Red Hat Security Advisory: OpenShift Container Platform 4.12.51 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products95
- Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:2e80d55dbb7e6bf797262e13c20e6b3af732b4d0d5c31456585a649e367a32a1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:6660569ec6be47973974e4d35cd8611680beedd74f2ce96a9feef88be4823da2_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:c9247a566b200f0da3a6299d595b737a6796117dfd7937924f907376ac09293b_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:ce5fb7e5f8a80271acff183becd97627d79507713594306cb1a29bff22cf24c0_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:04ce678eca9f2dce98ed89c931c58ed01defc49ec0bef2756b0a6260b290e9af_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:3b72f8538e94512d07a9ea6208c88d0b89cbd068b9fa974625ddbc12d8059fad_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:459ab21f88daf89bea950f063880a4687c332ab480a8ce5950f7fc9116f3b26d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:5356ae64b19067535f3b628795d0ba88852a7d6118ca8aec216e1b3e9455f940_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:7ce7f326778c7626dd6b8b05a3d5e4490d4a414d49cd23074a5c58aaabbdbeb1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:304fa1a5a2944fc1c068f1163b758a4f9a085301426fe236eb479470b9c2a260_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:5c7abf9f7ae45e58e18832af22350263e6ac10bd57293fa0b627470297104929_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:7b8fc31cd3a991ef09f18830722beabc341c80019e8b8bfb841ccf854dc12acd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:f481ba48b8071662295227ad2a77ec5fd16e8e419133d44c15cf27981a237735_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:179b06aac7182cf3e9ce4f04b383df0b5afd3dec0624974abebe2c4a84b5f0c4_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:4956f49616423511d14b2a5cbe0b369825dcb2618b5cbee0793eebf6b90d2dda_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:7528f9c781759ae557520235acfe20e603e2b3bfdcdd9df693d13c132d70b80c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:7a4b2eae34d74a299c5c7ac7a7dee18bd5b077578a08abaa85d62032890d3479_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:19f97dcaa0fcd5847ad4202bde2705b2c0ada9c663f5aad92eadf2093c5f516a_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:67fcc37716a3502494fa0b32bdd2b5b7b2e9213be708bfd471eb36332003041e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:a7ff60e62790821ab489c5d625592f346f849a6e1f7a212bd619616bc64906c3_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-node-tuning-operator@sha256:d2243f9f00b5e2ce54d6bc145133bd3f3ddeb9c2820aae6eeeb4f2c3ef939ab3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-console@sha256:14ccb79c16143c900215224924f3c9702bdc1a38830c611fcb10a4022d7d400e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-console@sha256:1c6792fd4ae1792257bb04e7f3d8c9bc6134345d8792ef172cb2f5609b0006fa_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-console@sha256:4108f6ab3df488861e3bed74d0c0d2e1d001148c407f0364f0204347bb0f8c97_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-console@sha256:813248a588ccfcc5ca94275139e8ad9720b914020275c141c5d2134a94098924_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-external-snapshotter-rhel8@sha256:066407a4c7015fe82c2efd69c8c2ea49e427db0fc7f7caacd671a8670e5cce3e_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-external-snapshotter-rhel8@sha256:189d3c8b6f04292607820446ed9bbda1d8adb99fbf01bf9297baeb63493d917e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-external-snapshotter-rhel8@sha256:243cbc2b1f798af2cbac260104336f689a95aae08493a06ae17b386a0c5f957c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-csi-external-snapshotter-rhel8@sha256:e3f7e2a427acce5bc3ea21342a8840c9b608a9e30cb4fc0556904de787b76332_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- +65 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:158ced797e49f6caf7862acccef58484be63b642fdd2f66e6416295fa7958ab0 (For s390x architecture) The image digest is sha256:0dc967d680e06ba58c2e30f3729fd4dd0274603b1e5e717172bb06ba1977aa9e (For ppc64le architecture) The image digest is sha256:485e2734d2f926af79f555c24fd622dd2c9765e830e088a1b843c2534dedbce8 (For aarch64 architecture) The image digest is sha256:84ee8f7f61a0b2ee67e83e98ed48ad6e2584253fba44047716d042a8a90ff4c2 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:1052
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-22928
- externalhttps://issues.redhat.com/browse/OCPBUGS-24524
- externalhttps://issues.redhat.com/browse/OCPBUGS-29167
- externalhttps://issues.redhat.com/browse/OCPBUGS-29232
- externalhttps://issues.redhat.com/browse/OCPBUGS-29244
- externalhttps://issues.redhat.com/browse/OCPBUGS-29366
- externalhttps://issues.redhat.com/browse/OCPBUGS-29746
- externalhttps://issues.redhat.com/browse/OCPBUGS-29767
- externalhttps://issues.redhat.com/browse/OCPBUGS-29769
- externalhttps://issues.redhat.com/browse/OCPBUGS-29884
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1052.json