Red Hat Security Advisory: OpenShift Container Platform 4.13.23 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-30551 — rekor: compressed archives can result in OOM conditions CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products183
- Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:0b8e808f7af34ddc4836fcd94da086c6d4a67f517267a3537669f4a640e1e41b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:2bbf4bdeccf26689c4ac51a3a609c00aff3ad1da05939204a7ab8b60004e61b2_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:9437ccf659c1a99594a0d5321aa2f6a230c15066b6e04efed60380a163646c6d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:b3f3970ddf34ae51560504850eea2f0b06a821bd2d1ab6ed161697464efc34e5_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:520b3b787a38cdc8610e040e38c56e82956524dc363844a0f43f8d14af1b82bc_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:82b8f30aaa3850d6f2633a2ec602b998edb11c1c88a2e484cf6460c887c3ae88_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:888f5c3e01a594c3f72c1b32736e78b976f5cfccd9be5447b9137d9d23e8258d_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cdc3eb6349e09e46ab151dd030718113dcf87417bb365ab543de40bcd02eea52_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1820743a5acb540f1a40fcdeaf5e52abe0ac736a0d207a72d9151766a2fddbc8_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:31d5312c00eaaaeabb0b7315a6e27ca18c111b9463e7d33533551c4364c62d63_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8b8a8fdb394931585793c899f2eff684dc6ac838e267b6e7cf8d4ca4f55ac337_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8c614deb7d728538c75c9d0ad4583045dcedd0cc8cd1b66706b76c31bac8f54f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:0b0d2db9054af3971640e8a015a84c0716839e4304c3e677ef43e7fff2b99ab4_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:9d40243e5bdf2fda691e0d2b0ec1e9bd84ec0197f8d98a3cf20a0f31f8809b32_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:bc5d4a8b34d4f202f1992929de2619c2f5c5a8dfea08fca3faae5ea1f2e20ec9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:c06c44066614f92b6349ab3258f73cce42cf323d12af748f626bfcc7ace76ff1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:2c0340a78153869d9bfbb5a7c1361dce3e2f3b930d3edec2a939a3883b7d169a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:a8a72f83d1e2ffaa610cdfd9036bdc0f6f87890efca62056eb56945f05ec5e6e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:4bc774fc1abbcec636e74858107431fa3014a0fc38ceb5fc0410214ab213501f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:9bb248e159c2c1c1ae06ab5bb28b4eaf6e07af12359af6633fd7edf500fc46b7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:0b9d97e86798bd4a674ca9e4134517688935f4443c06fbce41c7a00aa91d2cf8_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:202e5d09b1d12be482c2453b30d731390f956486e1761e59b922164b02d53bc7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:267852cf4e78ac9659421f0ea65d75b2b7f5fef6a14b6c06b71a120a7f15a637_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:f1429981147b0daf1573cbde9fa468403eea0c26cce5d24d011b3b2a8555a475_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:3d3328e201c9d24fccb3620085a276b80d6fa320741fd9aa73769b17ee6008ae_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:3d86afb646d5c03d35c8bdfcfcf3132488f25885aefd471966c38d25a3fd2f49_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:a9222516d280e07dab0b3d58239353e2378ab812c2ca2b6e3707c0a65acd3999_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:abff00ce8b86b3252cf2287e6422c4247b232a5b00b94141a26cf1dd305bc964_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cli-artifacts@sha256:43974424f0dbd0208a78b9fb42ae3d46306eb31461b485176a88276f4804b547_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +153 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:ca556d3494d08765c90481f15dd965995371168ea7ee7a551000bed4481931c8 (For s390x architecture) The image digest is sha256:77dde49307e9fd00cca6a152f4629039f00ac8c2a729811decb007c4fce73ddb (For ppc64le architecture) The image digest is sha256:10c619d4139ee72c7e3a9007b0d5bcca1517f86a14c7e6e5e74cfcf977f2ada6 (For aarch64 architecture) The image digest is sha256:b2e0ff69918b845d1a1a6c503b764facbfb34afffc64b5dcfb798a385a8f4af5 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2023:7323
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-19078
- externalhttps://issues.redhat.com/browse/OCPBUGS-22815
- externalhttps://issues.redhat.com/browse/OCPBUGS-22920
- externalhttps://issues.redhat.com/browse/OCPBUGS-22939
- externalhttps://issues.redhat.com/browse/OCPBUGS-22953
- externalhttps://issues.redhat.com/browse/OCPBUGS-23044
- externalhttps://issues.redhat.com/browse/OCPBUGS-23065
- externalhttps://issues.redhat.com/browse/OCPBUGS-23072
- externalhttps://issues.redhat.com/browse/OCPBUGS-23116
- externalhttps://issues.redhat.com/browse/OCPBUGS-23141
- externalhttps://issues.redhat.com/browse/OCPBUGS-23160
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7323.json