Red Hat Security Advisory: OpenShift Container Platform 4.14.30 packages and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🎯 Affected products129
- Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.s390x as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.src as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.s390x as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.src as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.s390x as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.s390x as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debuginfo-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.s390x as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.s390x as a component of Red Hat OpenShift Container Platform 4.14
- cri-o-debugsource-0:1.27.7-4.rhaos4.14.gitceaac6e.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift-0:4.14.0-202406060308.p0.g7852426.assembly.stream.el8.src as a component of Red Hat OpenShift Container Platform 4.14
- openshift-0:4.14.0-202406060308.p0.g7852426.assembly.stream.el9.src as a component of Red Hat OpenShift Container Platform 4.14
- openshift-hyperkube-0:4.14.0-202406060308.p0.g7852426.assembly.stream.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.14
- +99 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748