Red Hat Security Advisory: OpenShift Container Platform 4.13.10 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:25e27b4ebf5584123de93bf738857d06c86fbdd1bf0d544466c26c7a2500e444_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:59fd4690f0b643f57676757630e4322a94ed1e09acd68bb64dc5c9d1852332fa_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:86dcafc2aca0a54eab27962a1f03e7d692e6015a47d9aa5c397d01c43740a183_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:bb034d69d0db0aaace3004e1a0165c7af97d2643ea7f055bfbb23fa82fa6c8d0_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:16098c68302abab985c5ea1bc28f6bb5fc78169d7be38c399fb7e03183bcde66_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:aaf906b32a0bd20a1c59422c47b24982db67da1191ec736f9dea679ff8d2f479_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:bdb1ba4beb6f6032155ff8c6ae592d97c95148b646f5a59f5665108b5def9362_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:f04368a12caf33c399b5d46bca2b179bb6e7183ac85842342dc899e578c032cb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:0784d31a06980b215d3cef27635182085ef4ad588e09fc0de3ede05e6fcb1b60_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:3ffad8abec6e4f1fc231301664364b9e3c289b8a1e3d88ae5c890913fa1146c6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:a744e594173b83039a13b71b24c7276e5c33c5c160f9ba8fe3912facd61b9f20_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:b4043947a960cadbca65248bd160ce4de01c381ec53d87021fdbfff5f7e29cd2_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:0be381620468646e987c6e05f8834cd87097ca35a0d534b2c72d19015eb3158f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:970da02b49c071ba070b9f46a3ad33a1ed6a16e8c68c71f8ec55954b280a977b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:c3bdd10f7737060d773cf44ae93d472eb45d6dbef7cc21bfdff92e6a605009b4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:d07c02d14d2a129f9a46f482b3ef6a7debc516d51095e9f08dab8e90beedffa3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:130d7c6a1959843a3e8196547429482639cfea04b733916a4b90937d52718443_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:18a943135079261276b5697e7797376a2fcd101f77b3e8ee3664275b215fbfd8_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:38e65422952319564a6b256bc53e768e03f5f542d913b4989e32f56f27b45c2e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:8761f111aeac860e31f413a43d2e8e99ed3be4f9c89ba8db047c9201a4600794_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:a8eab30c17fdf1b0a64e55e13a8770376d005d2b2635cf2ac53b2db9c59e3a40_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:1983c78649ef9c936dfb32c768157723097100d98d0cbc1279f22dac4a9ff059_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:57e4fe07aa04930a56f46426a7fccd2c3d2a91844a0c95c5e27bee3ea3c77ddd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:6a4c5b43c458adcdcb4cee4cafced6453300693459f0e487c2d93b90263eee36_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:87e89dd17776c248e90ec33e3a1eecfab85b4207788238958ba4d7cd8ac4b693_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:010be7e4a6a2d1a9e83b386b4b261d96acea6ee5265712e8f30c797955bad8f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a4a58bb0201d48e4dcfbc7c6f84d0a8bfb3d7dad8b659f9bfca2e87b6fd5f5f9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:b8b04b73de8f0a43751acf4bcd456cde9023b1f300a62d0fe56110f093c2b8bf_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d0ac3715fa6fa362bf4327a06285095578c2fc2e3bdae28277c378ba81e07a2a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:28173b4b6efe4f67f8753566e5f3c9831e454609b7f1888e4b6687907f4b7f24 (For s390x architecture) The image digest is sha256:28173b4b6efe4f67f8753566e5f3c9831e454609b7f1888e4b6687907f4b7f24 (For ppc64le architecture) The image digest is sha256:a52cb6235e043468cef505e4ce554743fb562d0d3240baf06c65e13c44201168 (For aarch64 architecture) The image digest is sha256:4aab4b205723d83e1ac383ee312ba95405523b7a9791174cd003dd6ac4e10628 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2023:4731
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://issues.redhat.com/browse/OCPBUGS-13075
- externalhttps://issues.redhat.com/browse/OCPBUGS-15897
- externalhttps://issues.redhat.com/browse/OCPBUGS-16013
- externalhttps://issues.redhat.com/browse/OCPBUGS-16640
- externalhttps://issues.redhat.com/browse/OCPBUGS-16772
- externalhttps://issues.redhat.com/browse/OCPBUGS-16777
- externalhttps://issues.redhat.com/browse/OCPBUGS-16804
- externalhttps://issues.redhat.com/browse/OCPBUGS-17158
- externalhttps://issues.redhat.com/browse/OCPBUGS-17187
- externalhttps://issues.redhat.com/browse/OCPBUGS-17365
- externalhttps://issues.redhat.com/browse/OCPBUGS-17453
- externalhttps://issues.redhat.com/browse/OCPBUGS-17557
- externalhttps://issues.redhat.com/browse/OCPBUGS-17559
- externalhttps://issues.redhat.com/browse/OCPBUGS-17728
- externalhttps://issues.redhat.com/browse/OCPBUGS-17733
- externalhttps://issues.redhat.com/browse/OCPBUGS-17769
- externalhttps://issues.redhat.com/browse/OCPBUGS-17791
- externalhttps://issues.redhat.com/browse/OCPBUGS-17837
- externalhttps://issues.redhat.com/browse/OCPBUGS-17910
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4731.json