Red Hat Security Advisory: OpenShift Container Platform 4.14.34 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-29483 — dnspython: denial of service in stub resolver CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-1394 — golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6409 — openssh: Possible remote code execution due to a race condition in signal handling affecting Red Hat Enterprise Linux 9
🎯 Affected products155
- Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:13b5d54b1fa9f33b1a36b4edababfb0bebcd80698e05ddc83b9f91ee75a0f407_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:1a43be3b3e596a67a270067c64697755de2a0918610e3ab491842363bd0f3993_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:1f9c18c0252c773ba6bcac0da6683d275fde647681cc370d3d059cb6701044c7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:e8f8cf2189cf8b0bf0b8822b07d085a9700080f8b0aef70ce169935c6ee2859b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:5914dba2f4066f5104ad13ab883470d4b50fa24f80abe6512b4ad4e22dc42d75_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:c4c1eecd0284e3d189c7c9515ef44ab5e744eb0bf11a2ccf919c02036f9a815c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:dbaaa3af89f6f865e561408aa9ee6df9d34ba3c897a6c7599e3491d32458b8ba_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:fb5860685db2f1dbc3ae868f27d73ebe1de08a334920973b827ba72be965da7a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:21e1eb3457b5a0b8e3e1ed8c3e9437b90656dca992755814d07d9055c5e4e67d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4534704fa226e5a5822df4970671688600dffb972e63ed824bce8be72cd9861d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:de389525b0ec234625e8beded112bd89010eb4979b6f211a4ae164e0f1bec8c4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f39abb13aee96f995f41ab7ff09703a3a3cb7267fbac70cbd86fb36475453397_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:05e6abab21c686c43d221ceb2f21ca4424a8c94843539576066529d874e88c98_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:52a18a107792445cea3de31b8ca92cd5f40a11632a487c27c9e40ff66938aa8d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:8577f6915c1c8f5014d371e30ceb34ea7786a292991ade5412dc1452e4541ac5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:fe1423a9a39ca606e94046d92951c8993dc0f179722f6c9a30c2304beb49d760_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:02e035860f22e5bf0be0a02319907be462e9edbdd24bd554e65d788c0fc151f4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:0ea9cbe10f50810e3a7f870eed222bc79f469785678b41788e4607c13f29ca97_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:30b2deb300c899dc4e147ae24c50ad02d72a5290afaefafd732d34d5960d8883_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:9320c859e80f949e45ca413c925bc737e7d44eb7a6ada04cef20ee60321587d1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:0c5bf1fe09028d792073e9fc82cff23c71e7ecbb79899b91929bee6ac3205a66_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:1042e5e6aad66b9fb16b7882702cc93d31774bd9a85f03033e997a629fb1b902_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:1b626fac3dbe69def883ca021613435957590c56d320370caa3cd44a09a7442c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-utils-rhel9@sha256:5bc8b363c61bdc63ecb2f66cac24f112eb9050cb8c6d4bbc80d286190b9d0586_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:2848dec87f62cb4613ee4380f037e9fac779b1b4f4e21f6802271388b2688e38_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:ab42e108468306492ac74f6fc2953833659c81bd469943dbaf7aa41d2042882a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:05a37e82418eec8bf0566937e6e6cb55dd1e1dbd7cd077ff75ed9429f805a2ef_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:594f20f31c2064776e793108481246d6c0e14e55c0a1d4b994e865c318c6778a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:81907848885c5bbccf08a328ebb081c4a3e22d9ca5e2eae1e16d9215afc5d2bc_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +125 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:d703e6615b85a6f94fb3f3e490f2eb4514412bc018ecfe967f57f4221116a718 (For s390x architecture) The image digest is sha256:5974477b97dd1b519790c6eaf644c8a4a00fe4347eb18551a94754075ca690dd (For ppc64le architecture) The image digest is sha256:43013ace5c68f0ba4dd2b648df54e1bbd8a4cd4ed301cd252d2b403c0ca9180f (For aarch64 architecture) The image digest is sha256:1eb0e157f57bebcfa8feed480479e540e60d93c4f93c951870002dbacd42c639 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The process is identical to CVE-2024-6387, by disabling LoginGraceTime. See that CVE page for additional details.
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2024:4960
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262921
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295085
- externalhttps://issues.redhat.com/browse/OCPBUGS-33022
- externalhttps://issues.redhat.com/browse/OCPBUGS-33367
- externalhttps://issues.redhat.com/browse/OCPBUGS-36159
- externalhttps://issues.redhat.com/browse/OCPBUGS-36380
- externalhttps://issues.redhat.com/browse/OCPBUGS-36397
- externalhttps://issues.redhat.com/browse/OCPBUGS-36452
- externalhttps://issues.redhat.com/browse/OCPBUGS-36467
- externalhttps://issues.redhat.com/browse/OCPBUGS-36554
- externalhttps://issues.redhat.com/browse/OCPBUGS-36555
- externalhttps://issues.redhat.com/browse/OCPBUGS-36565
- externalhttps://issues.redhat.com/browse/OCPBUGS-36716
- externalhttps://issues.redhat.com/browse/OCPBUGS-36748
- externalhttps://issues.redhat.com/browse/OCPBUGS-36800
- externalhttps://issues.redhat.com/browse/OCPBUGS-36915
- externalhttps://issues.redhat.com/browse/OCPBUGS-37068
- externalhttps://issues.redhat.com/browse/OCPBUGS-37197
- externalhttps://issues.redhat.com/browse/OCPBUGS-37204
- externalhttps://issues.redhat.com/browse/OCPBUGS-37242
- externalhttps://issues.redhat.com/browse/OCPBUGS-37276
- externalhttps://issues.redhat.com/browse/OCPBUGS-37502
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4960.json