Red Hat Security Advisory: OpenShift Container Platform 4.14.32 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-5037 — openshift/telemeter: iss check during JWT authentication can be bypassed
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:0ca02133033b35c9f5be0b7afeb4c0deb68416b883347ae459fbbb0b24e10364_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:17fe48872fde5b6713bd16c14fab7454fac77b3126f5178b4fd06ffb425cf825_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:68da5c0f54d1736b84284552831959d728f11e454c5dbaba6994204baaa0c483_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:d3ec213c76157586f3b960da1c77efb665ff2281efa8e9b451371a65f07844c5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:3ca8918e6d302917ae9aed04eaee70fba1637c42c604dd3ae1817477664c8c4b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:4021cc266db00e673d2d6963288b1a4a29cd20b5cbc938dc2617fafd168efe88_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:922d7766eb508aaa8ce42422df0b00393d07b578c613688a7b52cab4f97b859c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:c8278adf14b1bb65b53d061e092c524049439de1e305968a4a277141184d6814_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:04c479f0ec13854ac90ad6db5256c3deb073e5672685383bc464d9b543030168_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:874f7cf71b80129117e7a726000caa8d2f23db79891295c645b8bfe95d9f638a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:ba289952f212e425d60f2eb050ff41629f17c8d5277dbb6cdd3f206ae4691997_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:daca00c953599a0b6706235f0a4feba2610810f57d10c74da929fa589e1fe3f4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:3face4f6a1aa8bb51b61c0038a7fec7ca39a277f27b2dc16474eb40206e2d21c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:697f21689cc6b94f20a8f884b8594fb8b243164651724b50f3fc10ba1866ab47_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:aa6f19d1083e04b841f591ef4777b9516f87cdc35acd74396fdf9047a1ff2e31_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:c3668f45d77e81b776b7ee55fe3ece8fdd27a064b9c18e36de05bd0750a2b9a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:649ea85f362ad5ce632460a90f485aacc5fe77dbc8b516575df670bda126de7b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:c26b1c5075902c3987e6eae2f523bff48d89fdf77edc15fdba5dc5113acf8d5a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:e25e6d8d4a5507123d920aa6449e13d38448714cf822a2ae69f4145e66eb7250_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:e9b6c7c3572f244c487f16bdb62b3930d10efa079ad21054ab02e3be09ea283c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:131b62d34d6fac57d08ad435efd0d1e428a6c718a4579cd58401bdd6921b8e34_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:53a5d472f602ccbd1c33cf69e2281d0253f9b3a1e3ae898211a0a88b8804a499_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:f86f64a8a1282ab0b9ecd41727210f5e0e97d9dcc5c71c74bf9486ec5c4652b2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:ff6b6a14a8ff3e010b40baad82a9a2092309be85280f15e4ad7463c8c5121536_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:24d564df7808d533320d6826caad7eaf82b4e12b2b5d2fabcc2ad5fc9198dacd_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:26354f91a5f17c87029789b5729e1c5bda7e3f1794e521e907eee8502fa519ed_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:9a196c711d0c52cb188fc7690e1008dee21717b3a2134915b4913717516984c3_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e4a8532edba2c74652adb4fc52f6d0923013fe6f955ae946ef94a4cc7a33b323_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:2ea912c7eea611307066e207648b39bab131f247601e345342fba203b0e1e07b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:912d7c15e1d82ffc4aa1fc34d2b64c4c7b6670ecd11314c14ca2d6ffdcea22a3 (For s390x architecture) The image digest is sha256:c32644f572297e736d768d7bc3046e1e0bd1f5f210cff02f12e64bdfb3710ff7 (For ppc64le architecture) The image digest is sha256:9d2a77eb45f1c1785296d755de2c74e032891358818205ecaf185f39e64d3312 (For aarch64 architecture) The image digest is sha256:534f13d4930731691f09aec733ec80a6810aea908224d0384ac181e6c3a81144 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2024:4329
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272339
- externalhttps://issues.redhat.com/browse/OCPBUGS-30259
- externalhttps://issues.redhat.com/browse/OCPBUGS-32472
- externalhttps://issues.redhat.com/browse/OCPBUGS-33942
- externalhttps://issues.redhat.com/browse/OCPBUGS-33964
- externalhttps://issues.redhat.com/browse/OCPBUGS-34885
- externalhttps://issues.redhat.com/browse/OCPBUGS-35012
- externalhttps://issues.redhat.com/browse/OCPBUGS-35183
- externalhttps://issues.redhat.com/browse/OCPBUGS-35290
- externalhttps://issues.redhat.com/browse/OCPBUGS-35365
- externalhttps://issues.redhat.com/browse/OCPBUGS-35401
- externalhttps://issues.redhat.com/browse/OCPBUGS-35475
- externalhttps://issues.redhat.com/browse/OCPBUGS-35482
- externalhttps://issues.redhat.com/browse/OCPBUGS-35520
- externalhttps://issues.redhat.com/browse/OCPBUGS-35549
- externalhttps://issues.redhat.com/browse/OCPBUGS-35553
- externalhttps://issues.redhat.com/browse/OCPBUGS-35723
- externalhttps://issues.redhat.com/browse/OCPBUGS-35750
- externalhttps://issues.redhat.com/browse/OCPBUGS-35826
- externalhttps://issues.redhat.com/browse/OCPBUGS-35827
- externalhttps://issues.redhat.com/browse/OCPBUGS-35877
- externalhttps://issues.redhat.com/browse/OCPBUGS-35889
- externalhttps://issues.redhat.com/browse/OCPBUGS-35913
- externalhttps://issues.redhat.com/browse/OCPBUGS-35957
- externalhttps://issues.redhat.com/browse/OCPBUGS-35989
- externalhttps://issues.redhat.com/browse/OCPBUGS-36356
- externalhttps://issues.redhat.com/browse/OCPBUGS-36369
- externalhttps://issues.redhat.com/browse/OCPBUGS-36416
- externalhttps://issues.redhat.com/browse/OCPBUGS-36464
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4329.json