Red Hat Security Advisory: OpenShift Container Platform 4.14.5 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp
🎯 Affected products84
- Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:013fca7b4f09a62f7353588918cef344aa8c4b2e77fb27d22ccbc76411f1aa7a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:09a499d3f73ddd66a061b33e6e4d36dea1e4e039dfdf7782ecca699d281de4c8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:3dc0ac6a3702bc31d58a44f756f55b2cfddb8211f160c12cbd0df3d38f921ba4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:4fafc151367baa64d1eb2cbd94ff9a52adda52094db61fc255cd5e57fd982728_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:34e81e6a9b748ec469c331f736ddcc023ec1bb5138a6123aabb25c51426e3d90_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:8ee7aca747e153a02a3971b0ec106e8fc80ca03a7af89fd63a6578cb43a1edd6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:9b07081f827510aac25f1d537a67feb3d9fb0800174bc4de377fd77cbf613816_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:d6be41b385861a76e83fd7230669f64a6bd32c311da2c4a6d078fefdb66856de_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:462518abb5ec916e4f4f9f6ae1c9c047308369e12d79fe814a1d02c6c4d689eb_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:61dc42691c1e0774687b0264e8a5e280080f3affd45f3de8024150f132e42436_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:9fb7c83d8bde3113b9139cd47e3f8684bcb5a635d4d23db12c52027e7cc0369c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:d48367eb54bd3a95eaf44ace2de093d14d8830dbb59e41447d6f77991c730f8e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:501a79e25d3b708604a3fcb00ea55cf7081b8e6a813ce7ac49a2b6cc7dcfac69_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:6e095c7bbae537d0c50b56e851216a43ba6e754f5a1281f7ca911e697e23e000_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:8273c7f6bb7455bde86ccec0b12375132295ab11f4a5e6649c9f267005d6afe7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:c397243c3953c4e2098d7b66042dc942755e6552b45b443da5a15c10d02efc4c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:a88ee00b1219561954406cb26c49fbc6d1fc0cd57b3b27741090b8512b25a9d1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:95c277eb37b6e5a6af98f03ef5a849d782de5486c7f9fc8592f1feb03a98096a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:fc143afd94fb37d10ef56f8e486ac20f925726071b3e5a9221f8adecf3eecf2a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:1cccbc92c83dd170dea8cb72a09e96facba21f3fdf5e3dd3f3009796c481cd67_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:60c347a61c0f9b5388bde25256c6b3146b20686598856ed6fa72b97d42e2c0b1_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:e6ef5ce6093e298107a4213cec7433ec0bffe1ef4392b136c3c898ee4f936984_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:f10ba3fb28c5d070f6944f68c6f37706df9af1880d6e6ee94f5abcf493fa2092_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:0bffe67ca6a6de7dc83fe2cdf467e8710d0f747a247ae2e70b150a42202a84f5_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:43a88c3c2db573ff7fe0dfcaf96318913a050a6ae3725632339f60a95b14d253_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:7330b82d15b7025e2c3a3cada22382e3588ba13f34b6d78f676785da3549b023_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:785f5c3b99a91afc319e1dba8eeb605a0f410202e3451c9db0c3a4bc117ab195_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:3d4484b32bd14c03d042eba002731852ff937cd63fab7c990316179836f0af9f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:534330c1f08638dff21532f75742004c916e261fc7f736bad9e00b16af0bf2d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +54 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:0ec9d715c717b2a592d07dd83860013613529fae69bc9eecb4b2d4ace679f6f3 (For s390x architecture) The image digest is sha256:068a5641d0180d70d48535d01305fb3c3701ca137be08cffa886694ef515ffa9 (For ppc64le architecture) The image digest is sha256:6f7faaaeedc96b6e262e0d67fe2147022369104eb5a239bb39fb56f2e844d86d (For aarch64 architecture) The image digest is sha256:e602f9df03cda6f7a8fd76f21f0d87eac6a5310a6f6dda1b1d70e803191ad482 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2023:7599
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://issues.redhat.com/browse/OCPBUGS-10126
- externalhttps://issues.redhat.com/browse/OCPBUGS-22286
- externalhttps://issues.redhat.com/browse/OCPBUGS-22363
- externalhttps://issues.redhat.com/browse/OCPBUGS-22430
- externalhttps://issues.redhat.com/browse/OCPBUGS-23426
- externalhttps://issues.redhat.com/browse/OCPBUGS-23490
- externalhttps://issues.redhat.com/browse/OCPBUGS-23751
- externalhttps://issues.redhat.com/browse/OCPBUGS-23906
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7599.json