RHSA-2024:0040CriticalCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.0 security and extras update

Published
June 27, 2024
Last Modified
August 22, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28110 — cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials

🎯 Affected products179

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/frr-rhel9@sha256:271d77e60abe131d84ab6c14d80994a861bdf5336ba11bd20cf31d6613a4c709_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/frr-rhel9@sha256:6a3273258b1108500340c54261c72a9221d191f35e2155b3fb71366a1cd66888_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/frr-rhel9@sha256:cf88802d93c9a3db9148117d095af2ecf94055e03ffb04d2cac4c0db707a0914_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/frr-rhel9@sha256:f9d0b91b3046c1ed7774e9e84a2718b800c5a68a29335a2a03f40798e0e63d8d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:3562cd9fef3f4adfa2e6dba1f68e86c78ef5f7eda4d1436343fb45e0eef1fd9c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:3dcdf4aa44a2f14d4dafc4d481c1512f7961004e38c9fb8075c8244c3a424b06_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:44d92bb0eae0990dc89f5b90234f608c61247d2ca7804a5c5ed32c603254c258_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:a45768a84b0b53453329c0f7b63ecbdbe8d29f02f2d9ce8f8c2e2c83bc777ad2_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9@sha256:0af5edd75e7a64914f6ec08f275274a0d4253e287877834739174b93fede9ee2_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9@sha256:9e70ccbea04ad514c96e4c3f177067792c943b647302111303f13e127cc1e048_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9@sha256:c900d917bd3463f8a5c76828140df9f61f12ae825e73f7dc5044590b7816fa71_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ingress-node-firewall-rhel9@sha256:ece99dcdefde395488af1abe8632a49aca3cd791c334eb4518d9d3b3eaba2dee_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:2e45097eddcc0f163fb6ab53ac67f22a1e87616a334b14ea7b65fe8df8a78354_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:3486f3dbd6d80d6cec2d125af8bcd05d4370421fc7d3674e357243abb1ac2246_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:c6cb73a8c7a74d9c5399cd5e6d1dac10deb507042f006498ad0187660252f13a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:c80bef665875f91647af49f0843768ff40792bd64b8d74a55a6000651fb42dfc_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9-operator@sha256:4f384a0135307bcef97c5f2e7ea8cec004feb4a9b0c896937a75206d566153b2_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9-operator@sha256:8c84b63c1fee67b5688124bbc4e7bf1fc9618f30cfc2b4c57d9866b456ec26db_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9-operator@sha256:b6a885a4f8986228285fbb2b0bd1462a056d9d821adc83eb7b052e01473fe3bc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9-operator@sha256:d370b015b73ae98efaa95c6730bb66ddb125c97dc26212a8b9887b0a0389acd9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9@sha256:3a7736113ee4e1ca9aa5c95bc746f7ee6bc2d80a92a65312ee09e8e0327f00cd_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9@sha256:6e0ae62703c2f3eb52683c917812ea595ceeffaf2651dbe25fbd61a8dd7240e2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9@sha256:be6c6ad031d71184a361213b29f8f2c506c31cabaec8277ebd8db4645e8bfd18_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/metallb-rhel9@sha256:bed2d67c83088b538736b69368fddfa3801a0a04791d0e78aa4475ea80f30bc4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/nmstate-console-plugin-rhel9@sha256:68af7bc075b872571dfc72adf8719af0d4ee8994a8fc2b41a0757c345337f767_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/nmstate-console-plugin-rhel9@sha256:8141253a5ce901b5e7dc207e6883151566d4ca43ab59960f8ae34d1e489b66da_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/nmstate-console-plugin-rhel9@sha256:9c90a44548951da62219d9d688517607185b4ba43a60bda5773fd31ef6aa01c3_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/nmstate-console-plugin-rhel9@sha256:fff3fc7d754a57cf5b0bd88f10b504e7c31259f7f8b65140a8d1814e8f494201_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-ansible-operator@sha256:332419ac9f16b60a148aee4157dd8edae54b10f0b6d70c9998cef4de66efd39e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +149 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (42)