Red Hat Security Advisory: OpenShift Container Platform 4.15.9 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2024-21501 — sanitize-html: Information Exposure when used on the backend
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:17d97590649647663466f7a2487a2d886bcc604b6b70d78784ec40562b338f9c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:27b87264d4f267f1cce581b1c1fb56c7c25ef136b25787db900ad0e48b67e169_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:5a506275088ea383f4c8b283df5cbe15b3be45c51493829aa4d6bcb8602e4f8f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:7242d01ed692d239b6a9d9f8702ca1e0c2cbf51288f8dbc529d5dbe3e93b8c49_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:00083226b5ded55e187f68a9ef222b29ec6874ccaf56f4064db587e884200bbb_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:233eaca43b9b5213926f022b7dcf5cb9aba2de1ad4310e164eb1937f74eba65d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:62388f05f5c9fce5c04ad0518e2c4509228736c8c46ac2e4dc9ae361a68af83d_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:816f4f57c9796e2f2c0fccf866d6e76bc8df44ee30e292957591897f99066a4f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:5be32aafbefd9567b392acbcf88cebfc6513bd5899f052d6a1ed49692519e77a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:a27b92ecae58d9938040a2e0bf59d215efaa43c5dfdaeb2e1fdd9a8098a14a90_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:b8ed6cc5f9c1602b9e6989b842aee6981bc943056e4acf18dcce6e3d85ea3b7b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:eeaf7e6da92f718af2f071f7ea3f365258586eae3123d589c0c224f7a544b791_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:470fe8e02f8e4017ed6bc6b21a4bec0b4b0b33337f21f29807e05755feb39d98_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:5d2bc3df7189b159449a3928aab3af2fef529d27d23bf12be7f082b0ab23590b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:665b258327a3e265fff953eaed4a43fcbf54bed6279d96e6c3089b4ddb4ca157_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:9f7c790454541c3f5441e4e2e256a8d77e3a857de0eae42430d9eb93e0b433d4_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:1cfa575bc3354d94bd1bc3e3321ca142fd7e863a3d10579224ecdd11f195906f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:8820b2544c1ac1c1f517b41ba4443ffb530a9a3deb7351bfb08520e64e96e980_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:93fd04a8e3871f80bce8b6ef79aeacc3a6340c7b666bf2dde48e3076aa16a1a2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:a24a0b7d4390f42096c7d2406d79779acef6adfaefc2598cf9b3f4a48f76296d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:727e5c1ac82f92443ba4ab768788b46f6bb635a889f895a4f2851538b14ba31b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:93ffc53f22c0ab0ff29d1fb4212cbdd2b4912736468c8e968be4fa4784a3cb69_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:bce2429f7c101a57340ef8e7078723aed9f44c9ec2fff2f5e70dd79983668f2e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:f8c90d0b93a487fb4d0c6ea4189dae7f337c7d6ec5cb4f2a01a38742020c6448_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:44453dcac206df64c79bcf6e336fdf3e80e2cf03189c59b4e24e243bc5797baf_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a33977020cfaa32fdf45e081069d0a00f933339802696e0f1d59122413cb7ad8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:eb7fdee7e143bd9eee5b1da380c585d599a02dcd2aa65e3ff4250bf3d83b3baa_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:fffac1fc49f1b16031cdf52e5625c7b60949c3fed8fd349cd5dd633b515753bc_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:1dea41a56cbdcbdbc2739049cbd0b55b4ae54abefd3af36a6ee1a6283071cc8e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:4c57e9589ac8d96ad74fd8c9fce35c5e507a20a88a6871d8a731c3b295abc79a (For s390x architecture) The image digest is sha256:634e598fa7efd07889134df534c48c9e9bc3a9c9281fc9f92d3e6e7a3c9c636b (For ppc64le architecture) The image digest is sha256:2efac9327f58a2356a094cad86cc2fa6a1258256a84cbc049adc16bafc7ff845 (For aarch64 architecture) The image digest is sha256:6033ead0c6171aff24c4b8825d6556ba23aa3f176883d705896056f93191083d All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2024:1770
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266111
- externalhttps://issues.redhat.com/browse/OCPBUGS-26208
- externalhttps://issues.redhat.com/browse/OCPBUGS-26542
- externalhttps://issues.redhat.com/browse/OCPBUGS-28731
- externalhttps://issues.redhat.com/browse/OCPBUGS-30215
- externalhttps://issues.redhat.com/browse/OCPBUGS-30621
- externalhttps://issues.redhat.com/browse/OCPBUGS-30757
- externalhttps://issues.redhat.com/browse/OCPBUGS-30810
- externalhttps://issues.redhat.com/browse/OCPBUGS-30822
- externalhttps://issues.redhat.com/browse/OCPBUGS-30877
- externalhttps://issues.redhat.com/browse/OCPBUGS-30884
- externalhttps://issues.redhat.com/browse/OCPBUGS-30922
- externalhttps://issues.redhat.com/browse/OCPBUGS-30927
- externalhttps://issues.redhat.com/browse/OCPBUGS-31064
- externalhttps://issues.redhat.com/browse/OCPBUGS-31105
- externalhttps://issues.redhat.com/browse/OCPBUGS-31284
- externalhttps://issues.redhat.com/browse/OCPBUGS-31383
- externalhttps://issues.redhat.com/browse/OCPBUGS-31426
- externalhttps://issues.redhat.com/browse/OCPBUGS-31464
- externalhttps://issues.redhat.com/browse/OCPBUGS-31604
- externalhttps://issues.redhat.com/browse/OCPBUGS-31751
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1770.json