Red Hat Security Advisory: OpenShift Container Platform 4.15.5 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics
🎯 Affected products105
- Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:29e61ef973163f33b333d522ab8c95ea82e941926bcc889b9a971f66866ab77d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:787e45877f231df2a14be13f3f41739f8f702ebaef2da2ec21c7cc7a15626514_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:abbff60a77f7ac2276dbeef33fb46ed32c9b9eb1c5813260c6383605bed76a08_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:d66e5999b9932fb0b6daffb6e60b663ff405f87e268d823bec6e48b4076eba4b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:34dc122bd3349f57fa03523a492487e00dc0d7065c5cf0c76f8a9653b6008270_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:4dddbcc8cd51564814f3a8a5f7c05a8e3b0c159d0aeddcad31721d0760fddfb6_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:b98e809102d070597a03973d6acef0b578466ca0005adc39141bfc664e0b2004_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:d721073a7f5bee15cb5b265804d1070bdc9e3d7edc7196c0c2958f2fbe975ccb_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0c4bd4d0c7ffbd47698be6945cfb5f050a6f85538935bfaf43a9f24afff7856e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:57fc901b72efe536b414c268be065aabec37e1634d0da142d2691eb4ee83aa6c_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a39ae848a1b90c5ee139077468722a90c9c2fa528ecd370490cb937474cafa3b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:c5052e0e7fc81a160a911d3f2b73035790dda207873a6103f3b753406edd6824_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:0949ae468de89dc87d156d5d5269501c8732c730f5b77dafdc17631cd28f51a6_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:a1edd910f5021cbc3729237b161429c3c318a24de53455f0e7dfe1fa0cfdf658_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b5e2f96fb61711ec80fcb4c513a107d506e0ed54aef3b11746be008a9619d1d6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b60ae11fde611dc6b8038a61bc23e36d3cf7eb5b4ab9a9eedeefdd528e71e613_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:449f9bd8242b49486ac25b27d114a6250739036b0ddbdda192466b05726ac325_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:627b3e72ed3ffe82d1b7badbc3a325fc9306bf47824429c84324cd560cf3969e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:674fcb2579150a25c900fa3b56952db26fb5a53e749c556cc957650d5360353c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:c394527582bbe8386c02284074b1bdbb4803d031b13255dcbb4973b9128b4417_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-api-rhel9@sha256:1a85d8949d48144663c7d73004b0725ab64289c214cc059b89239e36bb6f5737_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-api-rhel9@sha256:b927664c57f64a6f0c45d48b6914af01ec24b4fe6d3aff3f88f3a2231d1cad2c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-api-rhel9@sha256:d9ece0b6aabc912ee4c467d260e8813f30b30f5e9b5464529f23a4bc150992a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-api-rhel9@sha256:f6f4a0a71956df7401ab74da5d0fe0a0f4cde2f569ccf203fdd6ecfbec86705d_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-network-rhel9-operator@sha256:4dac13c65035681a1e77687c817f960260cd42c91b9f78643c5f60f05c40899f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-network-rhel9-operator@sha256:72721605b5ad607331d2447cfebd1999fae67e3deb570b2dcdb589f37f308bc0_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-network-rhel9-operator@sha256:e90d012e580e2843ea1f93bc8e2ecc4559a784cf45af5b7bf57bc73295ba458a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-network-rhel9-operator@sha256:f2d79e98edbf5c0211935fdfd415cf249323d970c3f55adad7137a7918160b15_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:0f0620930e5dcd4231f2e8a78eb99faae1d79974a877258b2bdff79f7b38f441_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- +75 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:b17bc935bfb0fb250e738733af5d3d4ea1f27065de8e2622890782780b36320c (For s390x architecture) The image digest is sha256:0aa6dd862d7c6eec317c2ad70e578fc664d8d58da3e74558827e954bf75304a4 (For ppc64le architecture) The image digest is sha256:48a6ac2ef09bf7fb1504fad09fa53614d28b7c86864f3335c516a71741f25bf7 (For aarch64 architecture) The image digest is sha256:67b7e76b2e8e0c4d90f0218910653dbf57e3383f685915830b6e0b68ba8e8e0f All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (31)
- selfhttps://access.redhat.com/errata/RHSA-2024:1449
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://access.redhat.com/security/cve/CVE-2023-39325
- externalhttps://access.redhat.com/security/cve/CVE-2023-47108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://issues.redhat.com/browse/OCPBUGS-18986
- externalhttps://issues.redhat.com/browse/OCPBUGS-24118
- externalhttps://issues.redhat.com/browse/OCPBUGS-29236
- externalhttps://issues.redhat.com/browse/OCPBUGS-29458
- externalhttps://issues.redhat.com/browse/OCPBUGS-29930
- externalhttps://issues.redhat.com/browse/OCPBUGS-29955
- externalhttps://issues.redhat.com/browse/OCPBUGS-29963
- externalhttps://issues.redhat.com/browse/OCPBUGS-29964
- externalhttps://issues.redhat.com/browse/OCPBUGS-30093
- externalhttps://issues.redhat.com/browse/OCPBUGS-30180
- externalhttps://issues.redhat.com/browse/OCPBUGS-30237
- externalhttps://issues.redhat.com/browse/OCPBUGS-30572
- externalhttps://issues.redhat.com/browse/OCPBUGS-30577
- externalhttps://issues.redhat.com/browse/OCPBUGS-30595
- externalhttps://issues.redhat.com/browse/OCPBUGS-30601
- externalhttps://issues.redhat.com/browse/OCPBUGS-30742
- externalhttps://issues.redhat.com/browse/OCPBUGS-30792
- externalhttps://issues.redhat.com/browse/OCPBUGS-30801
- externalhttps://issues.redhat.com/browse/OCPBUGS-30814
- externalhttps://issues.redhat.com/browse/OCPBUGS-30854
- externalhttps://issues.redhat.com/browse/OCPBUGS-30870
- externalhttps://issues.redhat.com/browse/OCPBUGS-30897
- externalhttps://issues.redhat.com/browse/OCPBUGS-31042
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1449.json