Red Hat Security Advisory: OpenShift Container Platform 4.14.42 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:30ef67ad5f2c0f5ddb11882b4de86a71580dc26540e0b9113308558fcd6c2860_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:39b5192fa3eed0306c164e601561d3688668a2145422f5f3f16f49a695d7365b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:3a8ef5e8fff8feae686c171d28ba80557d3fb983af70d84cfa3fd36a980503b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:45a88e3210f9e8adfeaf2b4f54b0e2aa0bedb7da4d9920e77e0e9c368303d3b1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:38b723820a28a6a0646822dcff8664c367de51a15d7f2016d2857f4672fd64fe_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:c66207610f3f9abe5969e71674ae6e985a9c47c3afe36f97555ecbaed7a4af70_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:eb4bc5134b0dfd9d87ca90d90e00faf5c1099de66b9114c159e6c3ed8d810937_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:ed392e8d49ff8c67f3b350dc8032b256001f9e7f43c3593c50effe551e8e20a0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:2e7e49395a559cf287c013f9fc1b3b951eb75f698e6530ce5c91ad7ff71ddbeb_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:52ef1845dd31906411335b6121f306b17a09dd692b3c1380e118d7468cad71f1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:70c96b8260fbe97fa0f0012c30623d5c1d7251d0425f5f359451b91631000075_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7519f2c763e6d8c3169e00948c1d1965f844c5ae79fbe95abb6e48017d65e73e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:3f471f77020743b4e863559280af5557a8071c084cd8a6d992d03209fab6906e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:51ad58a39bb6728694ff1948bb0d52dae4c019835c3afcd220658e0c2aa70bb9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:694b9f8aa7bb9292f69aaa3f8bd1ac45e6bbc499bbeb33f6ec8ab8f1c0d90b0a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:8add409f5a3e50d88636fa8076d7e02f59c6946f742c57b49529cb39e5ccad9c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:03f8077ceefd241ad50ca7b4f3bee073936e81b602a2c2f9736d949ef53a799d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:40e587b4162571aef7dabc9bb61938412a04f682244f3bae4dd1e9a5f81d9e09_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:60531da790150a81298585b2a5f141dac7a86481fa877d9824639ef40ef17c75_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:c504e305c9ee659ab4acccce36b805304114ac29e20eb6ee444231af4d6f45f7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:946dea879aa3ca23112a9b6cd1d9ceccc475e937883204fda6e0394ef9da8ec7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:9d80c5551f0ef65df9be6e0be7d198fa39e83b7e40b6a0fc86712cb09cdcd1ab_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b5ce35e650ed4b0140555a45032784daf5c2e8af6d961f1e6b1ff8e628856ac7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:bc5975cffbcd0a0620e748a694e2fbfb8d93182a4e628794b00a7b0f807f4cda_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:5746e0f2fc169c0a010351a23b60f340ffe08535f8e26a49b37410535a6b7429_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:5df4c808baea60a3685f058df5415ecaacc8fa681132e814d46399cacd6d2465_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:72f7ab8cd076938cb9705aec187fc49ce31fb28231755a555f406174d664f3d4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:ff7c1d9089954d07cc8d223d28cb47ffc3a41de6180dff94b74fc7ff785f6eb8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:160e0451ad282a09dc42f5c0f4cdfa6c42d02ce43c35bd89d012a691de379e7d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f01782ee9d7b8355c3adf4665965fa0e7a35fc78ae2f2b4e28bdef9004e44256 (For s390x architecture) The image digest is sha256:1ed5269d30ddc3a9768a3c8d02f52b77245b2147b71b7d69fc43789622948024 (For ppc64le architecture) The image digest is sha256:9c4cf803b58b098c4a893fbf8c9edc840f1a46cf6594f1c6cd2268a162659422 (For aarch64 architecture) The image digest is sha256:2a4ec2d885d861657e8c3ea8e3002b9986cfd8480a03b127b9b3de2090074845 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2024:10523
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-24306
- externalhttps://issues.redhat.com/browse/OCPBUGS-42962
- externalhttps://issues.redhat.com/browse/OCPBUGS-43000
- externalhttps://issues.redhat.com/browse/OCPBUGS-44007
- externalhttps://issues.redhat.com/browse/OCPBUGS-44435
- externalhttps://issues.redhat.com/browse/OCPBUGS-44506
- externalhttps://issues.redhat.com/browse/OCPBUGS-44704
- externalhttps://issues.redhat.com/browse/OCPBUGS-44730
- externalhttps://issues.redhat.com/browse/OCPBUGS-44774
- externalhttps://issues.redhat.com/browse/OCPBUGS-44793
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10523.json