Red Hat Security Advisory: OpenShift Container Platform 4.12.60 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-21708 — graphql-go: Denial of service via stack overflow panics CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-28180 — jose-go: improper handling of highly compressed data
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:0bf42879aa97863bec86cc9fe3bba46c3d70c8aa72362e8bf7b3dd0fb9b6454d_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:a0a3c4b87aca731597c177dbb5559e33a884941ccf66b3cf587f5e3e50c082fe_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:ba8cce4aa318298eba106200c5a1338f7008a928c7ddeb506dad9624b37fa2ae_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:ea737a34fcbcb3d17a2686676c3ecbfd063066c36d8a96ff8e56301c2b140950_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:3d6197315cb3d2dba1c2723248b20f467fb652af63d927154ad7add6948b40b8_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:40f0d74709e864e0654bfe6afce7a7cddcf062a2874629467b6477d8c06229eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:48e697e2a08800e4dfb570acc99b9a9a608bb5e0d449f8b5227e8736f8665edc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:9082040c7b740f3ee77cde8b6688a15994615cfaafc42ef9bd6ff00c3bd76860_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:0069fbf81d4f86181982c046446199453cafcd313f4ef11287d62455841ce9b3_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:0c2600a0f3aeb6938476e1ddb162b32a7a8d27fd02966b17ad9873ae2bf63662_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:775a8b7f2b2a3db3cd6ced8c9c2f691e22d097e65132b28d7fc77f47f9cf42a3_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:cb86e6814d6c717755a7d25e8ffa6f54a7c508306d30d37def58b2bc44ad8f5c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:0e8f31630120b4bceec8ebd11422be47fab7a8720365e19df7ca3f1208ea4d18_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:80ebab7de26e5a628b69f122133ecde228c57c346d7a0b03d670f615bf6925fc_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:ae14544fee95a499461e07f5509991485f9d19aae74edaa215be423a3d1866c0_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:c200b6a1258d2fc47417222b81b4cbb2ce7c79588da8026a15b2ee402c842997_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:48f8913b1e13224e3e5e2b55228c2ea1ae0357387528e75887e79d4edb18df83_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:6f4a0e1b5cf42114826c8ce65d98a822d65c58ecb92f1f964e59799e8f9206c2_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:af5c5aecc0593c82060ff3d514011cfd9a453a918156a494ba0a49d6490c955f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:fb318b617d365353011f263aaeda38bc1610d3c1ad875dcd6488b8322143d4db_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:c2d950aaa41c8b434bc909d0c1e1586462c8b79c202eb3461eb9b109a8a1761c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:32a0d255b6c552e323089e3c7cbc80e659f3028ac220a240af333649ccc0b3db_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:587f69742a88631f84cffe21860f712a3da54315e692c3a31190d9a11181ea83_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:5adcf0727b213cd65d22f6a0cee5c3d785087d2f94feb657a96361884f7f9454_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:eb8a20efdb7848904f1fae8a4cb664121b748a0b04db6d51fe31cf5ac7f1caf6_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:013b7f09b7f1a1a4385394cc24d18af8146c1069e872332dbdca7d581eebefe0_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3dac511dca7b6b659cb1b91516014d76511d450c7e81ea1bca478154c3592b33_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:82880b3e527f371c8d2d2f6985c855eb40e98a979e152e9a4ffeacf422cd7430_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:deddf5defa4e17a66c3b9c0d2c901111591b92b8a6db139623b6b3ebc8f28378_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:22174072f8aaef46f80bded25d5a2bdfa6fd8bb01fc5242a07e550f132cafc5a (For s390x architecture) The image digest is sha256:7704b30376a598a9f532e2883c1d1de6927384665de2bb2120f4abb54ffaa063 (For ppc64le architecture) The image digest is sha256:879bf487996ec676e7376773724b57b3e29e43c35643ad5c591f03cc89cbdf47 (For aarch64 architecture) The image digest is sha256:5fef7bbd0d0d5f17269de502bf37315d9e1e8d2d95da9a5d654f807029280d75 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:4006
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2045014
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://issues.redhat.com/browse/OCPBUGS-33432
- externalhttps://issues.redhat.com/browse/OCPBUGS-34845
- externalhttps://issues.redhat.com/browse/OCPBUGS-35027
- externalhttps://issues.redhat.com/browse/OCPBUGS-35242
- externalhttps://issues.redhat.com/browse/OCPBUGS-35304
- externalhttps://issues.redhat.com/browse/OCPBUGS-35421
- externalhttps://issues.redhat.com/browse/OCPBUGS-35558
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4006.json