Red Hat Security Advisory: OpenShift Container Platform 4.13.22 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:0350fd481fba885ef4d5e24666ab85f6d0949afcdb588e635a0f6e8ca7dda78d_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:38783af9ee72eb09b0de06343e09e8257bd8c00bcf7bf459460dca360df879e8_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:9c27d0eb50c00575469f36956db89f320ceda5cd9387791290fba69193bcbdcf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:a4c9a7cd2607935219d3e661c23b739b4cafdbc9e67acfd0d51c7a4d04418dc1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:20792125361ef94f744e52bc7470368b66a9a2fb3599d8c3e3be27202d7ae4ea_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:4eb771bc942cb3475c5f6899087296a89688477e199516011bb63f4a2e8a78d7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:91b5b395e96c2e6829707940fc7e5b8116f9b4fbc2e911a7b1cb99aa11ed3e00_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:c060636db6dd69cfdbe897b2238642d60c3196d950c43c6a6d35b922ee683be9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:3d4ba4c3b7921dc7476ed2ee5e11bb172ff1a922cc23f31aff94002520a9aa4b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:94404207ff932467f8070bb0058be2167872c8898171278e13e792a9cb184092_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:d0d42eaee03103d8f8e48ec079ba21757a986a68ab291e2fc52970448be95e37_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:e42836d96d009d93c4e47c1b4b9edf732d9c14854a376aaead1c65506d65575f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:26840cc475f495ed8ce956fb774dfb33399a22ad3ddc0aac32ddc918cd5b6973_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:5003e3c6e7d851c4906dcddd5e975ff1d755923b9e87f29bfcd10ac8bd5e20dc_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:7d5ac437e013700fc44f943a45d545e9897d077ac4e56ab010bd26f509b8b9d9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:f1ea2bb091a1c3bce0c712eca4817bffd94e7dd4afa16f753a7f2bae6f52fc88_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:4b4edb3b8473dfa05703ed5717a1054787223a6ab8cf2e54a287f32cacfb9cbd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:5f11b7dbc378d3ff00b0617827a03c4e7ff293a9b987b676086625139ea1f27d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:8e41c1f2c6746f00a29669097b0fa234802354f03cc551d2803d881d9c6093a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:a661bf78a225da509f77fa7ce3a6cebe98f05e5193e693569a22aeafe3888b79_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:f4f12517a08d5898db74db5b2f168fad5f215c0a10469fe50506de1b63dda695_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:34b402ace71901b880827ad5f6cc9e711930fd3bf1c01d8ab1800e397f407cc4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:4e8c9630aa4a4f246773a686174757340739733c618d63c5b3c90e2e9eec0160_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:87a237bac446e50fdcc89fbfa59b3142313c1b785f26f4ceac8e5915c5251a59_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:e77b666b0546f196cd186739b20237017efdaf98870ffc7c0f4f31ce6ef6c6c7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:18789d04db2757704442c0073007d3f036fe3dbbe5bfe459266a7559b27cc4a3_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3893c1778f8b2b8471690a73a23a2253ea99afeb0eb84f9ccae22b475a8a921e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4f4f73da86d9b2c04fae8931681de10f4b47341f997282ab65f4a7dfa460349a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a79750273a3b0e1dfcbc4bbd738df208d4e6d51de009fe811a41dc9fd18359d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:f323afe3e80d44da7d0caaed8c353fedef37e5fd5e7f765e8440be86f546cba0 (For s390x architecture) The image digest is sha256:5b9d3c2516d33940271de3a48777889f186a9d7a5404d2fcd0d7ca94821d13c6 (For ppc64le architecture) The image digest is sha256:6991d5bc9a4b1e40b7f9f8df5d2527aed63d247cf9c08ec740011028a98f691b (For aarch64 architecture) The image digest is sha256:0553defae52c1674415dd8e26bbd9bd011b2b15e643cacc125d4f4b0b532de7e All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2023:6846
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-14551
- externalhttps://issues.redhat.com/browse/OCPBUGS-18143
- externalhttps://issues.redhat.com/browse/OCPBUGS-20278
- externalhttps://issues.redhat.com/browse/OCPBUGS-20365
- externalhttps://issues.redhat.com/browse/OCPBUGS-22205
- externalhttps://issues.redhat.com/browse/OCPBUGS-22210
- externalhttps://issues.redhat.com/browse/OCPBUGS-22870
- externalhttps://issues.redhat.com/browse/OCPBUGS-22914
- externalhttps://issues.redhat.com/browse/OCPBUGS-22932
- externalhttps://issues.redhat.com/browse/OCPBUGS-23021
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6846.json