Red Hat Security Advisory: OpenShift Container Platform 4.11.55 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:163558f8599f0fed24f2ca1d6853c9fa0f24ca4417a83a0ca7cfbc1f05ce0f30_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:1e2511b92b7d6ff4575047478c73cce77621f415614d0dbb27fbe8036babfa54_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:bdd7476f4d268a85c6c4d8fdf7a62774614407253be106a33f439adae270df16_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:f83baa7e7f3234d3b34729d1e64b2417235b5d71590b31a58412a8a255abf0e7_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:2068de534df853da1e3b0c037ffcc605dbfecd2eb742e0b5eac8435a581322f2_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:87866a49ef7b90217fc88281b92f4df1be3f270a50b6eea6bc9cbec2a4069d9c_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:f0cef1110d60bafdf11f58eeda401a09109009c42aad76979736036c2da049ed_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:f3e2f03f117efe598b09acf67dabd9d8570d9a6cf05acddc5336f2c655735050_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:3615df9a2519c4523335513c6b58072da98ee1c265b0421cdb230cd1dc0dc44d_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:4437a31bbb2569ec4df7c997b05452ee692f3f5fd4280cd6b8c5f56d0ef1186c_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:839d0da6b020c7beee549d3a16042991bd1261036048c90a7d34834e99529683_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:ae982d99bf677f9ad06aa61477cf185448e6cae7cb132ac6999ba686a12a1628_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:6b9d737d1d3a308188d882f19215c0c1aba5f6ed5f4a231670534b99c1d96493_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:8a7b48ad3e1f603297ee0e397d82a57e5d52395f8bd2520aec75fe477cb6d475_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:a2d766c35246677873f156dbba0d64ed9e0cd4e37b85e05b35cb498fa14e939e_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:dc15bb5cd8d908910c6725b7796d6b6aee7ca94a4f3873cce8742d2a0c2c371d_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/oc-mirror-plugin-rhel8@sha256:4cdaea679add9a7203af2b9c5b7ce3b6655731cf2f2cc680162c12705c2b4aef_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0d6d17d78b66433eec3fcab8eff0a6c6803f58dc9e36c80c9fa965713c2b4b4c_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:154c15f133f181872ecf3dc35eeff27ff30fdf33d79569c1dd7fb6743b385965_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8a1c3830455859e9081bf72c220e13ed51a2ed8c874defb6afc4ed8e136a8e01_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e15f82d7665954e22107e3552f7d51a29fb21f9e523c8dd483f0845d59e316fa_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:463ff890a96c855c52bd288b90dadcea0ee836fc4aa1e6fa37a4f57be8d32208_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:75fae32d07922ba111b23859d85618e0fdc5e42aa02e1b85c5fb581c6d9385fa_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:bfdbf0c5b3a63a06cdaa74c6dae707bfaf1f41d003aefef20dd9ad677b79f6d8_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:dfe25ca4e5230971074dc6a54ccd74ec477c72b82133e98275a3a30db2c27cbe_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:23586fbe1a5685a279523ab77467a253c575976f3023efb4f891a55408beae21_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:72b1dd18d62af6f5ebc6c991173ed02e39629a47a5a4ac98f1dbf45a126dbe56_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:7ec81463b7f9b0cc8d20af4f1b8118b601cdf25ba28dabb2661d568efbfd793e_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:d90d9f6fbd24996172d01167031d89ac49333b144074f36926a2a4717fabf866_s390x as a component of Red Hat OpenShift Container Platform 4.11
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:5054bd54461e838f8ecf4a9b1c012cb38001ca79586bbd23e4db7041f2777a26 (For s390x architecture) The image digest is sha256:ba0f017d2b97afc0feec37a09931ff93ce5e25afc16c0c5a3ab7a8dcd3af0a58 (For ppc64le architecture) The image digest is sha256:b575f66fe84f0a60fad5698bddc6a77c9acd86c585ea16f81a670c3f05b382cb (For aarch64 architecture) The image digest is sha256:471f4044a365e4c6a22f75cb790c279e7a21a9b083a296e2776b5ca877107a8e All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:7691
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-20122
- externalhttps://issues.redhat.com/browse/OCPBUGS-23574
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7691.json