Red Hat Security Advisory: OpenShift Container Platform 4.15.23 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-29483 — dnspython: denial of service in stub resolver CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-1394 — golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file
🎯 Affected products149
- Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:411d4fabc93c7e3c3a4f36462cb12078f0124891c3a8831d7229528d93d85859_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:6281053cb7bc6d9d85cc2cf892509c8ecffe8ae48ff4aa62428cc64061e0ee57_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:dbd7a9ebae4efa2661d6812446e1bfefff2cde3cb2c9338c97ce7eb8a60be690_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:ecaccfd0a4d3f77ef99f773f3eb2871e88c4475cd21f88c3b08de65d981a5415_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:065d131dc280a3f6281306e7e434b3d745d832ca5502e71a6d54d3a6b3d19011_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:39eae74e134826cc2bf8ed869ff363429363c2773136a04159eec1da05fb7d57_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:5c79036d0f3d3a06be098c0379258769a1a62eee44bc2135d9e63f2cc24ff02a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:8e56d1107a0e8fa3ac77a0f35de9de76d4adbf59e9c8ac8b551a756cbb22f2e6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:517b05a222dc0f69d002bfa480e428352cbd23135f078d692b9e318132094359_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:59e67dca998d89cf9b95333d5434f469e9e24fecb7bf7fe29776d9cadd8b1f64_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:81da9cc843f7defc2fcb19c720d502b72bdaaa738a6477a9525ae620cc96c727_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f56c9dd357d9ea470a9372f66e735d8bb7e2a2d9831922f03088cd9ecaf22d86_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:49ec9cd1831327ed5915d41cfc6a643aa17f1aa6b7e961213d40cb0389649cfd_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:6a6a5027023545953a2c17cd54ffe439c8388619d747089c496f1d75c281affb_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:84574ef689ba5108e5c5cd1788346929d28d1b7a8fe1ca0beab3fece1c49328a_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:d4a54c61e9da550fb8e30087fd1ada363c6a559f5e6f86bb423675455e2b1a1e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:255936cb31c1aeb1cb7b1f93b5aa43ce5b7023f0a38d808a24972344a2c7b19f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:3fb2d0cfb812a5f9c9421386dfb11748591c91af23cdda04abb674dec68b1acf_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b0c6fc83f98e85fad2f4cee8bef57692199e96fb93ac38d0c42f68bd816812b5_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:bbbb8eb3dd778ff6810285183a67269433ab438a2f1c04fe4e3769e107273fb6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-utils-rhel9@sha256:43da839b1ad16a54b6d6e7ab987d8d4b341fa9da6b8b4c3de473fe939033cbd6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-utils-rhel9@sha256:6076901f4db7f055af645e04e3795dc60af285887a9fc82d6276da9aa033698f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-utils-rhel9@sha256:64262dfeeca80c273c0292a30ab88d0586a91422bcaf6a2f71998e3065b1a497_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-utils-rhel9@sha256:6f3fbc193bb17f28b0b4e75eb40f375c00793884920fa9a7b9677d77e60bcac7_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:26227304b43a3c83fd63e76b70980d8cb2d6af5695f5f2b453b95cb0ccee53f1_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:5f6639181046a4964876ef610804b033fbe6b8cd1a4c9ff95e1b4d16fb6ea593_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:64624952cf94139cb5d199a8934f97b5bed7c1ce036ce40591a49d1558ad8b87_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:fa0ec353dc6bd05b1ed4c10142543c733e44203d7dd0698ff618933b54039013_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cli-artifacts@sha256:1b01dfd8a6567db44434cc03cae41246a0524f1bf47cb2167042e1e458349e02_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- +119 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:e39f4b55929f54a720ca84075544920ddc9fcc1e6a627005ebfd4c3b64e5716c (For s390x architecture) The image digest is sha256:f71ac459550d87ea330ad86155c0c03856691cca3704ed833b715daba03e9e6f (For ppc64le architecture) The image digest is sha256:1cda629199a1a845e6f8419551b5f818311a5592b4cb19b563db6d4b7f349602 (For aarch64 architecture) The image digest is sha256:6338d2c24bb593f02980f8627b5a154cbef20a45d541f7c697666c5ac880a02e All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2024:4699
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262921
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://issues.redhat.com/browse/OCPBUGS-30139
- externalhttps://issues.redhat.com/browse/OCPBUGS-34477
- externalhttps://issues.redhat.com/browse/OCPBUGS-34809
- externalhttps://issues.redhat.com/browse/OCPBUGS-35756
- externalhttps://issues.redhat.com/browse/OCPBUGS-35758
- externalhttps://issues.redhat.com/browse/OCPBUGS-35888
- externalhttps://issues.redhat.com/browse/OCPBUGS-36208
- externalhttps://issues.redhat.com/browse/OCPBUGS-36329
- externalhttps://issues.redhat.com/browse/OCPBUGS-36451
- externalhttps://issues.redhat.com/browse/OCPBUGS-36466
- externalhttps://issues.redhat.com/browse/OCPBUGS-36606
- externalhttps://issues.redhat.com/browse/OCPBUGS-36702
- externalhttps://issues.redhat.com/browse/OCPBUGS-36813
- externalhttps://issues.redhat.com/browse/OCPBUGS-36842
- externalhttps://issues.redhat.com/browse/OCPBUGS-36863
- externalhttps://issues.redhat.com/browse/OCPBUGS-36971
- externalhttps://issues.redhat.com/browse/OCPBUGS-37067
- externalhttps://issues.redhat.com/browse/OCPBUGS-37266
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4699.json