RHSA-2024:1210MediumCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.15.2 bug fix and security update

Published
March 13, 2024
Last Modified
September 7, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:6430fab390f89490220157eb3823e18afe98d50f9ead50da0321a0288d6e07d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:99af9b4a045c8c012b1b46552bae9b876e157f27ce0ebd28a2520010229e0c9e_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:c4c99b361d79d3857e2429aeeb8872830b0525ad2e3802e3cefd191a8f3a25cb_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:e0b130a246cbe8bebe765db2da4846197e5a55ee390ac0c8168eab1ac0b262f0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:9d974e00ebe924fbd03abf03c55d873108a1593b5a5e60f0daf4b867fc5bb1b1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:b87f82c2683e565f309e09a340f0eb210e61e4a5121bfe99034ec53467bee817_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:c95c4e54f6b31d37092580c25e0ba4a0d5e7e0a7279d18e596d2ed47b20566cf_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:d97924c32b5cc849168f8fe90dfee28bde54fbf48671da1861f7a7906dec0289_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:8f0d5b63f5fda0f85d4b4480183006eacc2d2992cec8de7525cf849f4043857f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:dacba541f83830894c8a0d11c057ec4fa8dcd50fc222c3bf070fbc34a0255a41_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:dc4d5ca20c15f5a8c68c9cd0ff6bdf0294fb42decb67d789973ae2612d6a243c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:f73d79a4ee3c3fb9611e380d3a5aa7b4f75f5b2c8ad19550b11587c2c38ca277_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:04ba1b9798f71b51790e48a728071138ac298faa4259ee5cc46f5919d85aa400_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:3f5638dd9f00196c1b99808421b071097630d904b055a4c2a568822aa95797e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:6980c57070dde0ca1dfc993ccb0f83e18f7827f929e3e0bfd9c5dee25c60fa15_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:bfecc7f0d4233a316739f838adb14bcc2afed17c39dcb90db176b03ef6de4566_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:27374390a3852fba6c5497b5e3df8131022357d777bdf75775143311ce020790_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:44f6c2ea5bacde2cbc3cd2222d3e5974c18d5144dea3a1b0eb35c2561e77ac40_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:ed860f47823e47c39b6fe5d10c49d734acef2481ce758670efe0d2b41e5364a1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:f2df6f6bfb54425017aa6a905d9d3b0f17f5f584fcc6ad22d6f2924d5910d574_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:26fd5291a0cd40ae1dd250fc1ccf588caa7b122b641ed5d17f5b877c037c1560_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:a5ef5aeb7655ad1c0e733d45d6216919b6e10108ac6aacf3ebb5e4839af8f82b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:d6cd45436a3a2f2657b35f440c7bed5481ea2a0de1c7614199ca06463d2770af_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:d8577277c08bb104b249b4305500b49ca4a663e427d8c27960828ed260651586_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel8@sha256:1c78c6f6ad459da84f1c945b5ac9e5ab7ddbb0e84d92c60c4cf895a313324db3_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel8@sha256:84e3cde6dae10051d7ba492e27cbabd7487c72caa5413c24d58b3b41ab8279d6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel8@sha256:91349b7aa001ccb6b86635d90513f19bfa244205d17bc00ec1c65ed00beff2ec_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel8@sha256:c32d02e5253d634146546f217443677d822488eb539148bb071bc5bb4d940f1c_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:4bc16b7b4fc00296244d7fa21456a8ffeaf1daea97fbd26835a67463739614d5_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:8e5ebf5d648eeab2d440036ce0f94ab73743aed85f9f5a4725a6aefad8f842e9 (For s390x architecture) The image digest is sha256:33e173482489c5e0627e0e49fe21fd34c3ff02bece3d6603d333ac6ef6b9dcf1 (For ppc64le architecture) The image digest is sha256:cdd529e2297aafa8e1ebcf2ea3cce5df1b67360aaa3cc40da2b00bebd60405a9 (For aarch64 architecture) The image digest is sha256:b3d1659b00b74ab8734b2b54720faa0d4292edabcbef5600e1adcd396c172ba4 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 ~~~ NOTE: The crypto-policies workaround requires RHEL 8.5 or newer. Customers (for older RHEL 8 releases) who cannot immediately update crypto-policies packages may manually configuring Ciphers and MACs directly in /etc/ssh/sshd_config and ssh_config (as used for "RHEL-7") method documented https://access.redhat.com/solutions/7066001 ~~~~

🔗 References (72)