Red Hat Security Advisory: OpenShift Container Platform 4.13.19 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-5408 — OpenShift: modification of node role labels CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:45918cf67a88cefb1c0bb5877ff2c43fb2786428f213b0a2ca4fa662553b5191_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:6a3252a941df86c2a9282c036c4be713059705911d357c201b66a0d27b65695d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:ad3902aaee2de7271d8a95d8849b4fe32d2910a771f1d62c687ac17bef10d038_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:d3aa78557c1751f6c03d66bd410343588d5260d0fd0b171f2e2f7599a6884a2f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:1198b596958acf09324e5b17f054458136c4e695a3143f2992affa42bb2a216e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:2a5a4e8ea4ea8b9add9ec7faeac6aa6417616ad653518cbcb67722d0b9fd89f7_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:f4f0e65b6c61fd9fc5cb5166579ef047d911844fdffef97b0fece3f1bfe97905_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:fa9eb4e1c6a645cf118dfd46858bea14dad798c7b443c1beb3a6860c8faacd7f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:1fd923729931a5e825fcf81a2ec0f39d7cc0517afa11ac6f50b9e5fde78c695c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:5d93e7bbd34b04f54e5ef536b0ad539d48a93cc876c98a88543de980ff3c176f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:906445bcf3796cf04a30ccf8ea4c2c28f8b891919c6470cf486c21c78675ab19_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:b17a397e23567e9fe7ee22826f20449aeffc527e3da386c5f2b28150d4aead15_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:1b04aa85f157a96fab3b9240f1e8ce93ce05a12014c95dc0d46cc585d5412731_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:2defc2c20a714a4d587a4d1b35f97d41c5e1ae1e4282d475fb651aa51ab938d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:5963e84cb581f1028bbd615effd0b5abf0f63135a20e63318d07cca78567dd7f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:ca4b713dfb2255138f3bcd063b1c60cc957322cfd191f5d883ba844a98247b34_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:2584ff6db8e331692c9163e31507d08e99763a504889cd1b385e42bed0d67659_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:644892aabe16ee45ed952864a3464115ee4b2485a1066b9e57c493d8a77aeb72_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:7e65922f2cc70c1c9f4405326f2e485f777d7c4d620cd1955b9b084dc768a2df_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:f6ef43cd488a3574d34f3c8c220f1933702c2b192611684f09b4800b8fd9da48_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:9fceba393aafb422b5eb005844161302602bb9f72bd86b57b616fd4274bea4d0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:bba2fa669e77c90ab369b7ffb708ec0b5c72781c775d4c4fc77e549183ec7aab_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:dd2f3a89807ce21295e469a1265dd1b79802813773077cb0a5809d45f50bf753_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:f161cce651452c36d617eef0af41b217eedcb55d3717b1d20b34a809104ef495_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:ff72e2146ccf6d3d9eca146a18c0b4b9b8f69e6ed096f0a533c057b80f74f63c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:042248d2950dab0cb12163bfa021ce5c980b828feeb33080eec24accd5fb8adc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0529e808700e16e070cdd0f8cc3dd7c570b56484b9e7a111d9b28af83db74f6c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:bc9f5f8af32137a27e56ea04f31cc49050f4ed1d3aa2f40cb70f0f2b29d54026_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:cc2c1d3cee345e4c29f8a358fe53459a9e82b5109effcea80ac6abd5b2529dd9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:f8ba6f54eae419aba17926417d950ae18e06021beae9d7947a8b8243ad48353a (For s390x architecture) The image digest is sha256:bd5308c33c3074a837fc1629bcfdbd9bff4a0d9a0256a9e193a78fa14b6f68bb (For ppc64le architecture) The image digest is sha256:81dd6026306b18d8b1ac57b079422e7de992a438d41d6a6a744e630387308ee5 (For aarch64 architecture) The image digest is sha256:4a7a79b8b6fb8b86ea37396c1b40063d3fceeb0ba98c4350e11f522ef81edb41 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2023:6130
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242173
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-14314
- externalhttps://issues.redhat.com/browse/OCPBUGS-14504
- externalhttps://issues.redhat.com/browse/OCPBUGS-15231
- externalhttps://issues.redhat.com/browse/OCPBUGS-18271
- externalhttps://issues.redhat.com/browse/OCPBUGS-19378
- externalhttps://issues.redhat.com/browse/OCPBUGS-19472
- externalhttps://issues.redhat.com/browse/OCPBUGS-19532
- externalhttps://issues.redhat.com/browse/OCPBUGS-20069
- externalhttps://issues.redhat.com/browse/OCPBUGS-21721
- externalhttps://issues.redhat.com/browse/OCPBUGS-22099
- externalhttps://issues.redhat.com/browse/OCPBUGS-22330
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6130.json