Red Hat Security Advisory: OpenShift Container Platform 4.14.21 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-26602 — kernel: sched/membarrier: reduce the ability to hammer on sys_membarrier
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:09d5d2559e2791c6bb2f8fe9804a03d9408878cee85803343140a8707d92b41e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:89c827d5f664b80cdc15d9a2a54d29fb76a4156a687d5976f2fc2d254d07c1c7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:9783a947e59bb9e5b446123a11a41abcc4a72be46533b86db8e818715c4dae36_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:fca43af24437504c3a729330c9b4f3e44f4c928df0e5c9d06e4e345ac452466c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:07ef57ab74c7570aa69670937043a032870a9d5c0012bd7fd78307150a6b9947_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:0af143d5be6b06de161c419af9774a924d00ed2c18197069001f3ce4f039932f_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:68c176d051f0b76299eb6da55e9fc90a0273b90f7ac35e37261fc7a8c3a2fdf2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7a69a85577c8891c0e739ed11b15cd7683a2e5bdbe049af3fa45109727abc347_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:1cb0bc72e2b6dbed4c96d28f55dcde8d6c3e9a1278685c4de48aa35dedb068e8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:59905bd73cd1124382aad2a04eff3a18b2b559a1d0de6ee43525df5b3ec9ef3e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:95d8a602c9bf97880745e84af74c3a519f45987090dbd7fcc4791e0460ead0ae_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:c5efb679567991802ccd8842c09043d180c4c035303e5b75dffaf03c955304ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:4573ba26135fa9c3b49b08517bf5c345f6d01151a8f606297ca7d0fb0c2d7229_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:731c4e3236e3041acf8fbaffaa4a3c8e0c98fb28d289a1c413ead6e5fcaa3e71_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:99171e8b00005b3d74b25d018f52a963448dd196689eed5f468d1593154fc25b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:e219e6f17b000b8fc5a4f6fb004637f7c3f96ef343ac9ec311a2c43755e1a0f8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:0109470d34576b44ad5fed0750046acc9e7408e9680840357812c0910d933491_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:477919439bd395e811b7219598a311f835422d5161b18ec353fbd295c08d0485_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:5f6e5bfbaded8ed5f32b70dda6be73ed160e5b6ec78e4020bef72630825bbeb6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:7ce8922b12a36fff3cf85d302fa09b048dfe123762283174ff984f156193f3b7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:4695d201f02ef8b1f67672984bea8b8a3104c3345395be8c5ed5c51d92e10642_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:b6e3ce037f4cabb3d3704405d19045cb9ab1c0e798024de74e3a3ce4594493f6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:ce33894dff124a52bd2bb656fdc1d2f3111ee5a3b124bce8332723bf10606427_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e004bada2813a9397e7ddb11870e25bd0cf55a2d427bc343681580185939bb19_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:2b2f6bed4bcd5e33b936d37bb800085a2968e23ac5cdfa3514645d821335ce40_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:30c58b49fd0671c8055896168a12460fddeb2051ea4eb0f24461d76c76bcba5b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:db2938150969e2f6da5afe8a2910c8de7e0e39715f6452275d9d1d910faa4c7e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f0d46fd719d886753286a50327fdc83c1c370e4ad9c11cd4546aeb84c2768085_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:232b4335e3d9fd76e72ea0f86535e9dd941c22abb55d788b1cf4e51e4b1b9278_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:6e3fba19a1453e61f8846c6b0ad3abf41436a3550092cbfd364ad4ce194582b7 (For s390x architecture) The image digest is sha256:8f515ed12955364be27b2b5730fd9a2e65beacb9ff39a0dee8344a80662ad212 (For ppc64le architecture) The image digest is sha256:5c8d3fae5b4924f1ae4e54a7450dae5aec8eb4b000a0309400f45115739365d0 (For aarch64 architecture) The image digest is sha256:55858221f81364cb977b715c469664297768b1faac9e7623e6bf8ed56443361e All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2024:1765
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-28746
- externalhttps://issues.redhat.com/browse/OCPBUGS-29783
- externalhttps://issues.redhat.com/browse/OCPBUGS-30749
- externalhttps://issues.redhat.com/browse/OCPBUGS-31212
- externalhttps://issues.redhat.com/browse/OCPBUGS-31316
- externalhttps://issues.redhat.com/browse/OCPBUGS-31332
- externalhttps://issues.redhat.com/browse/OCPBUGS-31338
- externalhttps://issues.redhat.com/browse/OCPBUGS-31417
- externalhttps://issues.redhat.com/browse/OCPBUGS-31428
- externalhttps://issues.redhat.com/browse/OCPBUGS-31621
- externalhttps://issues.redhat.com/browse/OCPBUGS-31657
- externalhttps://issues.redhat.com/browse/OCPBUGS-31681
- externalhttps://issues.redhat.com/browse/OCPBUGS-31752
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1765.json