Red Hat Security Advisory: OpenShift Container Platform 4.13.54 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-26125 — golang-github-gin-gonic-gin: Improper Input Validation CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2024-6508 — openshift-console: OAuth2 insufficient state parameter entropy CVE-2024-7409 — QEMU: Denial of Service via Improper Synchronization in QEMU NBD Server During Socket Closure
🎯 Affected products194
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:0640a436fc67c6aa75b253bcf8afc5b4e428348684e6e5e823ec344537a46f7f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:5ad504e54f7eb23228c77faf74af0b2fe95ba3978c35c5c6f3694097deaf2801_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:d275f29f4fe1b27ede12b4507d7e3dcf58383ad719716e5b2c162da920259a96_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:d743b4e858a57681b3feb3a69ec2c18b32969e87b02316ebece97ebcbf5fd0d6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:d58d715f48956b91e64e4b2b84b8284a04eda99f66c5692f77afeb03fa3f3046_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:4493946ad05cd3a657b69510d8927e7faf26e7965de8f362f98b06514da5257a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:d13b1f9887edbf020b1eaf18efc76116e0b89803f3c0a17e255a10b79bc0da0b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8bc83af7f70c29fa65ccc22fbf8bb2a697b165f378263a78e749c1d3833410d5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:03f3f96fe2a567313d71d58240ef98d2aab836c454349e52d01dd766a4e65784_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:0651915eb304b17f745749be35102117f2a7d2e559e9037f0ae25f1a1b149400_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:aa7a9897260efe0b91be65037a22893898e2e3fd943e7f134f09e406d4c830ce_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:f1344378bdb88cc8d5362dece420a499618306323fcf9d7cee99c529aec72762_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:07ce05441e66c59c8702324b3f3ce687b62737a410901e46a210369c94c8e774_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:74c4cd1247ca33657044c70c738610eb961d927cb7423d44ca72773e58b5bdb8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-machine-controllers-rhel8@sha256:abc31d6d805f48073c5c43e1cbe6ed92d90857a5e777f2d3663b1ee7f49779c8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:bf3d09536e36e3cc1b810f3bd98fe30498f117a51df45f7a8c24e3587239caea_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:ed558924154b79ff983a9f829fca69ddca32b8cc2cf36cb03771f6be320a3df9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:51ac1f5a1e005073799653765543d19178e2664a72746be1ee4c8381927c34f5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:5eaedeaa3eafdf41bd385579de94c52599dcc0aaed69203ed30c4b34b0159d75_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:f56b330ddddb9af899a0ad8c626360cff0333b15741cc1d3ba95a0578ebdd343_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:1e7089a7a26548bb2b84d085ec10a84f09ba3203b510283cd27a73675eda7f1f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:61c3c420943cf404060f8d255996461c5349aac734bf3328a7b47c5b3a59d8b4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:66f462b7331916cef3b329d8e8ee76793ded7a1787daf5b3a073f9b5488dd62d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:3923c7f67bc06d92ea003d68e9a421d256c9088aa3c9ff40153d09c06154e9ce_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:0f77004804e8bc910ef7447b046871d5048ed08568610b1f92fd8bc5ef0dc225_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:f41ca801ba1939785dca81e10cf8a02ade1fcfd10cb58c555c71c02799580500_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:c8e826f0a9fae06a4abdca92b8b5b921172b09649ef704d58530bb32b27646c0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-file-csi-driver-rhel8@sha256:3b09633de6bd6d6e0845113392574bcdb7032ed302ae713e4517a19ef2b6a62d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:d19f5d804d962d2886bbb6d87a6cd70ee1b958149e50dc34316d08d1ccdc08ee_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +164 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:bfe066b4b30eeb48f1099339131d56d4005f0867d4e4b3484e3fcfee39b3d26f All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:10813
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2203769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302487
- externalhttps://issues.redhat.com/browse/OCPBUGS-42951
- externalhttps://issues.redhat.com/browse/OCPBUGS-43886
- externalhttps://issues.redhat.com/browse/OCPBUGS-44206
- externalhttps://issues.redhat.com/browse/OCPBUGS-44585
- externalhttps://issues.redhat.com/browse/OCPBUGS-44692
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10813.json