Red Hat Security Advisory: OpenShift Container Platform 4.16.3 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6387 — openssh: regreSSHion - race condition in SSH allows RCE/DoS
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:2e754e01be6e3c64f16f5548ba5fd99314882765f0c7a3039e7af43f3e92f5df_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:7693d35e30bb5ed18fda3ab6880c0b5ba258cd34df61301f003125ad52c07260_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:b2d7838a12ed8ef812a0c40cd03374af08662e65cfdfad045d1e2239a4124663_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:c6d891a946a83f947e131221f42b1f751e30ed424d40bee0d6ad90c1f8d7fa27_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:5d7c1936313ec0088ade774681915ce07e1972ba79fec436adcf5c43203ee3e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:85953d9a2105ed8ae080e3bace5966dc06ee4b041d1038c3ba8b002fc26b8296_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:8920af697acaa1c0fa7e169d7b85caf80bdebb9fe4cb03bcae63704bbc85f2f1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:d5b1aa9b28c6c91c60d21c2c046822485642f7fd97455ff9120ce9c3706ce75c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:0969481e491eacd951b64a6f8d44af244e016464770c6bb25fa980751a0f27fe_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:63920164c27a442c6584d902d4dba13f0649cf971343cc1ad7efd366a0cd6bb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:68e6603a68df7bf661761330bfe3fd1ba6d4602429a18c73792af7a610a8f0e0_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:975c696f7db063f3891f1b84ae6b119b4d0aa7527db4b7f16b408def705b9a89_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:71db7add29eb8fff6ad3f460a58b2b14a6956b9fd8f3bf121dbd96ec483e57aa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:9d5e3434e145834f4402266f006bd0d684fb3d75d437fc06cf6538d2242f190a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:c74021403b36e60b57479ca0124e743e68ada75cba8577a1cc0b990eeb378447_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:d3fa76edd883616c57d11673f51c31f0aa76106f2d8c65da5bd246e5f038f484_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:70979d39af315ae689f54b6adee6c7d3b03e8c5dae1bafe0f6e847ffd97bd12c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:a73204d0c03454b02656801ca4c49cb2d8b0d54645bb90f74622df335c82dce1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:ba5feb1c4a3ebb1220c923312a4cf63331894f2ddf7754d1c241f638ff125d1f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:e28959afa9309adffa44549e29b115ea4b1d9c04208d2bf2d43a49798b6acfee_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:08faf34ad99d34eead0e16c425ecf8294b6840b8ce16f22df0d6bde21608933a_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:1c77204f8ef3961e4f77cb9b61b6032fbc3078c81440193d2da7cf90154f4934_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:4d7437098608e8793f1a09e3e125f0a327e1f96cb98740960a50224204fa2540_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:d3e3f52b571e31197f4272b2d1460bbe464591a08881ce93d724b2541efbbd5a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:1dd880696a8a53633044b42b05973f9d25d678a6e8e59168e60a844cd432e8ae_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:7a9f58cf60081c40503b023e7df764c8936bcc9fded90d990b8439d037ed85d5_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:b9ae6cde773f404daae603ab57e01264bc911f0a3e4f743bf45963d9cd51c0cd_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:ef5add2ea67a14f6767713ee4852d9733e404fe861067806faacb89b6d95d1a7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:84ece705f99ec839fa6a9bde1f43a7a5af2dfdd9960a21432e13b9a669ecd45e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:3ec3a43ded1decc18134e5677f56037d8929f4442930f5d1156e7a77cdf1b9b3 (For s390x architecture) The image digest is sha256:9b9bebfa88de4b930fdc0bbbe1b30baf35e6d732bd273977c6c46ac825ddc629 (For ppc64le architecture) The image digest is sha256:61d47638d63f8ba8bca42b12dfafb7bd8aa9fcb2d7e39d0ccf87f5e571a560db (For aarch64 architecture) The image digest is sha256:c33c0068a3cec747bcbac401a5fbcd6c9611f34e624b640da4378d40d8a48a89 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The below process can protect against a Remote Code Execution attack by disabling the LoginGraceTime parameter on Red Hat Enterprise Linux 9. However, the sshd server is still vulnerable to a Denial of Service if an attacker exhausts all the connections. 1) As root user, open the /etc/ssh/sshd_config 2) Add or edit the parameter configuration: ~~~ LoginGraceTime 0 ~~~ 3) Save and close the file 4) Restart the sshd daemon: ~~~ systemctl restart sshd.service ~~~ Setting LoginGraceTime to 0 disables the SSHD server's ability to drop connections if authentication is not completed within the specified timeout. If this mitigation is implemented, it is highly recommended to use a tool like 'fail2ban' alongside a firewall to monitor log files and manage connections appropriately. If any of the mitigations mentioned above is used, please note that the removal of LoginGraceTime parameter from sshd_config is not automatic when the updated package is installed.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2024:4469
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://issues.redhat.com/browse/OCPBUGS-33788
- externalhttps://issues.redhat.com/browse/OCPBUGS-34979
- externalhttps://issues.redhat.com/browse/OCPBUGS-35298
- externalhttps://issues.redhat.com/browse/OCPBUGS-35730
- externalhttps://issues.redhat.com/browse/OCPBUGS-35831
- externalhttps://issues.redhat.com/browse/OCPBUGS-36137
- externalhttps://issues.redhat.com/browse/OCPBUGS-36182
- externalhttps://issues.redhat.com/browse/OCPBUGS-36324
- externalhttps://issues.redhat.com/browse/OCPBUGS-36328
- externalhttps://issues.redhat.com/browse/OCPBUGS-36330
- externalhttps://issues.redhat.com/browse/OCPBUGS-36341
- externalhttps://issues.redhat.com/browse/OCPBUGS-36358
- externalhttps://issues.redhat.com/browse/OCPBUGS-36386
- externalhttps://issues.redhat.com/browse/OCPBUGS-36435
- externalhttps://issues.redhat.com/browse/OCPBUGS-36447
- externalhttps://issues.redhat.com/browse/OCPBUGS-36482
- externalhttps://issues.redhat.com/browse/OCPBUGS-36486
- externalhttps://issues.redhat.com/browse/OCPBUGS-36536
- externalhttps://issues.redhat.com/browse/OCPBUGS-36607
- externalhttps://issues.redhat.com/browse/OCPBUGS-36701
- externalhttps://issues.redhat.com/browse/OCPBUGS-36717
- externalhttps://issues.redhat.com/browse/OCPBUGS-36746
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4469.json