Red Hat Security Advisory: OpenShift Container Platform 4.14.18 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics
🎯 Affected products114
- Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:0911fd6c02ccb78134e1819e7cfd22947a7612ab6e10b6543e92274db7f9b3b0_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:6d322550a952371f2594154fc9c11d3e7f005af0acef23cbebd98c69e6f980df_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:6ee0b4c320b8df0e8dc242a5ee012a80cc34883f8bb7a0c130c3bcfa94248314_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:f87c10831421bb146f66d795b3d0a7c446c052ce5527e8e038a1dfca0d54de17_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:2bfa58536d2442bbce5e39ccb296c052789488ffd3227c78199507a3d11a0c50_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:4a21ab1b7296ac0d97291359bd1c6c6a8b4f5cc7bebf219dea5b461e9a772979_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:515ecf6652ad760cedc21bd57fed6d3c2df43eac0d730be83a152c21eb50006d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:798046de1f34bbae5b98e95b9b46f90d7077a26a1e7e6674d1b4b41051fd670b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:1ffdfb2c4ac5fab9c844ac36cabd034c7b317a4876b06a91e76f3d5de3bb8a31_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:59da5766d00e8223b329d347eb3afcbfc3aeb84a0279c68434dc3d595f16cd50_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:adabecd11413408d78eb85fa9254454ce103d9a0c579491c789e0faf3777a8bf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:e0a5fc84f6153c125e9f4e6be2b2f3e82d5cd8705b4197c78288b223d1ecb5d3_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:90c09e2975d2c46679daff24504bf599021a42d93c2c30a77ecac74cec18f5be_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:aa42ac8d673983e3186948cf2381cefce3dd96992b686cde15eaa0a22d416f53_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:b656d2a51f5aad7d906a4bd44b0fc35abebf6db044dfa0ed27285e0125af2fe5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:c855dcdfe750e77df0890e190b030de643aac9fb0dcd6e06f53f7362a4dd1a5b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:0b6ccfcb96f859639cf6ac093189b68291d4a30d29e4d7bb6a96f0dc44138962_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:3d31a0ef5596c1883503363ebf64387cc14526f787bec6d3c3c93f28ae1a861f_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:68783053ab1ec88ce9644bb1a8eac3887cb0f0ab0da75f56bd1312aaf89709f4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:cdcbf6efc59e49ff3ed5cfa8fa0f7105943dffe93efa8e3580ebcb26bc6ea1b6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-authentication-operator@sha256:2885e96fd8cf8329bade1ed390b2673cdcf4955059364c7101354846b87bc597_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-authentication-operator@sha256:c6731602a76a94eb098d0454a59cf6c3f54d562778f222de3cd217f39d8d9cc9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-authentication-operator@sha256:cd19161355ea255e41aba6a97089cf1c642ad9550152b779efcc9abf658178c9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-authentication-operator@sha256:ce59fad930595252ebe5a04b026d6d554f6f456fbaf3d97a3af6afbb589dbe18_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-network-operator@sha256:2158e5bfdfcd23b3d0e5a6c5f48943e8f419b0ddee504361637b04c4d376e198_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-network-operator@sha256:82fa7afd4dbf02f5444d3e6802fd3b0057e2a1587a072b0c37300bebe1849a58_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-network-operator@sha256:8f63c0c8dc0e30f97ec4113812fe0c5a1f8c873cde02efb12550681ea933f569_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-network-operator@sha256:addffc2b4d1dcb00446f5c28f275a0d3fbb6f0bc773634f6a62b103711f3ac90_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-node-tuning-operator@sha256:6bd3bfe8dd8fa6ef6127d32529b94da2b1a80acef331ed6ba882f1a4b82c3cc8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +84 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:b572b76fdc9ae73ef9e35d01b98438d9b19ec4ba4c9aabc5eea3972d4724bea3 (For s390x architecture) The image digest is sha256:14dcdd147ab689df829af0192deed06176ca3a81544ac171015a84836c2d5d69 (For ppc64le architecture) The image digest is sha256:92a0268f2e440d8ec4216e411ed1e08d4ba7bee9b6d288e2d013c2e83f0fde56 (For aarch64 architecture) The image digest is sha256:552baff44f3cc3733d42131c0934b89a60b08bd47dadd56eb8dc9be4b23cc3a1 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:1458
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://issues.redhat.com/browse/OCPBUGS-10795
- externalhttps://issues.redhat.com/browse/OCPBUGS-18640
- externalhttps://issues.redhat.com/browse/OCPBUGS-23205
- externalhttps://issues.redhat.com/browse/OCPBUGS-29237
- externalhttps://issues.redhat.com/browse/OCPBUGS-30027
- externalhttps://issues.redhat.com/browse/OCPBUGS-30878
- externalhttps://issues.redhat.com/browse/OCPBUGS-30980
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1458.json