Red Hat Security Advisory: OpenShift Container Platform 4.14.6 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp
🎯 Affected products113
- Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:7995434245b12a7535468f85a48f835c09d828046db573ff963502cd1409c7b4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:7af5b14af91f06bb820da68e3699c0ab88e6040a43964b22e37790b1c1d5d7cb_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:83dbe9eff6ae910d1868f8dc1b3651d49204ea57529f534a3f0873144b5bef87_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:8de7b26d4eb9a5e9aa0ba058735d3798591c929807816bc6af4aa91680fb4c46_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a0db9a817e589c8d47786d364707c39daed68f68c1114c7543fd6f4d00aa2385_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:ade18f2994669ebeb870b3b545f8b48574da9fc26ea24341dd1c16faac9994a0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e7e511a5446948ca0103951e41307c47417298d606247bc81abca1aced0b2ff5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f28f3822cd2d4471c5ab9e1fe6ee31a3d00a137fcf5ef1bc373969256ddf69b7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:00e44d07b20bc61d3396b9468c55747a3894f5c891030ff2f7157f496b98b531_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:7a4a60e1a5022ae0398f7bfd46f07b86268204805ce916aded24bed767c9e7cd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:83692ddd0895d00cf7a85f53d132671eb0a9027f4c824dfad5943ceaf8292b45_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:fddfacbff3f39e0b122e6c52e3166207dd29c83dce9f35ef737f341ef74945cb_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:0a0b3d5e27e6b0d854036bfd507e54d2d18397afd74848dcf8d83dc026927703_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:19e517553bc9922ef352e89194b7af0212f8791fc0d897532c3f5ce8a03cd695_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:402a011650f91c5040b91a757165adc5fea3fb93b6b875640c0c7beb5e8d2e76_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:dca52273b33af9c05d5da2000776bbda9add8248a260ae77212f14fa24e01519_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:0d8c08c80233166290c5b688de496e5138e553ad3ca9fd12cb2dccdcf5b7fad1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:212eab439a695b829dfb26912c39c6f56a71a2eefcad413410d68ed12ecc882d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:a5085449369b93f12ef3c1619c7c6445f95a6c9d99ed4f524ba46a1c92f9266a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:eea1701990efdcc306ad32893af2cf8fafce456df6c23a8a73dca553dc427355_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:1f02531a43a99dd2fd180e8bea2010680be9ffc2dc649c030e1ed2a519f56b4f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:b233c7a0c0a218322c5d2fd5d17dc21db914bd49e84f46dd53aec042eb77d39d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:f702afc07372180dfe38d285ddff9cb1e537ef5b2cbe77f4a142a29f5e6571e0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:fb60b805884f916a064698b3e0cacf4ffc773501cd610260a930b1278cce42bf_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-cloud-controller-manager-operator-rhel8@sha256:983ce415d6f8ba25e024e7917906a67af92e9281797a5d1a1ddd04fd8538e34a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-cloud-controller-manager-operator-rhel8@sha256:a6cd9f3062edcaa7120e6583777baa01881240a3482dc57d5efaef4625b3ea90_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-cloud-controller-manager-operator-rhel8@sha256:e09f1d49fbb3a1ee310a26761f43a21256b70fe9c1bd86ce912a11f98a9ed726_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-cloud-controller-manager-operator-rhel8@sha256:f58e1b4fc0c09e745ae4d4921266aeafd9fba8063ed6274fd41ed5655c010e9c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-kube-apiserver-operator@sha256:3f60b0d51781fffabf061d4eae04a3cc12eb93f0f4d08abab68983b8e56c47cf_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +83 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e5128c3b0ab225e0abf9344dae504e08b82dda4885bbd047e2dbc13cc3d9879b (For s390x architecture) The image digest is sha256:f024a617c059bf2cbf4a669c2a19ab4129e78a007c6863b64dd73a413c0bdf46 (For ppc64le architecture) The image digest is sha256:6c9d4941723561c7e650c0fca0b653010b76d1c28d8241b30e88b2e325b16088 (For aarch64 architecture) The image digest is sha256:878d14ee4651f77403e37dceabdedf31c0d7561e00ae3e5ee570ae98d200306f All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2023:7682
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://issues.redhat.com/browse/OCPBUGS-20554
- externalhttps://issues.redhat.com/browse/OCPBUGS-21774
- externalhttps://issues.redhat.com/browse/OCPBUGS-21845
- externalhttps://issues.redhat.com/browse/OCPBUGS-22295
- externalhttps://issues.redhat.com/browse/OCPBUGS-22375
- externalhttps://issues.redhat.com/browse/OCPBUGS-22478
- externalhttps://issues.redhat.com/browse/OCPBUGS-23445
- externalhttps://issues.redhat.com/browse/OCPBUGS-23474
- externalhttps://issues.redhat.com/browse/OCPBUGS-23566
- externalhttps://issues.redhat.com/browse/OCPBUGS-23569
- externalhttps://issues.redhat.com/browse/OCPBUGS-23747
- externalhttps://issues.redhat.com/browse/OCPBUGS-23903
- externalhttps://issues.redhat.com/browse/OCPBUGS-23982
- externalhttps://issues.redhat.com/browse/OCPBUGS-24063
- externalhttps://issues.redhat.com/browse/OCPBUGS-24196
- externalhttps://issues.redhat.com/browse/OCPBUGS-24262
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7682.json