Red Hat Security Advisory: OpenShift Container Platform 4.15.39 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:49af77f8674c4d85e13681f9e85c06666b874b7772dfaa1a3b230d31eae1992c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:4a4ddea697629584be2d7ff2bd28c2634335868b9873d8b44470d7a92e0f1d8f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:cf7312e27d9c50d2e3168fa045a15c3d636a133b9a44a428af0f86ce610fdda1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:f6f4d52ee9aca8ca2556543130875772fcc2f6e9f37efdd86475490e9ec89b1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:6573c8f98ec7d955afd5728a6554f31944d37fdb8975e9d5ac3f005d84b1b604_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:84c9ac71d8c40dbb72f106c67f93dd273274e39e1c26af94d140f1c5958cdc30_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:bcc6bafb6e0174df0a3b7ca395612a992a5d579cd93dd0aacd5f5935251c4a3c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:fe303523b2334599f4233e483875cad332d111c7a4b45040dfc4f38819eb4ddc_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:0dfe9ce75fc40049f43aff6d9fc0bba78a3b968eccf9adc0fe32162cc8417547_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:1ec00f7412ffd103212bc370002322d5c214de6142a8634082af2a9521a072eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:3167fe8e8a76ee44aa421fe166488682d4c8fdd95c981cfd8eeab724249592af_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:680cdb922fe9c6eb07da3a9c654e1a926f3fe94635405a8538e391771640b10d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:260d090f51e3ff55e2d01cb3dcb034fe1bb786139ab3b6db4e7b7a256d9bdec8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:b00b936d521569a39512b7babb931c238fa42867072f6d0eae4e43d4df826f9a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:d0b4d6746c7f3f0e515ac82c30083aa56691334dc357e0e515c4c9a081414011_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:d9d0dcdf81907c925724287b6a82d946e10927b72225e089f7e752d4196b0e27_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:5771db980487a8245d2663a5e245bd3977938572dde046ce0b84bd91f01fdbc1_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:713c7b50a213716440529abeb18c10fc51824cb631188c04417fcfe6b78f5288_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:ca77aee63e45e281281bdf7e1ef27a8d29ac86586db7ead37b94709be070ff9e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:db4f1854b7669bd9946f2450452fab3e5fd96bd5839039fff7feec038d7f70ea_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:471e4fecc0aaee611615b18dfbb697f595aa2ebf29851cc631cd9bd00e2079ee_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:48bd77d8b31fc4da7cc5f070fb9b5ed8ef6b899b61bb05392b151c1af9e68028_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:c8b94dc1543d802e7ffef4e3e3150fe1fd4ba38c146e859f6b17ab77dd1e3b73_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:ed981af608c1e2a2e715a8f33071b743e412a23aff222d1fdeb8bf24733be466_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:334aa529d16fe08719fabed1fd165db7b791c5a8c9e675d92acb7754dbf2cbc5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:78c50d5a6ac1c3daade86480ccacdd2ef65ace5501de031353e7646501b86efe_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:af53228916a8a254689eb4329e4d47fc5b57ab2042e7941711b69d5d9a52ccc6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:fd8e1b5c99e787e42ff32f86d0c56082b934926c7f76bc5a6bb249cc8f888930_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:47ea39fce7fbee818ffc99d613b2f7a1a67b34c0a82f15e717da90e6238b6e9e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8d8a016f337a14624b70341f63ce4a1d9210326940775e7b3f9765730677668a (For s390x architecture) The image digest is sha256:da57248333252d0c0a81d11e2ee0371ea8a4da9df49fbdb04517ea9772c092b2 (For ppc64le architecture) The image digest is sha256:15d401dd9df29350760bfbc78b119e35618859628e567b41cae827abf9473d88 (For aarch64 architecture) The image digest is sha256:adb48f66b85f4a6c2430c4b4aff688f1c6ba52271e2bbf1bd06cdb8bb67dbefd All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2024:10142
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-42137
- externalhttps://issues.redhat.com/browse/OCPBUGS-42355
- externalhttps://issues.redhat.com/browse/OCPBUGS-43414
- externalhttps://issues.redhat.com/browse/OCPBUGS-43760
- externalhttps://issues.redhat.com/browse/OCPBUGS-44006
- externalhttps://issues.redhat.com/browse/OCPBUGS-44106
- externalhttps://issues.redhat.com/browse/OCPBUGS-44212
- externalhttps://issues.redhat.com/browse/OCPBUGS-44240
- externalhttps://issues.redhat.com/browse/OCPBUGS-44275
- externalhttps://issues.redhat.com/browse/OCPBUGS-44283
- externalhttps://issues.redhat.com/browse/OCPBUGS-44294
- externalhttps://issues.redhat.com/browse/OCPBUGS-44317
- externalhttps://issues.redhat.com/browse/OCPBUGS-44328
- externalhttps://issues.redhat.com/browse/OCPBUGS-44378
- externalhttps://issues.redhat.com/browse/OCPBUGS-44705
- externalhttps://issues.redhat.com/browse/OCPBUGS-44729
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10142.json