Red Hat Security Advisory: OpenShift Container Platform 4.15.8 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
🎯 Affected products9
- Red Hat OpenShift Container Platform 4.15
- openshift4/ose-hyperkube-rhel9@sha256:043262e39d71e438c15e6f14464e00313cccf0272c566e4a0455974902c0059b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-hyperkube-rhel9@sha256:31b932ca8708d890852f482e85f56cc312adc2f58c5e1d6c4c6beecd557a4e4c_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-hyperkube-rhel9@sha256:7ea13c72363c40ff8d87625a66f8913f2f43accabac67614e922eea26b3b70d6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-hyperkube-rhel9@sha256:dbb6ec887da8c17920f8ceac12c9c10c77f9c77519f3c61fb4c3154d8424db32_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-pod-rhel9@sha256:0693c62777e309588603dc9b20eb1df71b577fb203238ee8939b46da61c295da_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-pod-rhel9@sha256:5fb37cf023c5048878dad6e7020ab32b623047d98d779ef28ec62a0e29cb5e7c_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-pod-rhel9@sha256:69389bbc021900c662f1a27a62fd2a34977b991bd8fed863deb4fac1b24eef57_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-pod-rhel9@sha256:ac97982e845413b2b7377171d1b4c85d2b2cfda174e8251e3049d4843cea40e1_amd64 as a component of Red Hat OpenShift Container Platform 4.15
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:8032c4248d7ae032d5e79debf975d08683cc34d5f08ab2e937ce2d1e940c007b (For s390x architecture) The image digest is sha256:5c559596b08743a73919228fcf2708fac65763c6ce250a840950490ad20f21c4 (For ppc64le architecture) The image digest is sha256:3c2cd656b9055bd143b223f289ef5eee027d7b6e5b0ae240b9846a4c99c52ccd (For aarch64 architecture) The image digest is sha256:8af6e7286d4c65c89fc1e8c150a1c1c8766eb652a7fb45d2baadf54e9e9842a5 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.