Red Hat Security Advisory: OpenShift Container Platform 4.15.0 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🎯 Affected products25
- Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-operator-bundle@sha256:ad4c55b7cc6cdc8a9ecff84e839b0b475de0b50c20db7926964d069ce8a7ceed_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-operator-bundle@sha256:311a354ab15895b2ba12b17046aedcc4cd95f384969a74d6decf45ee36875fb1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:52f97b60aace7aaaa22b5a790c56261dd2ab2d9396b80499ed3985906167f80f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:76b89600c2cbe4f15de39caa3343fd7156a9f0422f46e768c3b2c5ce01919497_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-aws-efs-csi-driver-operator-bundle@sha256:b7dcc39a068b4b706b36307b255b3997001bd93f403449496dee27edd19fb4ab_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:0cd3b44d1d6ecb9ab893adae94a3da6a4843882e65b4e1da860a542fe47ed33c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:f7d7c1376a89e246f09e9d8beb4b65c14d12dd072638b226b780f4abe1f45d99_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-event-proxy-rhel9@sha256:3905aee5836e2ce3b9572f5946731329b9b3a31a87e2dd61598ea93053c67918_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-event-proxy-rhel9@sha256:71813d71dbc4223cbf323ac4d9e9416f71991585b441f34e5e63084eca0dfad0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-event-proxy-rhel9@sha256:e2f61b3ff01d7c47ad76cd4f46e07b2ef96d4a5f2f74bc53bc19dca9bfc645b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-nfd-operator-bundle@sha256:f088af61fabb1c5dd221eb5815a8a0f5dda36805356a642077a0f37efb5cc272_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-clusterresourceoverride-operator-bundle@sha256:94e5af0c9d1caea39256063cdbc089bac09d743a9c0b14d403643c5a55af3d9e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-gcp-filestore-csi-driver-operator-bundle@sha256:ca0381b535092e1b260a5f4b37b0401eb24f704ed1f33f38ab43d69ed6784e0a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-local-storage-operator-bundle@sha256:b73ac17534596ae64be84320ea57ff61ff0c2603474f08dd0053cafbf0b0e929_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-metallb-operator-bundle@sha256:91d9f032a45c619dfc3ab1110b331a80b746c5547096a9e8f26e1ab0f0dce6ac_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ptp-operator-bundle@sha256:b892b627d6bb32c2e550392b655c816ec909e1229d3cc8818a9334ea7e8d69cd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ptp-operator-metadata@sha256:b892b627d6bb32c2e550392b655c816ec909e1229d3cc8818a9334ea7e8d69cd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ptp-rhel9-operator@sha256:23c0816967bb826b4885b5104b584634a76b81d10d1a623f51605023aa8c7fa6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ptp-rhel9-operator@sha256:7b5d1d62057e450200fb37baf3d4f4111e7738bc3029c735e6de5b1b0710fed8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ptp-rhel9-operator@sha256:af40b6ea728a0ab474a53509ba4d944133d1f70710ce99816658ce30ada3f88c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-secrets-store-csi-driver-operator-bundle@sha256:ff57e48dbd3e1ea53866839482720c83ec1004ee550546021e02ffeb6ddc03a5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-sriov-network-operator-bundle@sha256:805228e933414ee055fb3d733c6f270f29ac259b36288a8b3c6181f4a94329cc_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-vertical-pod-autoscaler-operator-bundle@sha256:451dcb081b95927c895f69b784cc4d29c2c0075368acc38c99fa09234d191ad0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-vertical-pod-autoscaler-operator-metadata@sha256:451dcb081b95927c895f69b784cc4d29c2c0075368acc38c99fa09234d191ad0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 ~~~ NOTE: The crypto-policies workaround requires RHEL 8.5 or newer. Customers (for older RHEL 8 releases) who cannot immediately update crypto-policies packages may manually configuring Ciphers and MACs directly in /etc/ssh/sshd_config and ssh_config (as used for "RHEL-7") method documented https://access.redhat.com/solutions/7066001 ~~~~
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:0766
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0766.json