Red Hat Security Advisory: OpenShift Container Platform 4.14.8 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp
🎯 Affected products115
- Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:9833aaa8ef64abfd5d456f8be81fc67d4ed5e2fbce70fe5bd2abac45b622ff4b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:9eb5ff00dcf0f81902f860d82ce342a5cdb5cbda4e57d0d9b2b7f56953caa2b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:9effbe9c30a6ee0855139aec62f34e507e4711305c10c4bb83f51a3a1f1dd9e9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:ad965dae9663986843a433ce5d5c6c5ce9a52df650c1c38fc71f988163b9ff06_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:02ed5a96189fff278e7fdcd473109d08030411c4cf6a6b419d911af9cc2cbd32_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b1a4933997319bddd63d93d3ca1ab0b6dd90409310c748afafdca6532583f847_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:bdf69741608b7465922a676812b82320fd7503641d769366a3b6a6f2b9d8be8d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:e301c4ccf40794c3ec23a4faf5f225fad8f042f1cf47792bda3ac9b2fa49de42_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:3a79ba273f4f6d9c0a539dd3d4546375acbd2312c16631e1d398eb53444a1e28_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:86d99ee773fd4fad9732db273a08b7f4b908ecb7c7e3e354f7030fbbb720d7c6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:adebb76821e84a04fc1a26091e17036644bc56e53e85a3cd1fbfe554c989bd63_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:dda7548f1910c71e204449b066c4725a42eceef2ce90edb0292493a9bab3c49a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:8ab41920e77329f31bf652ef515a1178d8452c62094ec7330e2fbd3aaf58b08d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:42fd35f30f05875421e9d1bceccea431089a9ca30eae29730187d0eeb431f1f9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:b277645e464e3c35c977f546fe6326bcae0cd68fba1c8f3553b01b10e1b40d7b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:1ea65eb77ab015fd839ee47bb9628a2c8c164060d8ba2bc79b5f4086baf16339_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:6806df12984414734b215cc5848272ec9d66f5841238c94cdaee26a37f302f0d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:44f6f73e081c81ab91d1a8cc4d77c8d177362b4b0a85910c8a532beb861679c8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:9ae0e78e085d124c0ac5f13a571a83553be1227ff8299d42737e77bb91b69d38_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:b1191ef30ed6a9e7e355561bd8d773ec02e72d5e413518d60842df11028af846_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:b83f73b8b94bf867476d037e8ca7ab626600a392b8e00aff3473178bf45a73cb_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:4aec428b5e499627092019dbba860b6e61646aa6283877b9a74e3eb47bca09fc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:ab4a8a2cd8b071c1a1a0ba20204b01623c94eb684b559d233008845960953d0c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:da63854deafd613d1bbe7e07066c5ef0e4324c16ee4fd3b058055efac2da43d6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:dd324239c480be2f566ee39e6131e07f53f2977e96fcc938f3d9d1fc3a277846_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-kube-apiserver-operator@sha256:302bf36b60ce951fde818ed442d60527ceb86ebbe20291a6c38c38d2b35821fd_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-kube-apiserver-operator@sha256:65bda7887fb8dcaa1bebe17b0e06be2f5b2fe2b5e25df844ad9183e797d1884d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-kube-apiserver-operator@sha256:71fe0ce94544f08e1d7e997e6e161dcd973db17569421b1490db4f5b85891e3e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-kube-apiserver-operator@sha256:e770f0d483a21c62d0585072cf8a701154b44dad18c49bf160d0dc46b80fbbdf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +85 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:073a4e46289be25e2a05f5264c8f1d697410db66b960c9ceeddebd1c61e58717 (For s390x architecture) The image digest is sha256:b6ba1ea6602cca707e6fdf0f1dd09fcdd2881f8b0e853d0f96cf83942c54bbb1 (For ppc64le architecture) The image digest is sha256:29fa39db92e471aee54c6a56b20b0a7f684da4d6061c0f5a6a3d81cd7c796ebb (For aarch64 architecture) The image digest is sha256:d71ce79db01d0ab7b4a2270ccc4162c107f7959ef9cd48b394557c4ef455cff0 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2024:0050
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://issues.redhat.com/browse/OCPBUGS-12720
- externalhttps://issues.redhat.com/browse/OCPBUGS-19884
- externalhttps://issues.redhat.com/browse/OCPBUGS-22267
- externalhttps://issues.redhat.com/browse/OCPBUGS-22771
- externalhttps://issues.redhat.com/browse/OCPBUGS-22787
- externalhttps://issues.redhat.com/browse/OCPBUGS-23771
- externalhttps://issues.redhat.com/browse/OCPBUGS-23968
- externalhttps://issues.redhat.com/browse/OCPBUGS-24281
- externalhttps://issues.redhat.com/browse/OCPBUGS-24320
- externalhttps://issues.redhat.com/browse/OCPBUGS-24346
- externalhttps://issues.redhat.com/browse/OCPBUGS-24349
- externalhttps://issues.redhat.com/browse/OCPBUGS-24474
- externalhttps://issues.redhat.com/browse/OCPBUGS-24489
- externalhttps://issues.redhat.com/browse/OCPBUGS-24627
- externalhttps://issues.redhat.com/browse/OCPBUGS-24664
- externalhttps://issues.redhat.com/browse/OCPBUGS-24667
- externalhttps://issues.redhat.com/browse/OCPBUGS-25275
- externalhttps://issues.redhat.com/browse/OCPBUGS-25384
- externalhttps://issues.redhat.com/browse/OCPBUGS-25397
- externalhttps://issues.redhat.com/browse/OCPBUGS-25417
- externalhttps://issues.redhat.com/browse/OCPBUGS-25458
- externalhttps://issues.redhat.com/browse/OCPBUGS-25685
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0050.json