Red Hat Security Advisory: OpenShift Container Platform 4.16.7 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-45918 — ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-34069 — python-werkzeug: user may execute code on a developer's machine
🎯 Affected products179
- Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:19ff9072b6f1ecec0bb4b62287244456a5cfa28127d84a64373412b0f4faadf2_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:33a99a2725ad33207a5bc37590bf5e19eeff3e37cf80711db116a4159765419a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:a866513f1f9f4c11eb6f5b4e7bbbdcf5153420f44893f1f5128adad1772e98f3_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:af687f54b6a0cbf28490b0c7e68d164c0f86492c8c9b2ccb45e416d1751e1dd2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:1b167a48964a8032a7374076f5d9e05541094f91ef684b41d298c5befb54b2f5_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:374593f23c0687dbdb243891d34f208b96a302640608e90d365fe8f8c0d83274_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:4874c6666c5df641447e43ecc737ec3c0d6939ab1a43c50b79dddadb4cd2050a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:c43dc71aa86eed8c74a5cd621b4d538dd302ef47df7c2cd91597368a38949fa3_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/oc-mirror-plugin-rhel9@sha256:1f74ff96512e2052d65c8fedcd01526076dca9b6ffecd4449c1b289da4ad84bc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/oc-mirror-plugin-rhel9@sha256:3186d4916bba984a1868e24c09dbbe94ede345a16fc6ad6f08818a4269ab6ba1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/oc-mirror-plugin-rhel9@sha256:a09edb144fc95112c038a0e2a9b00ec48630fa4335d1224f248053fd0a14d7df_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/oc-mirror-plugin-rhel9@sha256:f61e3de0e686dd60f11ef49dbdab2cf86af55e57f630028ff2b8cac95758d101_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:3124e7c64c1fcf2390afa4a4cc4d81117fed0862067200963c2f93b7b580d0e4_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:6b8523c0f50929641319aaf64d11d92c6484eb029892c9c06a210fab58ba078f_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:b111294f5a44574b69c381be74dd8fb4ee122c36b4d1016e3565fb2e338e06e3_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:fcd20d52cccbc5e806bdca21d287293747685078ecfbf7d68cd931697c1e413c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:42191dc4878872573b74e0adf586bf051a06902446931e779b3bdf8056c6181d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:71314d1786d3705b7dc169e54d9cf8d686f947462f3b94afb6c24debcd49dbda_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:d5ed14e0f7996c159d60fd57a1a3863fc93b42112367e08e4e908a176bd8c23c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:d86085458f1d7b86778fa6a68710f739a609fe7713e485635e3785459b7107d0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:4168712a61c3abd30a68d9a69bfd745fa3770828666bf17b6bbf501aa1e32d04_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:9b2f03948bef8de17b1a3ffea73a986e00fd6e00dd7f586e02eabafdfe48fc83_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b94a9043dba53f6dde23cbbad30f7b55394025be9381eda0ddef3e3f8eb80d2e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:f1c0100b73f2454b80b6243d28a9072f68448be1fe39160216ec56af9d8240e6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:20401245c95453064c2ec137bac88ff89729fb0047cbb1c09d93cd5cc3841dad_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:5c818d6cebfa0afc59e5bd66b1c264c35e79d25cc50de5c244898f8183ee81eb_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:81fd9f24d5a245566c14df4e7793ab3bdceee3c240ba94cb145ebd81a30d5dc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-orchestrator-rhel9@sha256:fce0a0cc9f436b168fb98c147fab11c7ef90178afe467710ff20a3b23658ce7d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-utils-rhel9@sha256:a747494ecdcb9658dc06aa7ec196ad98475bb82a3c1ee5995a335117ea7a9ec6_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +149 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:0d365611e78c5306975753975419851183536354273a6340021f9b1cdd2a34c3 (For s390x architecture) The image digest is sha256:97d964c6f8261715f085836a757e46aad4992b006f4151f48166c063099c3811 (For ppc64le architecture) The image digest is sha256:2c6fee680d01deecead598d8b027e1345e0915c0f2a9a260ed3ae953a100de62 (For aarch64 architecture) The image digest is sha256:035f90f1fade5e4346f79936a367573da59de007b943ec638f43241871d44f94 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2024:5107
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300290
- externalhttps://issues.redhat.com/browse/OCPBUGS-30282
- externalhttps://issues.redhat.com/browse/OCPBUGS-34783
- externalhttps://issues.redhat.com/browse/OCPBUGS-34790
- externalhttps://issues.redhat.com/browse/OCPBUGS-36766
- externalhttps://issues.redhat.com/browse/OCPBUGS-37078
- externalhttps://issues.redhat.com/browse/OCPBUGS-37097
- externalhttps://issues.redhat.com/browse/OCPBUGS-37167
- externalhttps://issues.redhat.com/browse/OCPBUGS-37262
- externalhttps://issues.redhat.com/browse/OCPBUGS-37441
- externalhttps://issues.redhat.com/browse/OCPBUGS-37454
- externalhttps://issues.redhat.com/browse/OCPBUGS-37456
- externalhttps://issues.redhat.com/browse/OCPBUGS-37485
- externalhttps://issues.redhat.com/browse/OCPBUGS-37492
- externalhttps://issues.redhat.com/browse/OCPBUGS-37494
- externalhttps://issues.redhat.com/browse/OCPBUGS-37550
- externalhttps://issues.redhat.com/browse/OCPBUGS-37607
- externalhttps://issues.redhat.com/browse/OCPBUGS-37621
- externalhttps://issues.redhat.com/browse/OCPBUGS-37707
- externalhttps://issues.redhat.com/browse/OCPBUGS-37757
- externalhttps://issues.redhat.com/browse/OCPBUGS-37765
- externalhttps://issues.redhat.com/browse/OCPBUGS-37795
- externalhttps://issues.redhat.com/browse/OCPBUGS-37838
- externalhttps://issues.redhat.com/browse/OCPBUGS-37840
- externalhttps://issues.redhat.com/browse/OCPBUGS-37853
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5107.json