Red Hat Security Advisory: Red Hat OpenShift Enterprise security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:320c76c52150a7c9a521f3fbee87e1a16293a63274a7246acb69831f54d93534_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:6900f4c8ca5c3ee1190f423e47e676e704178da1de955c5204bdba6c7b80322d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:ba9f88e9b305c6bbf1fadf76d4d3e7814921a06764b75b24236f725c1bf33a28_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:e51399c870d68b27ecc53a35bcd5136062dc5285caa0114c553fb99cd3b90277_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:a9c047d6ae8fc29685ad8b6c3e8ca6af795f6cfff9bb1a7bbc5f0269604ce4dc_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:e282aa9e9dc91493d0e0988ee8888485d640b7a956e7076fab2289b16d3ce33f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:e4574135e363372544a647a76fead73f4d1e28588f52454f7ec65503142e6df2_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:1449fbf348fee87b194c309b79b1d6f0d78311e2df518fc2f94bf5e303e57987_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:2248d8cc348b43e791c8f40113a1fdf024e30389be11361b185908e60cbabd99_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:5c5b4de8d522d388699013dc682c0f6b9618fd4cbce8925986b3070848c4fe9c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:6f99acbcff79405aa04bb51bd0c47650c204490979abdba735979b74d046f477_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpu-network-rhel8-operator@sha256:1e0e9c03c4c0b71e3734e5dad6010b8fb46c764146465dfd2fa8eb0d7a3aa5d8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpu-network-rhel8-operator@sha256:c70cdf2bb542b49ee2b62d2471d55e9bd5721c97b6d8af2acab2483d44ac1f0f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:40472ea3a6469d202add51fffb8868d0024ec85aaecf988b3dea190db540ded5_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:b9c98919d9926a47d89631788718b4d21985a03535a19ea915d4c62daab770ef_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:e1f5034ff062537afa7805fc0bf8d40981dce89595ff3c923c380c3ca77678c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:e280217aadb71060cb66f22a84d3ae89f240498c91ec7469eff8d8f67d803ed6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:4ac6e3b98c6812c24f7dbd29c6b629f877377a71e11aa5c2bc8416f9d6d6363f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:4ebd0bdc34a0d6ee6949ae433717c259d1a5e8505e59c470d8d9d49ab9bc5f9f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:876e7387c7a971eb1d5ed658fd99660c1a0d7f78b8df1379cb490012ed9f8d03_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:8f7d9f6a6bf2efc97bb254352a639c64a1494c56125fc4c9eb126bf2d65c64d5_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:1fc4c48774802c837c6ae160b1e489d0413a6c58d28e11402d5e83811eb4ed89_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:39c74b166e8b44bf05bcb1f55d2cb7440259e66945e9e9cf8528fd22e39ec2fb_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:9dcce8bc61c2a28b551f9091ffc16b65a8c573f9491641416532ca078459f743_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:fefb21aed145cf4032ac9cba13b7ff489ae76d65656f24a9b69797719c5a3b1b_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:2c49f3aa826c06c07d2f93c5da269f834114f2c4705e535cc0d320cbf692d13d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:829cccb57dbd0980aa285e45c27c9854f39dfdf5d7b8dc5601f2d4714c952470_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:ac991ececd24ac2c4e50551fe509e345d9991da4dfaa2143bdfb3850e9d5b065_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:f2ada7e231e840f0973b241f022bbcd5ae3337ffb05acf97e1e6539b221587b3_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:2309578b68c5666dad62aed696f1f9d778ae1a089ee461060ba7b9514b7ca417 (For s390x architecture) The image digest is sha256:571f9da5ab8ad0291a5fa822bd7b2803d5bf53096b140407ac442acf9dde4a99 (For ppc64le architecture) The image digest is sha256:9470deef9f3220fa1c05b555f5e10f448d2888e60f40a8e2073424dc6e672fd1 (For aarch64 architecture) The image digest is sha256:d9998b576ab98dcfd9024927572f698c0f40bf7fe4f8eff287f41ab4fa5e9c93 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2023:3925
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://issues.redhat.com/browse/OCPBUGS-10386
- externalhttps://issues.redhat.com/browse/OCPBUGS-11199
- externalhttps://issues.redhat.com/browse/OCPBUGS-11303
- externalhttps://issues.redhat.com/browse/OCPBUGS-13778
- externalhttps://issues.redhat.com/browse/OCPBUGS-13891
- externalhttps://issues.redhat.com/browse/OCPBUGS-13940
- externalhttps://issues.redhat.com/browse/OCPBUGS-14041
- externalhttps://issues.redhat.com/browse/OCPBUGS-14190
- externalhttps://issues.redhat.com/browse/OCPBUGS-14652
- externalhttps://issues.redhat.com/browse/OCPBUGS-14664
- externalhttps://issues.redhat.com/browse/OCPBUGS-14803
- externalhttps://issues.redhat.com/browse/OCPBUGS-14873
- externalhttps://issues.redhat.com/browse/OCPBUGS-14958
- externalhttps://issues.redhat.com/browse/OCPBUGS-15099
- externalhttps://issues.redhat.com/browse/OCPBUGS-15198
- externalhttps://issues.redhat.com/browse/OCPBUGS-15269
- externalhttps://issues.redhat.com/browse/OCPBUGS-15309
- externalhttps://issues.redhat.com/browse/OCPBUGS-15315
- externalhttps://issues.redhat.com/browse/OCPBUGS-15377
- externalhttps://issues.redhat.com/browse/OCPBUGS-15414
- externalhttps://issues.redhat.com/browse/OCPBUGS-15424
- externalhttps://issues.redhat.com/browse/OCPBUGS-15429
- externalhttps://issues.redhat.com/browse/OCPBUGS-15459
- externalhttps://issues.redhat.com/browse/OCPBUGS-15482
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3925.json