Red Hat Security Advisory: OpenShift Container Platform 4.13.33 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-0793 — kube-controller-manager: malformed HPA v1 manifest causes crash
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:2638ad1a58f51db3e1699280dabf6d257acddaf7aa67b942b309bc7411850a43_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:714d86be26be36c13a60965e95f5db37ce161851249319ccd4d79541008eadc7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:e121d33cb0381d9349e5c6cd5bfa360d5c3ef97a7ae9ae9414e9d970ebf569dd_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:e831c1dc7aa21f6897b3000d1f61c02e83c71d6c2a10e9ee4aa85fb3679c789d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:0b3b5c5dd66d5fca5fc39d430be7aa0d3658291199ce2d6e06ab7245a54bb7e7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:6642cbeb97841d31e6ebc5e9d0491d7137c68c1172f6a420f9a8ebfdf255fbca_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:8f59ff7ab97b79d965d85c56f3e049959cc3d92b61b53cb51b4dedf8133ddbc3_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:abe1d0cd5e0125da726635cc83ef861020ae6218c22c9f66825a6f62e5c9ecab_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:17b945c577ef87e7f661236fb3a255a5fd832acb4080b6d5c772fa05870931a1_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:331d70c1a323fd0b9c7b7b5c8a7367eb8651721480a6d712e8f7c7028caf168f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:3e6cedbcf1438ee161ba8f769f0b3b4f27a84a54c09ead4d4ed9b40df295e6b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:92d85491ff785008648c4539bef963e5b00a01530aac771327e67206e64848d1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:195480dcc46d0aaf1c5d74b2ddc714d9fefe1b4475f60c94b8cdec80fb4e5292_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:389b1b944931510d5a89179a1e2499ae762132c29437619e1352485d52c450e4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:42295bcd9290fcdd3a3bc7eec214151581565b2d17a9352283cf43793a689961_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:9e1df76cdb9c0d029b2b411774ce6c6dfd8e059cdfea1613ce7d117e76c28dfc_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:021c54aadebb2113be44755578eb1d23e89768f77757b61572431759070e682e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:7153ea1c771e924dc4045eb169e08ac751b60e1b0fb9d2c5827cfb60360a7f0d_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:d24451bd59f030e5b8227264cb7fa25986dd1f59f29074d36d99e43b0c96b57f_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:e7ce7753b9ff61cc9a106a6f1ef925ee2aaa00a4399680b6621e269641139c33_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:9fb638be285dcd2e4d6baec04b42c83264c1c7c6e47ef75b6bfe1f1777d37a30_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:61cc57eddecf44c72eb15e0a1741a06b5e306acbd1e9433e23b318c0fd63cefa_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:734ae4ce6447d307d672a1afe813a769a98024d5e8d83fc618789bb0c27c25c1_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:8718c7ca375d2e9bf0ef5f76dae0ccc9f6d7f1e891bf41cf0f616c39b8ad4060_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:ca5d6d444e8f9e67d542a1598eec06dd1620510992a8cd52a4bb5ddbe935607a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a378f1d2fc3938f375a2ccf49d8a56a55cc20336e1f1aea5080234fa0cdd21eb_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:c271f11c9c473af475e30d5a7edaa7c88d3fe4ee4766e4467593aed5e2332c65_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:cdbadfb04e969a94c554088acfe6e507def6da70c023f8aec720d8c041023ffe_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e82da9d63586517aaa820e86ce000ee265f2c75d16cd433672993f0e810df2e0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:7083519fd75dc187b7405968ba3d3d764a9807529e955411fd0ca1142dd4b560 (For s390x architecture) The image digest is sha256:fd12ce4b8e006c6d8613f32f36e5ca994aeef6dee158b7179c450af2b86de4b9 (For ppc64le architecture) The image digest is sha256:d46a10358eb60f80a0d483aeba8c28d834769465a298ecb37dc69c7ab4cd92d9 (For aarch64 architecture) The image digest is sha256:2e6962da6066332442fbd5d27b5917f3980bef59be6cabab263774ac615213db All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2024:0741
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-24661
- externalhttps://issues.redhat.com/browse/OCPBUGS-25611
- externalhttps://issues.redhat.com/browse/OCPBUGS-25805
- externalhttps://issues.redhat.com/browse/OCPBUGS-26508
- externalhttps://issues.redhat.com/browse/OCPBUGS-28205
- externalhttps://issues.redhat.com/browse/OCPBUGS-28208
- externalhttps://issues.redhat.com/browse/OCPBUGS-28777
- externalhttps://issues.redhat.com/browse/OCPBUGS-28953
- externalhttps://issues.redhat.com/browse/OCPBUGS-28958
- externalhttps://issues.redhat.com/browse/OCPBUGS-28979
- externalhttps://issues.redhat.com/browse/OCPBUGS-29151
- externalhttps://issues.redhat.com/browse/OCPBUGS-6236
- externalhttps://issues.redhat.com/browse/OCPBUGS-8343
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0741.json