Red Hat Security Advisory: OpenShift Container Platform 4.13.6 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-25173 — containerd: Supplementary groups are not set up properly
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:5b3bf4a5cfe22334599f097d6fde60d0fe47705d23c8f3df1ffade79214a75d7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:6f919097747367e3c94fba66cd57d66544f7ff950708e0a04de1064f7f473a9f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:f174b2ce2e716ecf4fb4401a884da87eb9b6dedaa7da054585d3c99b1f8c00ba_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:f2e0fcde8abda18f6d4db48a97db4558c6a1983fe3309959860cb810a3ba400e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:3918239dd7357f2e5926900133ba277fcb35f58d563aea70dd92644063d5bb14_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:7be892989c14810a3d3830ee07862f626fd4791bb6b01da81747427a63009c2b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:87d74ebae10438bb7f3e192079053d32097e836ef49be57188b35f6d2fc7a1c0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:c1015308347bb6236dc5ab989e9510417d7027619fee55ef05bfbc4c82bd4db7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:681ef93c89ae19b4a5b6a8af323d2115c840beae9c089cb500894da62b978c25_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:6d67f697e2d96cd2a974714baa137f2b6dab7558559c1b07ba25587a308c1104_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:b86b9f8277a4bf2165a38cb03a0b39e81e1d87541dc17254a85c779be95caaec_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:f5828b56670cda8b039a870da9cdc876c3db83991495c25f5d6fff55b31180df_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:13181c2d8fc922e1d38abb0aa6252d21cd937ccdf9c70cdb13b100568febeb40_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:36daf782cbc03c6b95ace166f600eb41342b9e156afb5bac0bb4bd22196cc17c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:5f44a0944deaece99d450093e46e8903ccd8b81dbdb22428e7ad9740e52e300e_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:b586981ebaf0209f654880bdd3794cf26af3ba68065fef727700593fe90c7c2f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:679fbf51acacf8d1d9378b4f8c39766bdfb9a90f956316a79c5e4a33fc7c7085_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:76c4cfd7b2f0568c2e422921989eabe488b2fe49e58e1f4a93ca75e13fddcf31_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:86a3985e83477c5c3f4030204a68288e3b8a9fd63d3442ffca423614ab21af59_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:d5e7e1b51f0bb66a2206415a74437faa5e28fb2aeaa76a400405d5508d294c58_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:554448c83678da9a6d664e54557312d4e8ad1cc92dac86f8ad8e2f3ce083dda2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:b0a795c4fb425ad575ab61cf4ffe470d273894b5b9012b56eb414a4d96283ad2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:c95c4ee0441e551bd05d775998e254f77726939908e01aa66dc1b4b01864e5fb_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:e9cd8ae38eac2617822144409a5a36dcc1ae1f3e9c8bb10e0295b7f44405eacb_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:f40fbd8c5a0681167270416905efccb8871a90476e2b75b4c13b9b289b4e4c4d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:39c19109b4cb1593c307e2fdd6d7fe81b3c9d5838a921f3c7f965116f74d93ca_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3e165f8e775be73b634b2ebaef8643e528ba01b47e56e81082dd3e7c07665ac6_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3ff54c2f5cc60083ed2c1378cb96a59550dc96bb50dd86c0d20af9794858af86_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a156da2f3ed7868046f260d04ca0eeb113461202fbe16910ccddff2941509269_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:3ca57045e070978b38c36d4c98e188795a6cb4b128130f9c8d7a08b47c133aba (For s390x architecture) The image digest is sha256:f4c42c45cbb85db643e72149d08719896f2c1b70707dde062ef570b4c2bbf6eb (For ppc64le architecture) The image digest is sha256:f219f4a01c3f8c8a15026d80c6cb606775cf53a86673fdb0e0cb5f46a111a105 (For aarch64 architecture) The image digest is sha256:4c5ec89db787852cd4118e1f3533e214878ba4335b436f7073296e6955058d1a All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2023:4226
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://issues.redhat.com/browse/OCPBUGS-11539
- externalhttps://issues.redhat.com/browse/OCPBUGS-15194
- externalhttps://issues.redhat.com/browse/OCPBUGS-15368
- externalhttps://issues.redhat.com/browse/OCPBUGS-15378
- externalhttps://issues.redhat.com/browse/OCPBUGS-15982
- externalhttps://issues.redhat.com/browse/OCPBUGS-16171
- externalhttps://issues.redhat.com/browse/OCPBUGS-16172
- externalhttps://issues.redhat.com/browse/OCPBUGS-16244
- externalhttps://issues.redhat.com/browse/OCPBUGS-16372
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4226.json