9bcba49aaab7d1697a206ca80efd7120223981c0a2900_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:3db0646a772c0db975179fa2af73a5af298392b5ff60a9c9d27a51cb7fdd784e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:804360ab4e01f2b04dd9d261a73d8bba907179944c3f6b20b13bd5d20d4093e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:e93e8a927684a6b7fc90e7d304e638026605caf43a5326877ebc6e69a42759ba_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:19b0b859029870542a16b291635e70a02c04e420adec0f69b795f27c8b7cfce9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:6ca9683ec9960a2e9f0a26a876f4f8563314403118718a69fbfa944bd7b8482f_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:b568e17e33b8ff0ff1b5dbd57302a119067dbba931a4e5481660c2e8e2f2bbcc_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:c4b775cbe8eec55de2c163919c6008599e2aebe789ed93ada9a307e800e3f1e2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:1ca67a5fc95fc154745c6acdfdd872849478a4d9950fb53ae9f175f27d39dd88_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:45783e817eac8aa242d203dfaff9ed82792d69881eb4981b2edebbc0bf83ceb7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:56af6bbe9c2510f6ad29fb5beb5b0dc9d00dcfdf2b5a095e80386287b139ab22_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:eeea3ce92b26911c6defd0408d64c2b66c0733e4e1440920b8b885f643bda445_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:8b9821056e79cc0dabd4ca262cfebad717e4298f16151a24548eee19a7bece19_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:bbfd94fb7766e74d140cf7484de0c66dd3f8247a46f902fc41169869c0b71efb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:2ed2b8f8db21cc42dd84d151d39cbf83b0a91d03cf2f296188dc504ae13f1371_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:365de8f47bd3e79faaed6e60321ad4d329135a848b11419a9474b1feee31646d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:37d07b86194d322cb827779e3766876c817a98a1193240079733d7a5cd5860bf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:d37dc03f52323590058530cb4355ccc82c1dc68397532c8258f8a574b8684594_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:846aa1ae96f3708b4523df52ca110772eb90e75ad582e1aa6321776e9c5e05d9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:b18f5945f44d64fd45b9a15068cfb3bbd3e1cbc7fb87753ff3a8c44788970696_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +140 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:bc9835804046aa844c874d2cc37387ec95fe7e87d8ce96129fba78d465c932fa (For s390x architecture) The image digest is sha256:c26d48b04d8864fc20145204b543957824d1d86696c82efdd9738d096796326d (For ppc64le architecture) The image digest is sha256:2bf60fe7b0c72a301aa26544e3faabb61fe750e449ee130ee6945b588a727e67 (For aarch64 architecture) The image digest is sha256:f61d496a3b69582f0f1c54da973a58241b3e6001d8d1a696368d604b9ae774f2 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2023:3537
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://issues.redhat.com/browse/OCPBUGS-10527
- externalhttps://issues.redhat.com/browse/OCPBUGS-11530
- externalhttps://issues.redhat.com/browse/OCPBUGS-11851
- externalhttps://issues.redhat.com/browse/OCPBUGS-12918
- externalhttps://issues.redhat.com/browse/OCPBUGS-13011
- externalhttps://issues.redhat.com/browse/OCPBUGS-13168
- externalhttps://issues.redhat.com/browse/OCPBUGS-13399
- externalhttps://issues.redhat.com/browse/OCPBUGS-13727
- externalhttps://issues.redhat.com/browse/OCPBUGS-13735
- externalhttps://issues.redhat.com/browse/OCPBUGS-13749
- externalhttps://issues.redhat.com/browse/OCPBUGS-13765
- externalhttps://issues.redhat.com/browse/OCPBUGS-13811
- externalhttps://issues.redhat.com/browse/OCPBUGS-13964
- externalhttps://issues.redhat.com/browse/OCPBUGS-13967
- externalhttps://issues.redhat.com/browse/OCPBUGS-14000
- externalhttps://issues.redhat.com/browse/OCPBUGS-14085
- externalhttps://issues.redhat.com/browse/OCPBUGS-14098
- externalhttps://issues.redhat.com/browse/OCPBUGS-14135
- externalhttps://issues.redhat.com/browse/OCPBUGS-14165
- externalhttps://issues.redhat.com/browse/OCPBUGS-14171
- externalhttps://issues.redhat.com/browse/OCPBUGS-14173
- externalhttps://issues.redhat.com/browse/OCPBUGS-14195
- externalhttps://issues.redhat.com/browse/OCPBUGS-14249
- externalhttps://issues.redhat.com/browse/OCPBUGS-14258
- externalhttps://issues.redhat.com/browse/OCPBUGS-14315
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3537.json