Red Hat Security Advisory: OpenShift Container Platform 4.12.50 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:099b15e7cd8329ff1435376a10a0b65aa2eaea4e75142e387c14c3a3b3893cdc_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:0a074e42c46365234931163979a581463f7fa87d3aaae1b8f61bda63b1a8c6cd_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:6c5de27e5bb2b974ceb49bf2a1e997e1fa60fe9fbabe5b19a78ac08251094794_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:b82abd05c27a842889ed14c992b00157882db8f4262dd4963fcf6a66e202d974_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:00ba9da97606f74ab831e69bba7cd33e99f6ef1bf2d95a008c8381d5ac3b81c9_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:a4bdae14f71433e1336d4f3130fbe128d285e61d05def4a97ae9d5d0cee16441_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:af8d920ad9b4474483a9add3d75fef8b2e312e9e1c7eb44360b6af896714b226_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:e37a9d3329e33535034301a8bcbb422bab1355d266686a67f6a432da8b16d67b_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:0f67224d0fb0b57747e508c7bf2f2e9d2df984bcea22561e75945120f5918da3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:62251009067494fc7a36289cd9884c90d4faccecc80a6f291c86fdc568483214_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:7c62b1a3cb2236fa04b2c29a235d845a80b7400d75df7ddb31326c0ae785afa9_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:cc6e6f9d776c08783f080054187264de219548630801b0a12a3b84e85cfed459_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:11bcf68861db26524f96038d55f25eebba37afef98ee46577763e5feabaa5f4c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:7c3b0ca52556ba740856cca6d1e04037d9d351c400051d75d312040e45de08f5_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:a92dec71d1d0653876f2e7cb9fb31bdbcdcd533e3e54658d07f75dd76553e411_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:f129f0c8d363c15b81ec97e9456d7f82399c9acc8d3644729517782d97389098_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:20876df6603f168af84467720f6f993252f1a91661dc129c293cbfaeed017c04_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:235dd33e619d126ce389ce40b7fec0909fc7f11c8842aea4be42e0fc747981ac_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:fc18238362426040f3cea53f7c9e2d17865a7931deb405daefdc87098f6e0707_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:ff7a5a216729ab480587a3e5460ad7621466ab8692889ae4f78d8eacee18e03b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:4bbe79e266a06f2b8ab2344f64232c76a04964e7b9ef042dba1ff9f086335c15_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:182ab7b9635eaa6956554b246d3d171cdacdb7a433dc7edc2378dad9399b3983_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:6831fdb4d9c13b36b03c27b525ac902f60e0b38e3982492b4ce13b510406a4c4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:b36c1a05d38e62d4597d07c3a4f732dc59448be969beacebc299ae68d6aa4459_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:e5bb7be2a8ff8aa796590d61410369c657d5811453da62a0750fd4a0760098e4_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:19a492608f613d0efb4b60657962d0cade519c1d35458a5f00bec525c15adb5e_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:7fa53d172df93a0463eee254481460c69083c0045fd981992f7693f09f3c63a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8db868c036c157685ad5af0ad594a7dd627269266283a00a1c91004dc16c09ee_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:fcfea50c21c160eb82d3d5d5bfaa74a1c7b03198673a369ddf6763c0236ca23a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:a9d7e4938d224a6a8f9c7a5c05ca2b4d6e92292812b14c4a3e0d9e938e8dc3bf (For s390x architecture) The image digest is sha256:d2b27993318e4e72388bcc8a4ba655810e903f0e6bdcb444648e8d0488646816 (For ppc64le architecture) The image digest is sha256:9d42788d7b8ad829c43ff536471b7245745ed86d6285f39a5c8050541bc52b85 (For aarch64 architecture) The image digest is sha256:192059898431ff5af6b60d4e1f583ef32b4c59b08772a9f73c1735a812700f6b All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2024:0833
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-27776
- externalhttps://issues.redhat.com/browse/OCPBUGS-27962
- externalhttps://issues.redhat.com/browse/OCPBUGS-28229
- externalhttps://issues.redhat.com/browse/OCPBUGS-28954
- externalhttps://issues.redhat.com/browse/OCPBUGS-28959
- externalhttps://issues.redhat.com/browse/OCPBUGS-29066
- externalhttps://issues.redhat.com/browse/OCPBUGS-29229
- externalhttps://issues.redhat.com/browse/OCPBUGS-29278
- externalhttps://issues.redhat.com/browse/OCPBUGS-29302
- externalhttps://issues.redhat.com/browse/OCPBUGS-29348
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0833.json