Red Hat Security Advisory: OpenShift Container Platform 4.16.8 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-36971 — kernel: net: kernel: UAF in network route management
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:141d3da884c56357ce9b1382b1cc45efa61885cbf0cb5295720ccec1fd7f9631_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1c60d29dc7915b7d5b7f9d1d9aa7d43ffe1d6ec6eefcc84516d26741d82e7f33_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:59bb5401c29d473dbea444a49bc7258d8d2ec4a98d7dec6ad75763d530bae959_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:ce54d3b6ccb945db54839cb2ded03ff42c7e86c1881dd9fbb16a98b19550c025_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:22c94b494f6ba6d2fd4a86830b6e7ec2a4592b3dfe3b51d8c55256afb0eadcb1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:463b07627f8ac45bbf96f7d1620b84bf7cd86005defd15667db99f059c823e68_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ab2cf0bf5f950fe1cde7774bb809056bce7b2bba11af92ec8900a3b68e3f93ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:b4e023eac30215e98688f117ee0e7d9baf07e1981437131aee457b20e383aedc_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:163815ba4bdddfd8cd01d1690d59b946d1e1afdfd77d85fda536f22570c2475b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:826dd20983409795d8570e86e6dd35c55b3487031f6102ff3eec050c33549793_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:889c6edae381237b3a716d61b46a7e6624c3942f79ad379faaf521997406d867_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:c9d61bf272a1168e4eebffc2bb90095fb28e2fc6a9747418634230e26871aa93_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:8b11c209a2f2cc5734192e627c1130d730e76439c53d99b110bb87aaa712ee9e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:bf5d3a7704663174cb273683770cbbce535792a55b96bb2f075fa568699e8b0e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:dac404b6ce58babe6f14077d69dd2593cc00ddfade585a48eee90a904284cd1d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f7c99848b6e4dcb42c73f59919b8cf2454eade1c95720ab3fce6af185797d580_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:08c72da1a2939f2123d03d84d23dd63180eac09fcc7a8fb9aa6c02f2daf5300a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:29a4c001ab771a941f63832f9f7613809ddaa3cb8704a9d3f86d47d14b6fb5f6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:dff16c4d2f1dac5f2fd14c74995bd7d62538eb9bc1a7b1d6c92111e7ddac51c4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:f761f003a72f13c80bcc7984b83432c1de0e847ad715d5dd6dc4275ad3124741_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:99b2d58cde95f315cf2c9c388e7ee89c88f2b39bc59715a5df064a18ca808b0c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:b870cae1ae542170258a66d6df719ff59feda4dc0d6d7ba6bbde558e0fdff7a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:c2e094e4661677500cb43cc6db0d5b0cc4a5fd367c98637cb1c1b274d2bf5a3d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:fe09a74378bc502b7631b4a9eb28f4ea25a247b6422f2196819f07c2bec7c260_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:35d1614efce3caa08455f68732015366c68663cfb907037dd3c2370d6e498b46_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:5dc9a977a7880e97349834d359e6023d2aa26dc6d3a29bb2d9ee87c245c20e4d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:ab56f313a674cb707a9dbbf1f210586fc87809b16867a298b516064e5a354a1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:c8b178c693a71650a609426f588ad2bf926b07a7ffc7808b326d76f706ee59df_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:5088f3bd7b21b39c5e309a504ed064060d094dc6b8daac91a097c33e440dcfd1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:5f1f16ecdc6429bafb437515a2bb131e367b3d98650599d735a2894cb0d0cddf (For s390x architecture) The image digest is sha256:7c5e8b9b0b8e9f9a90774420b9e6019838695e07812237da9338ee2d4b214d82 (For ppc64le architecture) The image digest is sha256:1ace403987619668b8322203cb7e6c266e373bdc765eef61c79c77a0b49af98e (For aarch64 architecture) The image digest is sha256:0a99ef4f95dee2d0f4865e32bb8e9649a7f7b0241a7d7312200f39d1a0120e9d All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2024:5422
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292331
- externalhttps://issues.redhat.com/browse/OCPBUGS-34384
- externalhttps://issues.redhat.com/browse/OCPBUGS-34690
- externalhttps://issues.redhat.com/browse/OCPBUGS-34801
- externalhttps://issues.redhat.com/browse/OCPBUGS-35407
- externalhttps://issues.redhat.com/browse/OCPBUGS-36171
- externalhttps://issues.redhat.com/browse/OCPBUGS-36484
- externalhttps://issues.redhat.com/browse/OCPBUGS-36918
- externalhttps://issues.redhat.com/browse/OCPBUGS-37060
- externalhttps://issues.redhat.com/browse/OCPBUGS-37857
- externalhttps://issues.redhat.com/browse/OCPBUGS-37967
- externalhttps://issues.redhat.com/browse/OCPBUGS-38015
- externalhttps://issues.redhat.com/browse/OCPBUGS-38035
- externalhttps://issues.redhat.com/browse/OCPBUGS-38093
- externalhttps://issues.redhat.com/browse/OCPBUGS-38129
- externalhttps://issues.redhat.com/browse/OCPBUGS-38167
- externalhttps://issues.redhat.com/browse/OCPBUGS-38290
- externalhttps://issues.redhat.com/browse/OCPBUGS-38373
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5422.json