Red Hat Security Advisory: OpenShift Container Platform 4.12.43 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-5408 — OpenShift: modification of node role labels CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:0188d585df1e84fc01882f2c8332be6835119075c78f269c09abaf0277571eea_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:14f2411eafb51a36c96f36faa11a0e46fc1de69c8bee89ac73cc57da626d785b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:712162a3ae4681bcb392def36da536b265e187f8bd9e673189a0e90c2cab0469_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:d4f191ba4fc18b1f1944dc4532614bddeb55948837e863394c7e5ee6c5e46059_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:3e9d2df901d8acbc349d8fb1ddb04d8f5e6647be0de0ee2c15f8926adc05c600_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:478cc2febdb56fa5a2d6c534ee2387f08c7d512f4da9d2cd89f1299d1fcb6261_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:65f600160f52e78d252b2736613e00c0bc424e7bd02cd19d48733087ff5a7761_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:a2ca40c5cbacab384460f5d4a2635e696a1491126646ba7ea5c77fd8826ec8aa_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:090da707f9b5375205fda45b8e22c199c1ff6e32edd3f0b192ad309f2599b955_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:0b5eec91ad98521975c537cf7d3687a69b64bd48f42a6f3727f0b630e8cdbaf9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:6b1d84982b392df69713cd04bfcd9ece04361781f17f5fc0bb86a359ee7347da_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:6d61b5bbff3b6e84de10caf3257d509ca8a593e835be476f87b3290a1ab1de4b_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:1d06aee31dbed4177c1b0d77dadf6ecfde90006524ba0e481b75208701df907e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:aa0e56dd3c39f67650922b94a0592291b225544c4c0be84efbd9cbff13d1df12_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:b0f05ebf2b6e55836a4ed2e17c3d1229fc563bec64153faf28100b33ae4f536b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:f97d6f521c6c3d121eb08f8daead6d4cfac3fee3541c673745487f845a8606ef_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:7e8c49d5a3b759e539e856d8ee3fdecb5be9b192df20cf17ac904cecd362bc57_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:ab28b755f376fd564d96f1fb93b04dff768b8f0cd23268e7f9ea2a21b739972c_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:ced616f6723f6a8c4a01bc977a713e1603ab33aa9e71516aaf04eb38b8a579f1_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:f85336a603caae25f8ad921247c0276a54d64a8040948b34a4e812bfe65e74ab_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:4710da52f14308ec00bee18e9d9c5c89b992bb7e9bcddc31d537798892d266c2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:2d368e56570e470ab1fbc0e95efec33bb7a6597c38f11bb27433d5c0656b01eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:31990b929946fb6426b02e5551477495d73ee0beea8b12c9c3e814919b7e0198_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:768f868fb1f13573ae40cfa25aec057f70168a1651bf84a0ead4b0fbcd2968fa_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:bc621b013b14b6e486a25f751446f8d802a6865e3d108580942ceb33d820ed85_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0c6b6ed1ab3c12f9ff83f5f0a61ca32fffc253b1b5e87c89a9fe407300cc8280_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4936f80c9ab8d91410bc623bf7a394abcf6d77d0300246507f985cc20b2392c9_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:b945319ff3d8542c4136c3850b963ce2feffa2a6dfba4ee9e91fcfc77e4e07c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f6d552d7d514bc06f8c614a30afb9461fbb950c9101569e5fdaaead87aa91332_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:10221b3f8f23fe625f3aab8f1e3297eaa340efc64fb5eff8d46cc8461888804e (For s390x architecture) The image digest is sha256:7945851ce4341404565c87bb450a95a334d46348688bcfdb720a3645a4e3c993 (For ppc64le architecture) The image digest is sha256:0d42da717df4fc371ee286b39922951f287a9947542be1d485099f3c0e5a7637 (For aarch64 architecture) The image digest is sha256:f7ef41ef23d923af26e277baecef9e496a61ce07b367fec1e9da3e5384e60eee All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2023:6842
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242173
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-18951
- externalhttps://issues.redhat.com/browse/OCPBUGS-19382
- externalhttps://issues.redhat.com/browse/OCPBUGS-20071
- externalhttps://issues.redhat.com/browse/OCPBUGS-20583
- externalhttps://issues.redhat.com/browse/OCPBUGS-22408
- externalhttps://issues.redhat.com/browse/OCPBUGS-22461
- externalhttps://issues.redhat.com/browse/OCPBUGS-22719
- externalhttps://issues.redhat.com/browse/OCPBUGS-22843
- externalhttps://issues.redhat.com/browse/OCPBUGS-23037
- externalhttps://issues.redhat.com/browse/OCPBUGS-7768
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6842.json