Red Hat Security Advisory: OpenShift Container Platform 4.11.58 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-6596 — openshift: incomplete fix for Rapid Reset (CVE-2023-44487/CVE-2023-39325) CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:02a8bcee22045d403d6d3377a61bc895b17b837d80055ffc8f121eb022923b35_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:48a99390191b3bdd6c941b2a06e38760432056674308630d611165fa400407d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:4bb9d4a8a838625ec869f74ff113f37172ef66a83996f47fc545751798bd67c5_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:5449386be217b990dd94b4fc82aa77bdedfaca116245131f261143e7367b1876_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:5161622cf3375154be94a278f7321afe0f3c7c77df3b8985f67b16a3a3dc8cdd_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:65008b6f7e439e865fc070bf3f3db1c11ef5eb069f3b250dcc2cbc047caa4235_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:7b6eeae22e3e07d82ba7cbffce46014c43f21017eee857c436a5d4e1dcaacd6c_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:7c37c1d6e6e18659819677b24a506d1d7102a5862a2ad6a75011ee5607079c63_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:46c304d57d893e4d7300590e7c0549aec6e97e0402ff2c5d38f42b2c5a95780c_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:b7b458aacc756c828fe55713bd57c21366e874059fcbc04b57331c0cd5db920e_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:fa66f872ddaef433b09e4aaeef55953acd54c65600be10994b408296d6a9d591_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:fdf9e7e5ec337a0190d60100f8dee8c5ac0e162c0c94864134aa8d8c0320f046_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:6d0cb27591bcb6dc69542c4083219195b8f6251165fe380c05a2c0e4504699e8_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:a63f9eb2aef8fbbdf2ad64f32d2f6355c86f313af851ec538fb6dc3e6e5ab7ff_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:cb24204145bd51e1ace3b4300d38528b8c6200a3641709cc8bdedc6d48faf93b_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/network-tools-rhel8@sha256:f91e862bfae1a170046c33e0c569d917405943a2cb20f7a32148711bfe31d590_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/oc-mirror-plugin-rhel8@sha256:2808bd6ad6ad3e593b3f0e72d0a23cb9f11960f90c3595374e6e5bfb7d9159c0_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:368506893895269995619258a118aa57224cee79bba562f2bd5f46cd09df9be3_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4f8dc5c0ca7ed061bc9375fba23161ea78b0d5d8fb69e9370371baffb4810ecc_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:583c0f0e6d5fd973c8d840885691731235abb2f8cdc000f1beaf7a6cb934a746_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f19c0395c03a73072151c49d2997683ffe65214c34e6a05b0e0cc18f0586c31c_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:17a3f940fbe627f2944f98144026c2f260c4efa01cec6ccc04852ba41e5370b6_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:5e8df90490759534cc6199785268b7a9ed7252cb6f0bc61106bda0152a730296_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:7113a193b03d1ff25eabdad5fce8afe8016e361fa68e3dccfba4b8739f860f5d_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:ed541e5ab3badf073e2e511d181df878bfa7208829ab54e7bba92d71cce15b5e_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:77be02cdbf8f50c2ff3ef741a9bf21f693091bc891ab0b96a0e0c03691d7a0e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:8673c58511b16b24dca329ab2e55c6cb4dc4f39c30df4a32ede092d10429fa3d_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:bf4f4c0ef447f6d712d9d6de45b7e32531f6cd65cddd73ebbfbe4e737b5ae234_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:db77a4b96373d38da813efbc082b19487e47cf1cbc27578baaf2a48462f2acfd_s390x as a component of Red Hat OpenShift Container Platform 4.11
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:60091111bfb629d995977e4a91f090a2306e5be609d3a2652f31280ce0eea1f3 (For s390x architecture) The image digest is sha256:aa4aa718213730ef9242358bfa0366dceb3d53c0b5cd988f210325f0bd17fed9 (For ppc64le architecture) The image digest is sha256:4f27cad0a41d1e8f95bc87992bf029ceb58ae20cfc9d1418a7fa4404296d20be (For aarch64 architecture) The image digest is sha256:7d20547a3a60ee4f46cf4b1e7637f7faa0b5314acfe935cc1c9b7e0a41cc7625 All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:0682
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2024-001
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258725
- externalhttps://issues.redhat.com/browse/OCPBUGS-26405
- externalhttps://issues.redhat.com/browse/OCPBUGS-27231
- externalhttps://issues.redhat.com/browse/OCPBUGS-28749
- externalhttps://issues.redhat.com/browse/OCPBUGS-28955
- externalhttps://issues.redhat.com/browse/OCPBUGS-28960
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0682.json