Red Hat Security Advisory: OpenShift Container Platform 4.13.45 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-5037 — openshift/telemeter: iss check during JWT authentication can be bypassed CVE-2024-6387 — openssh: regreSSHion - race condition in SSH allows RCE/DoS CVE-2024-28180 — jose-go: improper handling of highly compressed data
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:035b69cc5c4b61aee1f57de65f50dca2179c8b6e9191d2877cf2fc50008424ed_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:0c38d562748f139d3dc2402b6ef4cf82862add63ec6f35929e449501bb844131_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:10b82eb71df582b8588348d401e983816807ee10c48ab3df7115677eaf006133_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:8f130f6d2690f6dd4b5230532759bb876eba7f8b390e2a6c95894fe71506b7bb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:5162c36b6bc2158c79f205e9ce30788c052389f23d9afae689bc888853f90b07_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:adaf786fab33af1838b0874485661021e7f4611fd6856070b44081c9dcf1b6bf_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:d20ca9e61d40867cf1570350e5ccda3685931b91f30aba0e16a8bc3569f73c2d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:eabfdaad667f8dd3fbd8265d5387201a0dcadc0a07a101374ffdd68fbb187c2a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:0be9a8a784c75b39dd2a3557f1f22710b012fe332612de482c831f6c0c33c13d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:73eaf30cbb5935d189704c34b49b4dec9807db6b20232229ae3f49898d44b8f8_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:dae4ec54413b8d214a28c7c8ca7e8d3807c6c8697d6aa09410d615f92cc52efc_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:de881f75932a331cefac7724835a0afb9b06d915edb2c20db914ffd9b03068b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:0cb8c963f079d93685d4b11b7e1d09697cc4496a275628d5405723005a384947_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:4d88f5df6e8b6e1cf5a68dd9917bcc3ef95535efab37d971a472fddc9aef51f3_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:ccdffdb4abcec99878704f2793660bf4875cae55385b2d6c5ff04f82d390468e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:dd685a7c94957e2ceee56335ed57641b6169d5d746a9950106c84ee15bb3646f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:59d25ee4f718068857e1ee1fa3176c256a93c07f85c28a61c2d69dce689d3583_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:902ed980684e40822a9dd6338bfd29e318a63f25080dbd3d406f6819ce6d869e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:a9bc0232a18227071abbb39db1dadacf8c0c3f4c7b89417e83b9fbcf18bb28d4_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:dd7934cbe7a4e7bfad70a5879ea6ae66b3cdee538552a6e880a1f1cb22d4fe9b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:abb107cb2017b78fedeb8a014dc31c263e9b52b1b43ee6cf079c21ed1d17c03e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:21ef6953b633c5b7c435440751c9d752e228f2950cc3c9d0a86cc10252fd6c95_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:64538d01843150b290261032db558c72320e5ef1ce7d539929cea684ffcd0b27_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:9362befbfa2a81335ae60844dfa985968d309fa35fdfb9598e16868b5b7ed3c7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:e1889f04b3b35b6e5eeb0812d50665bab3987a9ef656de6a4d0c489aad7bbf4e_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:0466df2b412cc1824423b14b51a857dd0027dcdf614c94ad35fe6f4d0dc371d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1eb805ccd537995d96184c336a8b522f7a0d1164d5dfe470d0d6382731506caa_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:7f90b23035687fa78fc28716b7b1e060dd3530bf0237489b616d49a9a183e546_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:83060edbfd3533e5f034ec3a09e929a450e9a84b666fffc0a30dda94f1a3f0de_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:c7e3658ca8f0f1fc8ce1512ecc36785a68b1388dfbfc39642bff8120bfa86a33 (For s390x architecture) The image digest is sha256:71641ec665a81c7228ac2254ae30899ee68bef872653c807dc34dede0cfe91b8 (For ppc64le architecture) The image digest is sha256:a71a1339e4304715cb0957a5db2777fd6e626420ba252af8b47445bcbfaac655 (For aarch64 architecture) The image digest is sha256:4f08ad2deadb6731ebd82ae924c47d06c0c162bb57914e1f287f9c0c68e9838a All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: The below process can protect against a Remote Code Execution attack by disabling the LoginGraceTime parameter on Red Hat Enterprise Linux 9. However, the sshd server is still vulnerable to a Denial of Service if an attacker exhausts all the connections. 1) As root user, open the /etc/ssh/sshd_config 2) Add or edit the parameter configuration: ~~~ LoginGraceTime 0 ~~~ 3) Save and close the file 4) Restart the sshd daemon: ~~~ systemctl restart sshd.service ~~~ Setting LoginGraceTime to 0 disables the SSHD server's ability to drop connections if authentication is not completed within the specified timeout. If this mitigation is implemented, it is highly recommended to use a tool like 'fail2ban' alongside a firewall to monitor log files and manage connections appropriately. If any of the mitigations mentioned above is used, please note that the removal of LoginGraceTime parameter from sshd_config is not automatic when the updated package is installed. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2024:4484
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294604
- externalhttps://issues.redhat.com/browse/OCPBUGS-32015
- externalhttps://issues.redhat.com/browse/OCPBUGS-34422
- externalhttps://issues.redhat.com/browse/OCPBUGS-35077
- externalhttps://issues.redhat.com/browse/OCPBUGS-35380
- externalhttps://issues.redhat.com/browse/OCPBUGS-35562
- externalhttps://issues.redhat.com/browse/OCPBUGS-35857
- externalhttps://issues.redhat.com/browse/OCPBUGS-35976
- externalhttps://issues.redhat.com/browse/OCPBUGS-35990
- externalhttps://issues.redhat.com/browse/OCPBUGS-36501
- externalhttps://issues.redhat.com/browse/OCPBUGS-36551
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4484.json