Red Hat Security Advisory: OpenShift Container Platform 4.12.63 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-5037 — openshift/telemeter: iss check during JWT authentication can be bypassed CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-36971 — kernel: net: kernel: UAF in network route management
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:f04d363f314ac7c53273eeec9bddceec36c3818be50fbd61526ea6e894f12e02_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:f2d7483c0349d8e38937e00dbb60a7b63e0caaa4eed5580a84ab9c668421ae19_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:5bd4b736389c4d958c35ad0d3dbd194cc0767ac3cc55efb753a3b19984472935_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:bac281d0e01ee8f1b77033c54184eb31052f1c273df0866b4aace9e2bc2bdb1c_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:0ee20bef07c0618b15e5a80ebe8a7ee0e934ea1dfa4fef3b5f84c71c99678a32_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:2809d8986eb1adbc1fe7152984ba5165b82072848707da3f8de9110052980dc7_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:0047052eb5e0444394fe11fa3e22942457c3cd63583d9d04a5ea1fca1d5db821_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:493a3e39120d9f6878df9cb4ab30826d4dd66bf3291d57d6bdfdc82c4867ff3b_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:5a2bfb9c7f19f0da51abe6d4766f1b6ef130963c38b87b6e81d836ae68c5da42_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:9e78935bb59d79e2664ef5a23f97e037de6f256704fdfe3f28a2c6eac364d869_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:d6ea97e199c3199ffdcba0f026505ad14c7a457cbb46f0b6206a0fc4b2243f35_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:a65dfef684fdea3dd9f6ff0e134a5204a49d7f77d2ca5dee607e51a2cfdb0613_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:ef8f946022c14767d61b0ec2731114aadfad629914b7c8f8f8a4f766edf9d0c7_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:594eb18a5db7c6e4a50dae2539e5e7ebf9ad6390c65bd361e175fef4484314d0_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:bc555391a7c0180d4a2930a7cbb03f6ea6dba5fa9428eb4aa1f972d3cbbe5a44_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:83a62666f27aaa143896f825bff7f09864552cc018037ee22a0f795bf1fc595b_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:e8a24b102c451a8aa38d23f2628b626d118844a255a2b98ea49bcd24547df357_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:27e87b7f783559f76f6450f8c6d7bdec890c5e5dce5f826ab7cbb93c6fab01f6_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:b5a430c192417bfaf210793769096795a1a0195bae303d172ba6754eab281321_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:80d04a370092e7431ea1f08c8351a4bb802884d692e910d17f78e809e18b65a4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:b83286cce0fee5d264d8b831ed31b03c072a4d6978d9c2ca0146c7d6c0544237_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:1246c458d9a435d8554fcc428028e7880b840aad606160b643b486b86909ca3f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:9de9640b7bdc269e6014ea6e2946730c4b926febecc5455db93b23651822eca0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:e02a9a15578f41a28367efb423a1941b708a352f927f1f2e12da5dccd5bcaa92_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-machine-controllers-rhel8@sha256:83d5452c51ec69901a1fc01b4087a68d03c7bc040f29e1ef48235bb0e75340e1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:0c9d9edc2bb3e0fe273e267a081cbdbde72e6f4e3751c82c6b73b427b1c6e684_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:acc7cc344cf481fb095a15d4dc725e9dfe83176db5be6ea9e5e00187e9bf4c06_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:3a345b1a17825ddc8ee1305980ed8c659a6aa99dee1c3affe4170bea70134b9d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:ec40d77ad997ffb19c07ec1dcb17a3f73f1e342096581053a5a24765dd61d5e9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:5db6f8dd1db6b9d07dacfa74574a38a6e518145a3c0ab5d895e9c89e029a39e4 (For s390x architecture) The image digest is sha256:98c249ae7bbcb1824f1e500cce47cf4639e25341006d17c088051ceea0f96c28 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:5200
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292331
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://issues.redhat.com/browse/OCPBUGS-37422
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5200.json