RHSA-2024:4479HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.14.33 bug fix and security update

Published
July 17, 2024
Last Modified
August 18, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6387 — openssh: regreSSHion - race condition in SSH allows RCE/DoS

🎯 Affected products132

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:80df7609da24e67eb10198dcc9f2b65cbcb0203ea1d0ae195fc05dd8ea829a7e_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:a1ac0023fa9ae0837570dbf6cb5c95b20da73b6557d5f402c05ecec4086b8a8e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:de4de39815f9e683e272e4bcc19700c987cca7f60cb9ff4dd6f69e9ed0f666e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:efaaaf6541237d53f8bb1d47186e11403488687ef8761cbb9be1aea8a01ef7ce_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:1b91a9b486b8b1e33dd47c5fde7878564adb92d2e0e00901bf1087f1a72852ed_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:afb57398829df477c9f173637a0cb96ae17d351f9a0e9b0fdf7a5084a3848b39_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:e10d9574845b84149d14abdf8dbd34fecd545d170ed22d5bc18e267d99676a3a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:e4de6ba6cce54d59d253910c65dd315a281bfcdf578ffeea53c6ad7e84f9cd66_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:0d7b7b8d56ad9444e973db1f6d56ceec26aefe516bad1d7fe6d73abf4d9afc59_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:3a4eb576d5ccf5461d51df322d997efc0526a200e3d9b75710564f0edb68a62a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:5b464827218183166b185da2a72be33f92359b536956a6d79fe8e47280e0abe7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:c5fb8ac116a5fdfbb340b2f7352d430baa773a2c50e8f8a8dc711bc9c350653a_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:3629ccaf111c5f932096d7c0a517efb592f4002373bc1ab84b6673bd0fe4152c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:3fe775c6fe3faf2aeb9fbbde34b82f955426a37a86b27fe7610b5c68c74f0902_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:679f6fcd4152256b452589d5faf52b70079d2a4167c94b942b9d6cb9c75e1300_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:968857de5ffc614dde117da9bb4779a22aa3fd0c643005b85bdf7b64b1c7def2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-utils-rhel9@sha256:1bb05d766de56fa8801dbd448aa4ca90be8ed84f8fbace4102a897663bc6c5fa_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-utils-rhel9@sha256:3c166b878b7fec8a6715b85aa021c3ed14b95aa3234b9627fd8e27c38cc7fdd8_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-utils-rhel9@sha256:549bcb4b6c7251d756f47d142ac25f451ea025bd02af12ad90b31b6f4728f805_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-utils-rhel9@sha256:5665b5716a955a186d9c8fa8ea2eb26c10b443e81f1a962d49035fb2b93f1724_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:22149574c1fa105d910e6f082aed94cc3eb48ed1feed5f7b0245e2408c7c9722_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:f728323071be97a5259380b4d74b6770b12e9b01eff7c446db18000a80dfdd55_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-azure-workload-identity-webhook-rhel8@sha256:87b969fe4e4766927d5902e90027ee5450a09f705ad4bfda0195e50cfb7967d5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-azure-workload-identity-webhook-rhel8@sha256:d29421e404513e5911ae4936b1724be794271842a6c1b50dd254dd1f66f86737_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:1d45c36b1ede86b16f946aa21dc4b67fec70faa5fdab3788f7af3108cb29f7c6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:24e8b078e0d99d1241495039befac8cbe95fa24f97f3a05c5ccbb869b43f5f38_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:522d13cf11eea7cae09a8289c89eeef8868686e7f9ab7988b4c4d74068c90e99_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:872ccdc319cec9beb6908a0514a6de10a33dee1b1e0e2ff6526e92587fcc95cc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-image-registry-operator@sha256:08ef705a5b385c28d681d516e00b30853cca22fa6374f74ce4ed9796c7dc0940_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • +102 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:40ba8c540d16a97a6b629232a5a16da64fca655c4b83b734aa28415b5c708acf (For s390x architecture) The image digest is sha256:41509f7d89cfb28d88acc7264e5f63dc929fe15ad4c74a59ce97f92761c15f43 (For ppc64le architecture) The image digest is sha256:f572ab3c129f1440e4fc5d9996011d99d2160b46c1b8f814529fe92aa520f2e4 (For aarch64 architecture) The image digest is sha256:9b6f80b92822336eff876161cafef17100c240da1c1302c84d3816aeae255641 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The below process can protect against a Remote Code Execution attack by disabling the LoginGraceTime parameter on Red Hat Enterprise Linux 9. However, the sshd server is still vulnerable to a Denial of Service if an attacker exhausts all the connections. 1) As root user, open the /etc/ssh/sshd_config 2) Add or edit the parameter configuration: ~~~ LoginGraceTime 0 ~~~ 3) Save and close the file 4) Restart the sshd daemon: ~~~ systemctl restart sshd.service ~~~ Setting LoginGraceTime to 0 disables the SSHD server's ability to drop connections if authentication is not completed within the specified timeout. If this mitigation is implemented, it is highly recommended to use a tool like 'fail2ban' alongside a firewall to monitor log files and manage connections appropriately. If any of the mitigations mentioned above is used, please note that the removal of LoginGraceTime parameter from sshd_config is not automatic when the updated package is installed.

🔗 References (15)