Red Hat Security Advisory: OpenShift Container Platform 4.12.61 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:5e83ee865c4ed01e5082cb27a106ed389d0b248955e5736186864a304cf29f7e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:6db5a75d3b84e1b213855994fdc8f8724d3adb6353c7ce0561d8b3f4a3f50287_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:85abb972970445bf4a3cd57da2465a361940e556f9a5bf8a479f90f21b349ac0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:ab9dd626ad3c8a50004414b1f192ab9bd0066fb5381e2264bd725ef22ed5842c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:65fb65540b36f7409beb33484d419586c797b703c28b87b9fc1dfe570e41f351_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:d620916cbc7cd74a3260f8d197b5c096ab0681d0b1713b3cb002e5094613af72_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:e989c2802e31b3592b78ad1655b2744c8b486a2be1e01bc79e1d5ec3d3bd2562_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:ff5646b889d602ae6504f41230fef4a9a5b3f53957d31a9c1838a0c8d4729b4e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:4d47d1c318dff8d0693afcc97b9b4e154d0fe07b9be27a593d39c20f5335e2b4_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:7a4158a5a03507fc2b6704d12d6cd7bf2c307cf34751c3dfa575a88e518c994f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:b82a5fc24ae84e4d8662195421c693209b0fde91d0cbc0c1f8c42332be03fd05_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:ef08e9f8fa44680969c8b4b0d89c1efe209141465e7860e52906567ce8e419c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:2e8d5dad099a00b1b3d73a209acf5f36d2b257e6db11507e65a34dc09aeb545b_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:5f51ccad20c20f9009aa6dc229f66b314fac9669e67f05ac61380d6c779c57f7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:b0ff491e0aeac78706264e7452a8abf8e723716ec5c7ca36d6d561df92a07857_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:cf998295e34c9d44e655ec391662c2a9944275fbf0225900d3656f3d8f45270e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:1d2b1a558e23caad7f9f112cf3d1abd1655ab4961b034813657ab5d7496dd31e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:6636c9a9822bf2ed529aa87fcee1a138740a0813443d3bb1fb869b543b128f22_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:8aea9906b9dfa488078a34c2cf61d6bd31580e9a489d4b1aaf390c6ec148f68b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:8b29123f9912ed8c2ba1713a23bd84794fd1fc74cc45649ab282478c5eca65d2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:7240b61a50ce754f7a32141267981a47cd25a60d671fff9f33e5ac989c1d1b6c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:09b853b385cc341cb050d55c0f1ea593759f304dd9c13e61b9184cd067bbec93_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:68603294cfd1eb196756c0945b1d7b5a28a4f04c9697dca97d7872ec8c821caa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:70db76eea86acbea5febb9cd69a587fef71796052d18c12301009f6ca8e2ef2f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:e1d88f907422906c4f63210cb7d1be729c90f3400f771d86a2ebf1f3120d4e30_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:329a1e02733cd23e5d7c0e184d5ccf21bb9e94629ee91516711973b00fc097d1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4336a0974d929b82707c607971b946d76f689434ff810470b051e88ce865fd3e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:ac07bb5e8c7d280479ac6d8ab87b1ea4f701a40f01e1c2ddb2de335dbdceac07_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:ee96fef0304c478d142d4fa5dfa45049454ca53355d89f0ea5bc5db7d4c503f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:faa201ea7790bb101de7b9b6f01543136e8c589463b8437a10678da0cdd0197a (For s390x architecture) The image digest is sha256:787a9332c028eb973d5f8ac07318cc000e8dc85e1649bd235fbd813929a98438 (For ppc64le architecture) The image digest is sha256:3afaa5013a09558d7169bb11c0d114dc97f978cb7c3c131526ec796f6fa4bb77 (For aarch64 architecture) The image digest is sha256:490ac0af98efc201ea0bf58e9f0f699a37452c4a84a1e75ab8f4040f02426c3e All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:4677
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://issues.redhat.com/browse/OCPBUGS-22981
- externalhttps://issues.redhat.com/browse/OCPBUGS-34933
- externalhttps://issues.redhat.com/browse/OCPBUGS-35501
- externalhttps://issues.redhat.com/browse/OCPBUGS-36148
- externalhttps://issues.redhat.com/browse/OCPBUGS-36179
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4677.json