Red Hat Security Advisory: OpenShift Container Platform 4.14.7 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics
🎯 Affected products150
- Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:24d0bc48a5453cafb098a6b5859156cc03f3276f34d5e4111b3deefa0c7a7fa2_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:39dc39e71f7464bce00858d31f6d7a82acdb2901e604d70e0e9ac5d93ed36e1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:cd0192d8137bdbdb238cdad540c61bc3d5d63face2f01ea290d835e6cd96c0f4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:f01f7b6fa410572072b6ab68d62e82a7537e037e2e9ae51487e3e774a419f84d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:274f6753ff20c2941dfde732f039262caccca67a9127a40596fc1e250b2d3bd7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:3b25f883bec94211dad125146be19c7a46dfd08f4dfaa410d3fc831632fd2fa7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:4f933bb7bdab3b10199cf9b543baf5acf10c10755c24a9cd696b139bea607615_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:d37f8498571cea3ed86c13dad8764aefa772ef8d06b8988d57dcac6d7f7026ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:49e4f23b436aacca68dfd65f9556ef44d22d29fa244077267bd8c1e81354f462_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:64791c9cc233767e01eb68a9c4676d2275b8748c9077c3661034d2a322fc2d8c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8fcd87da9e68e8f55a9e6b71b6a5f7380e9fc0757f4e4ac63c50dc4b9c0cb737_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e382944ada6041a98f31620569277c84b8e4488135aeec2bc863888f45e40f5e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:2100dcc80e358f0975c876a6156a1d1f4b423e75305c9a335b9d8b717204ccd7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:464635329f0f0d2a5074b10fed96fc6f7a75347a51e42a0d69a7ceb239cb8570_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:4c78b495009dd7ef879d81f530e69f95a822f592e7edb7a13b5edf3a802b76c0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:b1f3f05f5690ebcec0e64e52bc186769ab04d7cf7bfe12b3dfd8fbae3fda8f2e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:861f528096137315cf2da7344ff946ca6a2caa7d2b18668a407fdb543f632320_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:b1c5c9d9a4f550329b6e7b69a0013593ec76cd376e72484b18a35e06b50b963c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:df382beda24d5dc151211980266d0813bec82632bd98af6e43719f1eae3a482d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:e4cb1b9a3b65658aaee99681a9c467538c4eb2b31cde856c4f9ba6bf3f67b737_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-rhel8-operator@sha256:169c8c1ac71c2d3af8b331c1b41eaec5fc98773b27d5a354618e2e67092496c7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-rhel8-operator@sha256:4d619fdfd80b50f4b2da86b0077b7ce4f2887b559318f921fa793ad902b6ed48_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-rhel8-operator@sha256:6fffab26d5b95aa424b049c2ecf5028c98a1604733db15689e038ddf7438644d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-rhel8-operator@sha256:81c7c59b1e0a323ad0468cec021a6dd5a5b8cec53c1e137cf214291f430f3d3d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:0a99560cdefe2201452242103c0cb36684e2cf855388701cb5b3c6496c30451f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:0fc0c9c1a272fff223f4cd6a252353bb119a3ed2b7f6c0499914ab5c18525c07_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:18dd5fa6b80637c13e769764a54682ea7c96d1c6c7cab65aa2f2b7f0b991b742_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:1ce47fe36245b341bd63fbd4a82a36e43abd8967e5492e4db8eb8db9aefe032b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli@sha256:10be2238983ce6a368a91144a9b9044b2d7adf53fed7d46366b511ca32b985d0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +120 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:a346fc0c84644e64c726013a98bef0f75e58f246fce1faa83fb6bbbc6d4050aa (For s390x architecture) The image digest is sha256:a5a493a8eda0bd2799cb2caffe39e4ac3bd931af2bdb961cc8e6638e17e7703a (For ppc64le architecture) The image digest is sha256:490211f45a752507d751152e6f8d7574dcc0fd3c840dce615256d0c53a869b18 (For aarch64 architecture) The image digest is sha256:ea95f560ceee5ec31a57060c8e88dd4b0ced3f6e52895d1d089bb9df67423b0d All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (31)
- selfhttps://access.redhat.com/errata/RHSA-2023:7831
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://issues.redhat.com/browse/OCPBUGS-18438
- externalhttps://issues.redhat.com/browse/OCPBUGS-22240
- externalhttps://issues.redhat.com/browse/OCPBUGS-22776
- externalhttps://issues.redhat.com/browse/OCPBUGS-22978
- externalhttps://issues.redhat.com/browse/OCPBUGS-23169
- externalhttps://issues.redhat.com/browse/OCPBUGS-23202
- externalhttps://issues.redhat.com/browse/OCPBUGS-23371
- externalhttps://issues.redhat.com/browse/OCPBUGS-23387
- externalhttps://issues.redhat.com/browse/OCPBUGS-23399
- externalhttps://issues.redhat.com/browse/OCPBUGS-24047
- externalhttps://issues.redhat.com/browse/OCPBUGS-24197
- externalhttps://issues.redhat.com/browse/OCPBUGS-24209
- externalhttps://issues.redhat.com/browse/OCPBUGS-24254
- externalhttps://issues.redhat.com/browse/OCPBUGS-24269
- externalhttps://issues.redhat.com/browse/OCPBUGS-24293
- externalhttps://issues.redhat.com/browse/OCPBUGS-24352
- externalhttps://issues.redhat.com/browse/OCPBUGS-24397
- externalhttps://issues.redhat.com/browse/OCPBUGS-24432
- externalhttps://issues.redhat.com/browse/OCPBUGS-24460
- externalhttps://issues.redhat.com/browse/OCPBUGS-24528
- externalhttps://issues.redhat.com/browse/OCPBUGS-24596
- externalhttps://issues.redhat.com/browse/OCPBUGS-24633
- externalhttps://issues.redhat.com/browse/OCPBUGS-25305
- externalhttps://issues.redhat.com/browse/OCPBUGS-6725
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2023_7831.json