Red Hat Security Advisory: OpenShift Container Platform 4.13.38 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products100
- Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:2d7c1bf3d0d57c0c8453883b0b05ade3a50a6b1c323a5e4cab05b829a006041f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:466c8144f0f53aec3a15575a87f3acac3de61101be72f7dc79e3599f75cd3113_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:4d9b58e6ac6f9f28a054a2a0c491c05a425f468cd9f1460ee1dcc2c56b91060c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:fa20bf3ddb18510902575e7481bc1e6879fb38548d73507f6fc3a211dff6484c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:105a91a836aa95de1b33e9b24b1c3b66e2905d052ea0735ad84fb90b0635a7d9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:67f7b4700feed3f47409a46faf57c27a9b3e329ddb075846650d9df3e07727e1_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:baa6522912450f3482ed9e9583f21313378ea4bd9e890eac5f7810f5cb4bfcc4_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cfd802f58ff145050ae68decf91adb26178b0a91fbbf54251d613805bf9f1aab_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0744b7c3c15c0ff927cbed6f3ff11b96bdb4fcb5cd117c98fa3cea5e94ee07df_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:49f2c20389d80e2ad642bbfb71fdd7df629dcc3f453f12343295a464abb8a0d9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:90bb702f9f266adb9ca46b9dae13f0b63d3571f1ca45eabaaf4f6e2cfe81ea61_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:cb775ce2cae7e175faa31f423cfbeb0a0dead96954e009c5ad871ab1c4d8e3e1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:54a9da2dffa22d4c453f63bfe21b551a416f0890438f796b20eca0abb1b1564f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:63bfd62b6bad1b8cbe8a84862bbcb933a2450e3be0e191d6be6604108b7ab835_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:96d0a1e521205030cfb2fca07a2b289d6aa221a98735de9ffb5ea1aa5500474b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:f751efbc7aa4dccec29385e1a351a9c4c0e7ec53b357b56787c93aba08d3fc51_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-rhel8-operator@sha256:016839fd5d6ba645958e0b3882b4f0fb965139aca461bd61a254e5a1d74ffb4b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-rhel8-operator@sha256:18a380cfae6c9a1fba886fdc1ca1595aa55ae50d8f9ef50cefa6c37274fbacbb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-rhel8-operator@sha256:a24bade640f4594bd9516e6f11f371a45207e36fac3229157f28390571f360fd_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-rhel8-operator@sha256:ddea1177b1389d26339ce5eeb8a7f9be2f38f056dfaebd5475d597c6a1f376f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:02b983e4a2172df2cb84aa83da0e715174ddd2dd8d7430b89d6c2523784502eb_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:1b7fc7f7fb8f147a7979617d59fa9a30aa2a3bce652b4edd55bc169c1185e56d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:c9095df6dda9e7439cc040d13d996c6ce7bac8e74eeb2592ffc5a8f31c47f647_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:eb3eb0c47f1d10463c9e472dccd08cc5e173dddbd01f437853946866934a1a3c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:40dbad437d37b340a0bb9fdb5696b92e871d51fc6994e89aa1958e15d0ccbe1a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:41c34eca0986697d740cb837e0f4bc07d8cf3ae4ac885c0c5ea3b8e3e451daae_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:d2997a6af5d1ea9b8a229bd36f3ce7654c3ac3fda4a4b9581e668b01a8bfd3b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:d57b6548aeeb795b7a792c2492228ae2e1b662c552f638cb45d9cc65fe789f8c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:234f9368646d07986112f9370df3d35a9ef1fe0dd0c20436e8506773742555a9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +70 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:db7a6fad1d56cf391159d252daabbb44178132081e077ae290317b91633fb1db (For s390x architecture) The image digest is sha256:ac2640b78a51a19e4cc5d8815ba36a51bea15626d153136d621952cdbbfa1b44 (For ppc64le architecture) The image digest is sha256:849d11b0214c68c023acdf6cd55d65a4e48d87d1c75eae92afcd470ba5ec9002 (For aarch64 architecture) The image digest is sha256:8425c6b8c2dafeaa1ff506acaea240c5b22da9d958c1ed21e95255cde0096e84 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:1454
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-26224
- externalhttps://issues.redhat.com/browse/OCPBUGS-29663
- externalhttps://issues.redhat.com/browse/OCPBUGS-29721
- externalhttps://issues.redhat.com/browse/OCPBUGS-29851
- externalhttps://issues.redhat.com/browse/OCPBUGS-29906
- externalhttps://issues.redhat.com/browse/OCPBUGS-30082
- externalhttps://issues.redhat.com/browse/OCPBUGS-30113
- externalhttps://issues.redhat.com/browse/OCPBUGS-30156
- externalhttps://issues.redhat.com/browse/OCPBUGS-30245
- externalhttps://issues.redhat.com/browse/OCPBUGS-30248
- externalhttps://issues.redhat.com/browse/OCPBUGS-30629
- externalhttps://issues.redhat.com/browse/OCPBUGS-30874
- externalhttps://issues.redhat.com/browse/OCPBUGS-30896
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1454.json