Red Hat Security Advisory: OpenShift Container Platform 4.14.34 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🎯 Affected products65
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:2ff6da9424c1becae9a60a96645ce46c57378cefa2c628a7123783351365a0d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:3b9a2c010486c5ee7b61781c877dcbfbf40d3deb69ea3c2d0ce50caf2fbf2d7f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:e40a806a703573bef1b78640d8fb5368467f8839ad45d64029728de5bf7a0d41_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:3d7fb8cabdbe4aac3f286db9b62de76259a31e3595cb9d8a6da6477784878b3d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:3e781358f7a45f6decd9f6fc9d4c50bd22b9cd6e5ddf4aadacca4ca5d13c85f9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:542747d350755a6b77f93d4a52cb47b1ae10a029c4d8371fc0759d810b536319_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:a402a2d18f675027b417551e1a8fdf57af39917431d1e1156b494aca92bde0c2_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:06ad3617b209f09356757a539c62f68a309d8317b615ec3e65ad8f1919f4f771_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:7389f68e849d37b3ae8ff94717c400cefc860e57bc424d526e9e2b58cb9971e2_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:ca7d4d14588f34646c8c8d37b8d063cecc5613bec2d0c972c4bbe9aacaa319e1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:ec5188a693729b006fbf9feb566f28fd49dfe63cbb846821c0b60710488177d8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:08f2cc4395f82620d57b1ab4eea66858ed1f7e136d85785670a149e7ad3edac0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:357ea6ee4e66e9bbd6c158b74603c4a0e2ba83f3b4fce10d082a28a1e86388bf_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:8a740b0a804b966d27a1ea64a7b978af30aaada1272bb868bb53c54a5e422ac8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:b7e97f0eff04d90ab59c2ed293fc09cc95f0cbeac8cc27dffe5fcaf6be534c10_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:08e5984366ad89d2c3075c3186e7352404fcbdea7b5126e61c8a9460c7325dfb_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:139be97fa8b7a8c8b74455f67e8b09ca2c86f2c2e24eeb74f3463d833ba24563_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:315ca8ca41231fadee157a98a6bb5aaa0f061444f33b48863c3ffda9e90dd5e6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:e8d7046ea584ff670e8caf0d9ce00f6d1b7f021374cea8d297432ec72302d15c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:37aa6367bb85d2262aa1bdfc230d398069193b83e9c40f417ce2efae4603abbd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:75b5c4e959175bcab89a3dadf0620ffd59163e8b152aa8145427784373022ad7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:6388a8891240c50c728539905b33f1f918f61ed88729419a4b273eda87dba877_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:dae98509fe6c22f1667afde0a8f2a6cdea3094e2b41136f2d8ccb26c29a8a52c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-event-proxy-rhel8@sha256:2ff6da9424c1becae9a60a96645ce46c57378cefa2c628a7123783351365a0d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-event-proxy-rhel8@sha256:3b9a2c010486c5ee7b61781c877dcbfbf40d3deb69ea3c2d0ce50caf2fbf2d7f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-event-proxy-rhel8@sha256:e40a806a703573bef1b78640d8fb5368467f8839ad45d64029728de5bf7a0d41_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:2a6841952cdc76e23a49a449a3292b77218a630913124fb022d6fbad3ccb6280_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:5b51f2b972ee7f7e3b908de04ad06fd221faf7e88291a1a592f1a6414365abff_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:6622d3ff6c9f60537d66df6058c67490964e4c26074c2b866a09f68c66802fa8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +35 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:4959
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224245
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4959.json