Red Hat Security Advisory: OpenShift Container Platform 4.15.20 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-5037 — openshift/telemeter: iss check during JWT authentication can be bypassed
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:0d42014b7984537609ec47cc560f1ec414476b74b881144bda1dc7a8567c8d4a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:44665a7687ef9fe33714725682875aecb86add22d3c25923060d32c5df9edd01_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:7744ecc7f352679916f3392f7d2eeeeefd9c9331c96dac43fb9ad76ae56041c6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:9bb0421c20ae2164a653ff64bff26b6ed3fac13bab625d2ab61aa9cb2fe97ed5_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:117c3c696eefec638c58f4ca8e5b156add06914e854da3b05aec52268a60621a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:7a889a15b1ecc0d448d2b88a0ff169b67af0181e349fdb1cc415865441d0aa76_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:856320402a94cab6c80f8870e45d49c4c54fcc96cb7b636dfc633080d2190295_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:9d104de9a46728c8e75fb2df16088e10574d49de6c411fdeb9762a136732e1bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:39845ff6a3a1a6737b1ec1e25eb70a10e6492f1d9ad3e72207d121f73d274f44_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:8a4cfa258c0ff61b48608f8756cf8a4a9c1314862e0301699c6975b5071bb464_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:ad733f6c1c08b610a00c9af5755a7dba1df8bed88911fa3973cc705c09cdad8c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:fd98f5a4aec07ec8cb3243f7b03f13b0f54cddb6bcd3f1464d31ca478417bfd5_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:334097fc47edc8183acfd2f569c4c516e4e080bcea92a2975b194ee40056c2e3_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:84480353a5a00797b46c32342116c10a0b7d9ab45796fa04aba36bdb6f762c44_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:c19f188dd14b263b95f0b4b60db0d7e342f2bb10a893f1b2ad198517ada2c6fb_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:c73b4f4e65bbac797406615e9d17a8b96652c18583ec593233266fe149139c2d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:1851b2287f3d63a63bd18d0f67812943447b29caf1b0760437d0be587222d543_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:3743d9c99e1259e6182446ca10af3784fa14bee0e09da3432fd4741d8854d5a3_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:5cc622c2d7ddefe7e37bb2b8d04117b3a3439606ce1a14ea098534e82e7e8a72_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:bd9ad4b349dd1210cbb0bb7db44b2148e56051ef274a10aa76df8616b57e3278_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:2bea0d1aa02ab76a0c0441c109cfd4e30e5f114e93a1280ee4f600b84ec0c6cf_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:33f5d26f23c73f5dc94c6d3a5171b1dea8b2706910008a6079def1389ddc3b22_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:9f6eb62ef2891129fb7a4a179c93c7f289522372ce4c788585e0ffa0464d7581_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:fe9463ce081f86c43facb2a0a29642c1e8752f53d57d5148a7a5c31d65efc9e2_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:497bdb9a6b3b295dedcb0e7f68ca5c7105fd4826fe2ee27184faf66b69534d60_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:5aaa0fdbe5c46f1052b746220a59925619b3e405617d4480562620a253b7fa48_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:85d84d80ff7520fb040b260105a749da27b2aa418e7fa0454315587f16fd0669_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:af1bfc660827637eb78fdf9d33880901c339d6b60cba48cbfa38e4e0335c405f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:419166ad13c3824e5338100a210800bdc92db2ab2fb5dbab75668ba0c781b04d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:478d9f5a1b496ebd69ecd0d7a7fc961f6318290ac9242ff65e1e2bdb88ff3097 (For s390x architecture) The image digest is sha256:0792d79ae4e5428851e387b00695934d90c2dfeadff5b05ac7979ebe83e1a127 (For ppc64le architecture) The image digest is sha256:83daa09f3de75c73d8167c4c40f22c28562e07d645682abbbaf9b4963c7ff614 (For aarch64 architecture) The image digest is sha256:739580c2175f81df210310042e4fd1395344990d96a39498e1df919df7bb97ee All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2024:4151
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272339
- externalhttps://issues.redhat.com/browse/OCPBUGS-32404
- externalhttps://issues.redhat.com/browse/OCPBUGS-32501
- externalhttps://issues.redhat.com/browse/OCPBUGS-33642
- externalhttps://issues.redhat.com/browse/OCPBUGS-33885
- externalhttps://issues.redhat.com/browse/OCPBUGS-34478
- externalhttps://issues.redhat.com/browse/OCPBUGS-34579
- externalhttps://issues.redhat.com/browse/OCPBUGS-35305
- externalhttps://issues.redhat.com/browse/OCPBUGS-35359
- externalhttps://issues.redhat.com/browse/OCPBUGS-35543
- externalhttps://issues.redhat.com/browse/OCPBUGS-35714
- externalhttps://issues.redhat.com/browse/OCPBUGS-35732
- externalhttps://issues.redhat.com/browse/OCPBUGS-35865
- externalhttps://issues.redhat.com/browse/OCPBUGS-35872
- externalhttps://issues.redhat.com/browse/OCPBUGS-35894
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4151.json