Red Hat Security Advisory: OpenShift Virtualization 4.15.3 Images security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🎯 Affected products101
- CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-controller-rhel9@sha256:be8aaffd692155376dc71302b292f98be2697f20e133a7e4aa910f7d502280e0_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-controller-rhel9@sha256:fa15bb8ee3042a0b98405ef5099b31f9d26470d67013eecc5e5657ab4a027680_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-operator-rhel9@sha256:b2165499a8e494ef0943ea72dc7bb5d2282d684c507ec6611310eae4bdce1c6d_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-operator-rhel9@sha256:c89a1682bc2f52ff7d71a67c6da63f96a41dbd83852563734a05dfbf31d4266e_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-server-rhel9@sha256:152d04fd37b31d03f1070b09966f43c7ecb2eb7744fc1e0e88f29d15ef43ae82_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-server-rhel9@sha256:56bf91538dbbcd28ab584cc161a94e18eb0ac83002e20f841fc1876e2bf6b792_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:0ab580d3e2ddb969296793ae6a3ad2c11f512bac76be56b6d9b041bc7c23f5f1_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:ca1067ec4e88602d53d041745719f6e570cc710dddbc8e2b6a2347189d16b694_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:26c996a4855c023531045671808f206070ac90ac3db0511c898fb7c9c43124d3_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:e30f9baa031f91246eb283d363887d86382f8f5b7fa1c06697d87d3c74b4ce27_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:2aaa5b8701d91a116e3d83fc481332e4d7af013b40333343003b49cecb0d0277_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:d7f0bcfe873dc94e2e79e7dd6d64afd815a2a9a0c02a8dfa84c8f22ff968ede5_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:3078deddd258d3f833526784c66f5f6eb0fc7ece6fb20c61e0b7806282748d3e_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:ea31b322cb8799856016c128da8edc5af588ba63510651cc859f0554c1da7092_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:236275660af638e8f017cd0c0dc028061dd643f7360337a23bdc732601439dcc_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:be006b1a142e3aa28fad8b8e5d6b64e883d7570d5229fbe1456f3d7f46acc1d8_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:2fefe696c18d443a18258980d124d43b2b4f08e8e9d53a28e6d29feb0571c5c5_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:3a99bf810f46005cb1117f9525de10360fccc377e94cd2c18ffb8fcfb38a33fa_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:184f4723a067a8131a5b9575596043b3d859a65ce55cc87a301395b05082957c_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:42f0031dc5fbf7b886b247d898d7299b69caf7da5517a722529b93d74f85aeb1_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:1e33504032b80835ed85348192e116aaf715a83252c1517a1784552d1f3fbfcc_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:26aec76478c65c51bdf56ccee26ddf663edfe1f52cb2ceb0483cc3e794477a9d_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:1057a5ad4dc4a52935416eaacf5dae8d9714b04b024861c32d31a451644809ab_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:704469b60ad76a4703d9152c382f8a4ebdacccf41b1f3639ccbd11b4e98e5919_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:3b47a4a82964f736d5dd33446b80c01369127e1d19ca95097d8f773ae3049ed5_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:a93bc411602546b26caefd0628340167057c0625cdc148ebe70dbde992908195_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:0176f567a5b7859653f715047eace3cbd871cfdb4502ba296eeeaa5e9082a852_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:afb9202935582f3b6848f0ded66818e38030ac073d3a33c488e0a4d2d4df95d0_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:481a4c938db0e385036b7a32c92e8487a724703bb828723ccd5bcd3444191f50_amd64 as a component of CNV 4.15 for RHEL 9
- +71 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2024:4662
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://issues.redhat.com/browse/CNV-28628
- externalhttps://issues.redhat.com/browse/CNV-32985
- externalhttps://issues.redhat.com/browse/CNV-38523
- externalhttps://issues.redhat.com/browse/CNV-38720
- externalhttps://issues.redhat.com/browse/CNV-41449
- externalhttps://issues.redhat.com/browse/CNV-41473
- externalhttps://issues.redhat.com/browse/CNV-41530
- externalhttps://issues.redhat.com/browse/CNV-41949
- externalhttps://issues.redhat.com/browse/CNV-42129
- externalhttps://issues.redhat.com/browse/CNV-42480
- externalhttps://issues.redhat.com/browse/CNV-42483
- externalhttps://issues.redhat.com/browse/CNV-42881
- externalhttps://issues.redhat.com/browse/CNV-43124
- externalhttps://issues.redhat.com/browse/CNV-44559
- externalhttps://issues.redhat.com/browse/CNV-44564
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4662.json