RHSA-2024:10518HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.17.7 bug fix and security update

Published
December 3, 2024
Last Modified
September 6, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-7409 — QEMU: Denial of Service via Improper Synchronization in QEMU NBD Server During Socket Closure CVE-2024-10963 — pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass CVE-2024-21538 — cross-spawn: regular expression denial of service

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:1e275a75c67a970163a15badf1bca25c81ac9be3542cdcac4f2b7293b124e5d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:5f474e3d5001a230bc835b72dea776579700431402b3cd742e3f8f93f586efcc_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:891b8592ce765b201426e1eaa7638d2787fabc6b3a263fab3af4db6fa419938e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:8f78d2b951d11642b06e53bf3b27bdc65ae56293745ba6a778116a8241091a4a_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:b7ae8ed25cbd79e30c82748921d71ee9df26480b5e473af325596057172bfd6c_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:b9e5788fd7391b979e51066813d1d83bf84539751557490108aeca90ce28f8c5_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:c7bdce91aea0274b1a499a54b938c55ce67a35bca085cc6e6f3a7685f9e42ff5_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:cc279a511e95e740445e0ba5f50ac8568c0494191be29b1539adc5cc34f8ef75_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:0b35c3489b4a47cda06c9f7ab17c70f1d3e4fd26b6b0542710a1d8c85d050632_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:a73a7fb3f12906e4ef45f073bb11cfe736e69d13fb3dae1060614a8663d2e9c6_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:b9397453bc892584e25ee9bb5966b4f2a9c3c08d5a75d94cce8ec596f44e9c27_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/cloud-network-config-controller-rhel9@sha256:e0c401e54a781c9983e7d5df7c2414879757f82d895be12ae8032787822f0ce7_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:675a418351b2c04cbf8cad268edd212636e5360c79c28c2f4fb6bd51f57f4875_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:6c1fc75aab0469c1c650914c0929918b48b5f3d29ec6fba0ac91188354f791b2_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:8e932e50e614a4d99197913bcb32bbb703103f204c91f2b9cbbb9c1a3c0010b4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:a308c466e3a745a96ef37ff93415853121c73b061a23a48e3ea0de4f060a958f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:0840c4a0d002167c8db9f61c4e3504fa7c68972d26ac601b2b68435878f55d4f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:3bfe3763e95c436a17cbfd870e521a238496bf5d7bf450101032f91ea047e3f0_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:44afe9759da03149207f599917f0b040abe66c903fe1180715b8274c66ef9446_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/driver-toolkit-rhel9@sha256:709069955097d8087402e00649abefe5df12b724c5d05e13d6a05145ef7e2a5e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:3eaf474983dc7fdbec4ea1e00862f01bba5ffacb4b85c7330bbee2d246bf716c_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:9930fb0803ee3c5de877264d0c6819b14f5d886edb1f1d4f5fd1e4c7e98bb41e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:af1d780f035f1d47ef474b07a93ad877f577c8dde12fa9e88f3fb44a829fa696_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/egress-router-cni-rhel9@sha256:e7f70b284d0f35536bed337913c7d23c2d3c5fa21a5129ec17fc377c041b453f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:1194a169018a1fddb223e574b14d74fec222da62dfb2ccf74967dd3b0e95bb12_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:151609231df65eb395ea43e23041e78ec399fe9751de220e0d47ee2dace7d23f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:b4f2e4c5de16686159a5d6ac9b123a27469225c3fe39e87864929237a579316e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/frr-rhel9@sha256:ddf9a00321e22659ff5e7607b62df3e0441cb2dbf5a50bf2f2acd062ce1222e5_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-metrics-server-rhel9@sha256:8ce45025bdee595b86e927ef18d08a18af39ae3accc990e69371fd015f4d327d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e8680baf0b44dc55accfe08c4ad298d508d5a19a371bc4747c2f6a92225aa38f (For s390x architecture) The image digest is sha256:ac5f1baaef0447c5010ddb9ff416e481274d045ca1641f00fccef680265fa47d (For ppc64le architecture) The image digest is sha256:ded679380070f96330a9902eeccc9ee8b13f7b4588b6d0e7bf7bb1385bb568ab (For aarch64 architecture) The image digest is sha256:ca82f8a3d13fa2a43a920f8be072df56ea3c24312592dce189039e8800c329be All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To reduce the risk, administrators should ensure that no DNS hostname matches local TTY or service names used in pam_access. Additionally, implement DNSSEC to prevent spoofing of DNS responses. For stronger protection, consider reconfiguring pam_access to only accept fully qualified domain names (FQDNs) in access.conf

🔗 References (18)