Red Hat Security Advisory: OpenShift Container Platform 4.14.24 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-31463 — ironic-image: Unauthenticated local access to Ironic API
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:9a8f7f22ae8b6a430616a2cefead0b68fc384bdea224edc53a86501f249198f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:d37e01650dc2bcfb8ddfb18e82ddeb3408ed5ce476822729acf1ae5371359c42_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:d3bfb1990bb15591e45d940211d604dad5073cc9875378bdac784ae8e0002957_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:e7af07f62a5f79c8a6a5f782e49f565dba59d4b1e41c560e0bb38178afecd51a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:471eade5294bbc118d359dacbf6eedc1f6b639492baa76a7d8fc1c1a8f143cf7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7165a8cff4754806cea6b02a9e09ac0c8ea5f21244657da5b9e26aa8281dd3d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:9a5c420920519ffdec7f8f2efaddc1afca6d9b9a1054ca19717140c9f7cb1c5a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:ca69843b0785b7900f1847c549c61154351074020f2324c0925cb31a0a527a52_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:0922934f381a80f2d5c2eefd0277535159a71b6d75767026f2ee9a878b3e603b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:379c3bfa739d67253f4ff5bb449dcda03258c130c6275ae6a930bd36f9b8d879_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:5289603c5fa7929eb91309e23cf7a8e1921995789cfe55e379a26b5c8eb6b1ac_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:8041fee5bc59d89cfd286c4ba209f2d3d6d88e15c390a8dbe4faadb7920498c3_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:3c07c553f7d4a18d0d72abe350f2d6108ee1c0dc36ea35fe80f4c94a76dbe0c5_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:75e91608ceee714579c9d8ca48acf23f58b58a44a9594af440a68883ab80fb35_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:770cd4c5f60a1be05e475fd8ca000f7df50e84b8b7657c008d9c398d4abf39c3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:771d98e0dc4ef513299e47e213d4e0f0d2c5a0d2f30f560602b16ee9fa26d6f8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:1362a8af82e52f0cb218405a801c9c225dee087236703853dc5e0279d26870d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:3c7deb3e05969389d35a641175c8fa9f83225017c1324600862e58c12f24031a_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:764918a6ebafcde1e8a0963243cc7bcdcb2418b697bfba5d88744e983e1ac05f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:ff0e87297ac587e1e37b05bb0769a3f153c2d4ffe7f726f5836692bf9b86d78b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:29d8b109af56634f9e2e9e59c59f050fc6e006be00ff4a8a7090d2f13bcbfe3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:81d264ee5382d092586ffcfc40706e9076fe07f5073ef6b77dbfe56ef6d95a0b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:c2459441717c862bd6f9fd61ccc34047b0d54395167032ace10f9b43d68b71ed_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:c38d65a06f72255f8b4f06d9e2f9327772a75a4f97833fe46fbe1b01af9f2152_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:058ebd72de147704218fb08362cce99166c6b6f40210a33a9041b47d1d35f817_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:93c0ec15df2c2d58a0c3039849935968715702b1bfe61956f3636221af5cce10_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d587568a9d4068a84b6bbf2d90e6b44df669a81e89aaea3a3e6029eb6e19bb84_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:faeb1179a2029a5d299e62e8d51267fc172d951f99fd30ebf2102a03fa864047_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:04662d6c9410457e8e6bb89fdc71788663239797bc77297533433722da0d8d1d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:0a34eac4b834e67f1bca94493c237e307be2c0eae7b8956d4d8ef1c0c462c7b0 (For s390x architecture) The image digest is sha256:21de2e8f55e480b0d2955847888ccd82949bb1ded5009261ab774f0c9063e53a (For ppc64le architecture) The image digest is sha256:6db0ba6638f3b2a758fb9806b42883604f2691923128f3f976f18fa60f7e79cd (For aarch64 architecture) The image digest is sha256:e7a33cdb4085fef0d406f77a9ab33d633d07ff78e8d8c24028f0784316e45886 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Below are two mitigations for this vulnerability: 1. Switch to using unix sockets for traffic between HTTPD and Ironic/Inspector (recommended). Set the variables IRONIC_PRIVATE_PORT and IRONIC_INSPECTOR_PRIVATE_PORT to the value unix. OR 2. Temporarily stop using the reverse proxy mode (set IRONIC_REVERSE_PROXY_SETUP and INSPECTOR_REVERSE_PROXY_SETUP to false).
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:2668
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275847
- externalhttps://issues.redhat.com/browse/OCPBUGS-20173
- externalhttps://issues.redhat.com/browse/OCPBUGS-21799
- externalhttps://issues.redhat.com/browse/OCPBUGS-31756
- externalhttps://issues.redhat.com/browse/OCPBUGS-31857
- externalhttps://issues.redhat.com/browse/OCPBUGS-32168
- externalhttps://issues.redhat.com/browse/OCPBUGS-32169
- externalhttps://issues.redhat.com/browse/OCPBUGS-32170
- externalhttps://issues.redhat.com/browse/OCPBUGS-32343
- externalhttps://issues.redhat.com/browse/OCPBUGS-32471
- externalhttps://issues.redhat.com/browse/OCPBUGS-33010
- externalhttps://issues.redhat.com/browse/OCPBUGS-33066
- externalhttps://issues.redhat.com/browse/OCPBUGS-33105
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2668.json