RHSA-2024:0642CriticalCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.14.11 bug fix and security update

Published
February 7, 2024
Last Modified
September 22, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:2296c27f9b445a09078dbcf6ad738293304a3223d6b154ceb88061d54eed03b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:7caf64b854c04b390ee2efa2e993dd87b925afc9ee4f77f14f458bb6442f1494_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:caa6f639d8e036b02954e9c2825cfa5dfce77e872f5bd8708763e02fe5dc855d_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:e48474c9dd8366bd0e5301c4b43203b47a8ecbd7da699ead5902b315b8ad818f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:01fd25dae5a3868364640e9eb3d1fb0494fc8473d4f5e037463fe0b3b36999f5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:3f3ed0600645c64674c4115d64ce281b01c7ce1344316376479708fa5b0f2dc8_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:69f287b827b623d0380d562af7514c079dbf9586d18f4298f51f4f9479940a71_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:e5791897768086da4b4faa29256a477d4c1689aae34dff6c42400e94e8116a2c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:0687dbe14319ad913327d5b38927d3dcbde8320083686c8bfcfdb8a47b36f720_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:ab6023e0bff1b75c20623b9f47b0c0115f90ab2f48742a228f0cf23857ced8d4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:b290eeaab12efd093893fa03b0451f3a91fba741553b8577298a74225942841a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:f3327d8cb1a36ad25969262c46351c6c23788593aad927467c5525a29bf155f9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:77342cbea9a06da5f785e68adb878148ee6d838143f31a5be8085133ae24ae5a_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:9c5f6ec84fc23e1938992c9a257b3c989a9529203e7c7c75d7c83092939d973c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:add65334ba813d98f6e5b114286cc9d14152b942da494346a10d49daba304b1d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:b3df50e806ce20c1b490d93236d57015d6920e952c30b84c757a7b1f011f48b3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:149c6aa67ed31d7a580f71d60c066325c84d584a55a53555689883e5813f5de7_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:1c4a44e831886ee046bee1a3ddb02090c1069c7b57640a74893917bb3bd9f2a2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:ad6182de5b2982b53e017ba94345362b0755efa1ef4babbb529fd1fa6a07bae0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:e277b86284e2da75cc91c074b537914e0280e65944fd9119466b5733c342b7ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:4f08c0372bcdc5d92c4e6c32c57d10149f90aa3fde1464007a2d0018cbc0cb0f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:59c032ef9710da468aeaab295fd78e6e6ce0a1f3db4820180280cb22965cfea3_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:a8ba802b95e3f65b56041a70d36b614863802cce37e550ff726f763edee29bc5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:adce096186e59d3013a452287d7176c51b387a257e1af914c497584dcc159b6f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:09686eac1b625f6c58c38331541d79d8a4769fd35277e00d43f1cbfc06b0d19e_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:3666fb2ac9b9fc5761702fb7781bcda5e583e80143bcf19db418b55fa11f2623_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:689d251457a992d408404f510699eabf0375e8852406014c6034c10abcfe3524_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:d67c44296567b6b772023a34b969c9657d8682365542f99cdbb8e99f0560abd5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:1eba5f7181601908887007bb8f754803a2151a084927073c65dd4613f2348328_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:36783a8b066c96dd6258e818ce51b5a763438adbf56221ea5c4b62ae4f345886 (For s390x architecture) The image digest is sha256:ae44573838e7a212a5c1c770249862763cacc3dcc07cedca37a140a73ee8ab01 (For ppc64le architecture) The image digest is sha256:6dc606eb76237e5fca46cf0ecc5665c473571b58c73b3e2ae48cda4f7eb62748 (For aarch64 architecture) The image digest is sha256:a456939baf9762ce465d90a73aee8b1dc73c79321472aefb88496766eba5add7 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.

🔗 References (48)