Red Hat Security Advisory: OpenShift Container Platform 4.13.31 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:250875faf6db23500c96e775df1dfc9f6446cd2e053b8ada5ae296c80170cf13_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:3466090e5a43a4c5bfb4801f89f958e37d918e553030443a3058c40fb5d9d97e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:3ca23eba8d5f45127f15a9290ff7a38a5905c0d419da5130d2ac4ddcd5edb2cd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:e1e7a2afd542fc799bdb9619e30680c821ea10081d59ad84c56dbd3761a814b8_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:127668170092fcba9524a3f13ab1e88745cf69dda2ccde8f14e7f42df0d7ad45_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:72dd64594ffc163ab2c6ebc63a5940849e4cbfd931225ed533a31da18d3f621a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:8b8b9cd1b1d975834902092b86d646b61208d3dfeeeba4cb730462303f74dc61_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:95fb554851f9a37696004367fe7180f72fc2b9c2db94215f857e8bd36708179b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:4a4cff3af24c99de8d5984d4f5d021ed10bc85abdab6b972105485f1b39f1a33_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:6f2a843ec6f57a9d31671851aeaeafd41850e32ec93eb8928d8cb2f6da0324fc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:82446162347593c39dda740d3a5d8c44245364eb717ed85dc823db1632cfcc17_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:d002a95d961455eeacc029d1050f09aa565319f1fd2c7a2f9ecf0550bded1e58_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:2806bd3d878f9578d09eba4f6c6f569dacc48612584cfe3b1f03b43ac4f05727_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:495a75e552469f2edeb467535bf17e207630adfd226610edf58df307a8133dfe_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:6fecf5a00b4edbc1db8e79afa8547f099f943fb747b6a36cf5b0f752ba6d4ebb_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:cadd110285fac4c27047e790090af93cb0902d21165b6cd5247bf68dd3ad881b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:2c4c18a99ad0eb107aaa9191c3a2848c5eafb893345990c06570a79a122d74d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:38902826d756ea9ac81d9831e3440b756592f680f825235963d8f99a435325a6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:3a2ece7f5e9e97c0b454599869cc66dac3538302a892377556bc42b600e9e0e3_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:a9a83fe268024587396ea57d89d968f8a198efc7764479ce398bb9a563aed734_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:c126a46870e59469dc67af5b44359c0c9a09215671399fb61324b7566a28a67e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:20bd5ed1a5c7e30b7ff3fd25d44db2bd5c3bc3325289a09e6ae69d490c8e58bd_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:a3af54736659451d145ab9114902539f88441946fe90041a42d2bd45f639bfa1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:bba3509614af738c4573dcbd76476d58c26afa31158df15c72af4d9e80783254_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:fee25b9036c1c0e16e7892e4fbb92868778794e2f35de921820d8a0a994bf904_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1c0f1f69c62054e94674e6cffaadfccb5927a69ea6f44409ebbf049dbb9f9d9c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8961e464f6c3b4133973e7c394ee91d1c2623a2afbb532672c959678d2c96cc6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8c6e4a0736bad7c72148f3122e97ab0c258a13d4ae6c3914326fdf06cd9fb9af_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f8056d961c0a14d5d0d33f58b0a9b24d933f1a93daf3d9696cc523c1970f0578_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:07cf79d6998a9b6a2d19b7fe168a3300ad682de33f190c9eb27bf61e67d3eeee (For s390x architecture) The image digest is sha256:92cd6a11ea342d5d6667e4fe7b209b04ec01b9dcd164c5332f74977c072cd59e (For ppc64le architecture) The image digest is sha256:064fc53014392b45f4b5d7c8fb4f24689f452e17b7549f371a434fb93194a666 (For aarch64 architecture) The image digest is sha256:7201b6624dca4678f472d8bf70322177bf392c77534067e8e1f4e679887a2f38 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2024:0484
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-22272
- externalhttps://issues.redhat.com/browse/OCPBUGS-24419
- externalhttps://issues.redhat.com/browse/OCPBUGS-26423
- externalhttps://issues.redhat.com/browse/OCPBUGS-27049
- externalhttps://issues.redhat.com/browse/OCPBUGS-27172
- externalhttps://issues.redhat.com/browse/OCPBUGS-27233
- externalhttps://issues.redhat.com/browse/OCPBUGS-27367
- externalhttps://issues.redhat.com/browse/OCPBUGS-27370
- externalhttps://issues.redhat.com/browse/OCPBUGS-27416
- externalhttps://issues.redhat.com/browse/OCPBUGS-27754
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0484.json