Red Hat Security Advisory: OpenShift Container Platform 4.15.19 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-28180 — jose-go: improper handling of highly compressed data
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:a3ee06c325a06aeefd3813430f67fc12e16985fdc783be6fa26f49a3ad9a90bd_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:bc31e4a9ba8423b7e7058a126ebcbff260adfdb781fa5bee12cac226a9f0c5f9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:becd05d58d1140e1a8ad0062354714a29eb6310ac7e2c2303f23ead3a7f360d6_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:f8f4ef2baa17f80cd5fe26f710b1055588a8a53b84c385ffd10724b7041eefae_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:9af82d27b6402b1333edadea55360f612be0ef8cb274bb6969c25594a03f4af2_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:a4a3fa9bf025acbb0a4de5624eb51eb0914b4ce468599bf50767d7eb2f608d87_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:b17979a1418efa71989cdfa57daf611b33de1c5231080a65afe3025c2fce1f96_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:d37a0fd58d82cf599925bfbd2579c6490123dbaa83967514b2fe642e6ed332fc_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:240236ae8c4020dab1479de9ba2837d956a28e0914724275e0b68a62c0c38e41_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:55e40cba290fadafc1b7b420fa7113a2d9299a8b1901a00bd7b233ac54867899_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:6a4ad9809b38984413a78a9b32aec52303c2eaa7519ce21d6d648c02ae2d0ebb_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:86345d4d69b2708eac4b4fcb00ccb830665798e2314e07b23f49e1c64de04ea4_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:184d2ebb3a16c7ea3099d85806018be7ae359275302126582e15d2506ad9e0fd_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:62816602566d5c3c13426873a6f5719a224638967f2703279e001e7003c4af73_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:a0d2f1aab3a3803fb9d45c1f8b25509c5dfcb2995fea40f01b03a49389abbb2c_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:f47ceabd682086fccef4b2218e8c36072f40644f1651d755c3b5044f22024717_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:2cf711ce6c240f7a06478e0e5119afddd89b7ad1dcf54a0111d70d69d39e2669_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:52f29cbcd4c782a65a0806a80a1f3079a522ce5dfd522ebc19bf1f09617f1df9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:85c831f6084bbeef405c1a7e531f0011951583b572c4eb82301508a38dd9f5a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:b926b4e9df718979c9f65e3ff8e670ce231b6259d89b3b8026a1635c7636e0b6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:02489f94627c9f025421484e574a99f277f3c072924c86a4bbee5ff6b88d9e8a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:a025425867e4e55f1829fc9ec263d9e556965f7f0e0f76a248e0abbbbacc1e2c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:c8efed2cb45f330031feb328e8e8fac9aabdf5588f8446877d9fa6ce78f5e291_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:faa8a803eff4ba2c8f32a7f23c8c3baa3575c5209fd60a3b1b0a56dde684cc16_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:15c5d9f78859d5db2d8984f6fd43d397c332659235749bacccf3207c36cfb48f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:1f8f78c57e6d8973135be69fc29abf9289e40b784cb74a7f5c7537db2badb07e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:685efb51a3556d60f1543024a3509cc04b79c071b021a0a0726411d1dfa68509_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:fe1efe087c5d34f11950e81513c76bff5403ac0b94271204347937be30a77f11_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:3bd8b9acc02c679b20a05a30a49f262842164bc1617fb1313b9ebd0183d49481_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:72dbe160063b42a23ba1b97eca3e22d75d0c757947890afaf4b27720c605e648 (For s390x architecture) The image digest is sha256:c4f65581ba78320a3b91af64dba6e138922467d419d3e397076046d86002c7b7 (For ppc64le architecture) The image digest is sha256:6170a9b8125c90fc7dba13c9f96a202745a1bb4bf5622cb41c458ad59cd51df3 (For aarch64 architecture) The image digest is sha256:37adfe2f474cf97f87adc378647591dea9a423e317caa9e8e3c873a5a3185c70 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2024:4041
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://issues.redhat.com/browse/OCPBUGS-29739
- externalhttps://issues.redhat.com/browse/OCPBUGS-31387
- externalhttps://issues.redhat.com/browse/OCPBUGS-33371
- externalhttps://issues.redhat.com/browse/OCPBUGS-33623
- externalhttps://issues.redhat.com/browse/OCPBUGS-33624
- externalhttps://issues.redhat.com/browse/OCPBUGS-33627
- externalhttps://issues.redhat.com/browse/OCPBUGS-33929
- externalhttps://issues.redhat.com/browse/OCPBUGS-34350
- externalhttps://issues.redhat.com/browse/OCPBUGS-34580
- externalhttps://issues.redhat.com/browse/OCPBUGS-34927
- externalhttps://issues.redhat.com/browse/OCPBUGS-34971
- externalhttps://issues.redhat.com/browse/OCPBUGS-35032
- externalhttps://issues.redhat.com/browse/OCPBUGS-35047
- externalhttps://issues.redhat.com/browse/OCPBUGS-35355
- externalhttps://issues.redhat.com/browse/OCPBUGS-35496
- externalhttps://issues.redhat.com/browse/OCPBUGS-35586
- externalhttps://issues.redhat.com/browse/OCPBUGS-35720
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4041.json