Red Hat Security Advisory: OpenShift Container Platform 4.16.24 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-9341 — Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library CVE-2024-9407 — Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:108df481a035b1eb81705e14b1b228b873c7edcba810c4b94431dd08b4386c86_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:8458520b6b703727eefaf1a9aa6a6b9c9b877f0f42e9202794ba501e80f7125e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:8f676b1466a41c396aa447af9e969b2c4c7ac69b4a41a65dfbf576efc5460091_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:c600181d81c8f0c9e5edd41fb812bb6d0fda82f3581f3fe09ba89cb7ef9a5c14_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9a20604faabbd9b0932a69632df4d085027fe472441498887ba660434c70fd7d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:a0c2edea5d84ad5e7f4f3937eb1fe0f4f9587840be62989c7033feedbbe32133_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:d434aa7ed16f93351b263010acc6bf829820fba08a77d49d238796090a9e12bf_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ed4c90e0be514d4b00a71abc4ef21be7fb75e9f54ec1de092f4c874487c8499c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:270b7fcac89bc10c5d279b2532aa112783c538ff04815dbbf20da5b1cade58a1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:3d4d9e6c4efe1be2e1e4fbbea97eeef75994e040a4a77191c37f311ff37dfea9_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:e8708e72ded78f15acf69b54bc8b91f670674f0500cd2719717749d9d98aee00_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:f2d4bae0a74995135548a895db6756e6fe76656d27815ec1886505a4c4ad0a5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:517d419e2c1ad35d1ba33f5db9da3c18cc4d19d5cf37608d8b4789000153294b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:a123fced01c674a0f60f578f084c4fb5b6a4d44d3f54b71c9cd3d349d9e844ea_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:ce5629811add6854e7b1f9d6d1961f4e99f2ea0ec39ab5c1ec182e93088ce205_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:ec330b9f16e00475585fb6df5d2890dad2a326e26639d82cbd658b385cad62ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:05e6e79639abac5e8a89e77a8cebbeec3c7d8e4679d595d57f361e69816b6347_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:0b659087c63a2565e5a59ad38d1dd692733c65df96979b68218c0e44918772a7_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:9f16f0fc03b3b11c57fdb4aaa9d2e403cdb8d47eaf79646796c02a80adc51a8d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:d47bceb64dc7524243c20e57f2d3704c46fa4357bf4f359cbec1d39cff986c60_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:1d9e9c846d2de138770b3edcf4eb6fef8419d5fd6016cd408b6b38d284881801_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:28508dd1ff08935abeff2e538e8e82e20d9a355eb121739892059202047cbc4c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:60f331838b104222fb28398b99f3aa043be9b1a81a66b242d6973d1778b3437d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:775412b8835debb30eeef124453defaeeef5b3b26d8d64f928b8b53a6b4f87d2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:506687bf6c975e94300c8a3197763849032352fab8d641844b2ddaf06a55a11b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:538652e26b5c12ea76c01f835448359f2ec95a6cec1ab7a0c93e8bd1d7cea252_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:6e124376a0b4b01860ee80b9613935319a4c4fb007b096ce156c6c3e13d81cb6_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:f76dcdf44b21a7fa4c38be0921ec09309733dbf18ca8b357f5a02a5606451189_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:4f63e4b3925c26596ccd6285ee4cecf5919b1a53d72c72009320018f041b348e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6a653700eaae84e648f428c009de6aa6c9a3196600554947886083cf5280ed07 (For s390x architecture) The image digest is sha256:6cd53c234dcd43b43468c6c6d23e17f610fb1833357de642cce3e83bd1cf8950 (For ppc64le architecture) The image digest is sha256:87d401d6c4aea2a914e5c94e84c133b8dc790dab95e775f6a4bab86f9bd26743 (For aarch64 architecture) The image digest is sha256:df25904d8701cc02e69780239ebaabedbf266ce2c96e7f18a8cf74bbb7f18710 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:10147
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315887
- externalhttps://issues.redhat.com/browse/OCPBUGS-31287
- externalhttps://issues.redhat.com/browse/OCPBUGS-41673
- externalhttps://issues.redhat.com/browse/OCPBUGS-42244
- externalhttps://issues.redhat.com/browse/OCPBUGS-43973
- externalhttps://issues.redhat.com/browse/OCPBUGS-44005
- externalhttps://issues.redhat.com/browse/OCPBUGS-44219
- externalhttps://issues.redhat.com/browse/OCPBUGS-44277
- externalhttps://issues.redhat.com/browse/OCPBUGS-44485
- externalhttps://issues.redhat.com/browse/OCPBUGS-44486
- externalhttps://issues.redhat.com/browse/OCPBUGS-44629
- externalhttps://issues.redhat.com/browse/OCPBUGS-44802
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10147.json