Red Hat Security Advisory: OpenShift Container Platform 4.14.4 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:03932d541dee539548c0bc2601f91f53b2eeabba1268fc5f6fdcedc26ef5015a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:2c5ac1d45bf89efdadf484047dc6b1f122c1230b51659b05d58376807840cd39_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:3e46978802ed8eb08f2741cc84ea4c962c296f4b52580492dcb59337c493d275_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:43aacdc34b294e6809a9585c0a9a83046fb347421bd892972b3d26f72ad88082_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:18aa6691f5ba65f5fc5720f0eaf440aae5e09394031afcb2c85f70ba938af74f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:5ca60ed7f149c54e2fe51edfebea3ca370e415f73a9e1e86d0fd98d1b828c24f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:8a2ab6e7e27fb0a02bf08509fb74a2bb5bbdd0e32575a2ea413510847393372b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:fbfa89a0371e9ced944c4035c1d99a4a32c07a8223df468446e2b9a9a110a530_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:04cbcaea06f5abece296a7480bfb726e04e1939388729fce8631dee70ed2b113_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:1e9b1324a7755c8f76dacd873becdcafc62634283f5263677143927302075df7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:3daf8f04f1cec19db45f16f698c8b9dce21594aa6b379fc34e0fcb0630d8e56e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:527cb1b167ac713bcd776e18b25218fc8013605dca90c10bb00cf5d6573663e4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:153893c52cfcef4122538fad93786c7ca6eb95d99872d1eb112d441d725fb41e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:720c46acadde99242689f7420c9d0eb1383f8bef7b1c7df6ec0d0dce11a22ee6_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:b26e71e8d3bb3310ee3fa0ca0a2b6f0e7d4ded33ec21d70a7cd00e960ef1e57d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:bf84ef0927660c5373d754c09822d47bce0cccbfbaa2f8ec64e7e5c38d2cc36c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:164e0254f5ab703df95e0c712214d1820da016942edba9fa3b3ce4d73bb1c5cd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:530cf48911a03dfdcafddb3b664e5e3528f68c3ae8273bbc74c49dd95fc95ede_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:a68359748ebb010bd4fa903a85bb93fae43891669ee9723de60e00d3a0aa3bac_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:e5101f60af6e6edf6ae50d0af026e83215b7049d3bcce36ca30dd733b668eb99_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:13f950ddf39f39c7d492025bf20eb03e2b47acf8df834a9ef8e388a4c16e94a2_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:1e52aa2267c7bae2b1a816822a1542a484124269f70f05cdbf747321051a2a54_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:4b893843a5de4625c7495ae475c5f8db8c200389c16a2d2fc3304f56750fe7d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b08d29cd11439c1fad610d54170fe36bfb51cbf25d5fab0fe8c31460cdff2f71_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:1162693d096155f9b7658f891498fbd45f7ff1c9cb2c96a0e3d5ab476095810d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:7d9fc0e06cea3c00ce26828e84312ce8385bfed593f3efba0d48a0ca6ff89e4a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e4072714dcd16d4c3af17eea0653866613593a0e43108d0bc4cdbf2a3ac72ca4_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:eacad1428b340d87aaa401b920ce9db5b9c1ddf247d1b4468a00215f7853e540_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1113433882ffc39221e3deb074fa1c83160a1286eac42aea44f91c42955dee77_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e6e1d90b492d50438034e6edb46bdafa6c86ae3b80ef3328685912d89681fdee (For s390x architecture) The image digest is sha256:240caa73646c1ff4ee044bf0d885efaffd27eb3932a2aa299031a1f5f94216a9 (For ppc64le architecture) The image digest is sha256:16a57a40e0d10fd4b53da7de6a8cfdf793af3181f656b65471d989800f6d833b (For aarch64 architecture) The image digest is sha256:c04f00535968e6007f8403c7d279c272c0211695008f889fefb74e47a7f9222f All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2023:7470
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://issues.redhat.com/browse/OCPBUGS-19678
- externalhttps://issues.redhat.com/browse/OCPBUGS-21761
- externalhttps://issues.redhat.com/browse/OCPBUGS-21868
- externalhttps://issues.redhat.com/browse/OCPBUGS-22688
- externalhttps://issues.redhat.com/browse/OCPBUGS-22774
- externalhttps://issues.redhat.com/browse/OCPBUGS-22996
- externalhttps://issues.redhat.com/browse/OCPBUGS-23150
- externalhttps://issues.redhat.com/browse/OCPBUGS-23210
- externalhttps://issues.redhat.com/browse/OCPBUGS-23212
- externalhttps://issues.redhat.com/browse/OCPBUGS-23315
- externalhttps://issues.redhat.com/browse/OCPBUGS-23392
- externalhttps://issues.redhat.com/browse/OCPBUGS-23393
- externalhttps://issues.redhat.com/browse/OCPBUGS-23408
- externalhttps://issues.redhat.com/browse/OCPBUGS-23423
- externalhttps://issues.redhat.com/browse/OCPBUGS-23450
- externalhttps://issues.redhat.com/browse/OCPBUGS-23505
- externalhttps://issues.redhat.com/browse/OCPBUGS-23508
- externalhttps://issues.redhat.com/browse/OCPBUGS-283
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7470.json