Red Hat Security Advisory: OpenShift Container Platform 4.13.18 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:26dcbe829d899b9a44447c327f48987f45f8eec1fea43a71c0a11a66b30a1a37_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:6c02366c9fb06aa24fcafa97f66f35099bd8a7c80a6e1ec59035a88be1b9fd5c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:8875ec444265a8c7338c7829377c7eed7676b450cb2825a523cac32bc2a171b8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:a020614c27920ad9880e10c0bc558389182f84e0b55cf144a42f947961b8f2af_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:11f156e415077fceb100b659a1beee2bb819a7e80e26022d6df0e2ddb727021f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:af3fd5e6a0002e6533d92bded7bb33da633d3b1b30d875545685b287b39b0b5a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:da458c490218f5e1482ceeb40b0bfa524cf347128e3e66613353bba03b890c7a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:ddd5ae8159e9da453907ddc8cea4b984afde2028a4a52553aabd66104cd2e328_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:27a6118e14c5a83e39d916859945b5a84bb83522404904696946f44ad6977a66_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:2e4351145ce1d199647ee9ac36c5dbc72d87e66b7d9c3b7a38265edaf2f8dfb8_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:420b337875b50415a090ccfc4c040e9cc85f20ef517edd6f6ebbd26db52287eb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:b38a3e591a1f3a321f408610a97868d1dbba0ce3494da79897485cc67d70d269_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:4b9cd657512d54a0b7ae7b8d2d304a55307aede8b5edbfbdc947f108e6723f36_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:9164a7c997831df4292d6d31be1b69f08f78d7c9133caec5adf10265386329a2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:bd9e43d47e77fde8c2a5cd3a0fd5fe0aea34a7ee75ccd63499914ffe7e49ce14_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:eca55e61186531ba0bfa837257961cba9e328a490864db612aa97b788023121e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:643f10b40b9102997f1e6871f16fe073b4b91b41ff95475028db677e78d76b32_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cf9d5a65a3ff55ae35fcfc0476e85574c369e73de0dbdc037092925299888758_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cfe00fa37cb2eb4604b436b58ba85c5c32e30cb2486d743d959411a21f841e99_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:d04a94d55c3c2394f8425d0dcdb92aa70b4dccaadca82cec27b926545b3f6f19_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:ca34cb26c9a6f95196e87e5df0e1d585d709bf325462777166fc2646c7ce152e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:9b05a3e28d3a7d4d343e298fd902d10bda4861a11244b499d545d426b44b15d9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:a71541cf58dfc5b7de21a04b576e435fd811b1aa869313d1687eaba82a5af01f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:aea0a528d84325e25f35adebb3a24ce9fc6640468e271cf256cd88ab3aa3e057_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:be0d525a9ae4e0ecb6857857f7472817bffc9e6d2502c50cd4bcb494a38e77ee_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:37fe0b45509528dd14fa7c2e5c95a984ad34b3cc1d95191f732971a916a03437_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4f5f696c13e636289e6dd98c716a49efccfb8abf5029b5aacac868c387931d49_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a7cbdfe16fdc4d7b2d5a22ffcb34704d95b63bbe0433f2744bf967e39c19741d_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d96d106dc2bb9f085033d06700b646161f1c76164d2966fceef9f4c3895412b4_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:d0fd9d3ab8690605f816c879d74f4e6d6d9f72982f63a3e0ef3e027ecc512e1c (For s390x architecture) The image digest is sha256:4b1d9c837a6699e1901a44ab0af11bf6320a228c314c80a8a5ec0bc89c6c90e1 (For ppc64le architecture) The image digest is sha256:5cf20d5f38b5500c9dc6a57b4c3e17863fd9f4e8f8755fbb19728c90f6190f5a (For aarch64 architecture) The image digest is sha256:5cf20d5f38b5500c9dc6a57b4c3e17863fd9f4e8f8755fbb19728c90f6190f5a All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:5902
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-12-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://issues.redhat.com/browse/OCPBUGS-18253
- externalhttps://issues.redhat.com/browse/OCPBUGS-19307
- externalhttps://issues.redhat.com/browse/OCPBUGS-20047
- externalhttps://issues.redhat.com/browse/OCPBUGS-20488
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5902.json