Red Hat Security Advisory: OpenShift Container Platform 4.14.35 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🎯 Affected products159
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:12fbbfa8a4e582df416cce6db97ad3c0a654b4a9ee1ab7cfe5a51d775dc4ef32_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:34a1cc76e8fa73cdf86903767830af45d8f22d139bd31d78606fcf7d1ccb8834_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:850c1c13df187ee3c4cdc6417c1b79a31be56d2a3b39ae363be81887d5ad535f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:245eb63d860e08279035778b3c08519dbe8fa0baa01546092d52730ab8760c6b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:4d283b47bef99891590b4e2a20d93c02d23a413fe687fc744fab6e2ca46b474a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:89ae009eb124ce0a2b08d586435623d2d7abb364f0893afaf1cffc1ff2763b07_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:d799818e20bde8b2309979e87bfc148f4de36a033fdfe55e356da75149789226_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:05b0d74b3c6306414af68bb181cc084a8b8c8024bdf8fff9f5612b74cf771abe_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:162fdd47449f4dfaeb8a8fcbcf442ece48a91a295ff3d423325880a36456ee13_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:19351ad3f631b987e9e974c80ddabf69ba181b253abc73d3521fd710b7bd2085_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:3f87327833f37ba4b1f8fa32140c545d0334c439102b4116db3967f1a9defb8a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:1ec4772ef25b922d315766c17c6d1023f616d4799cf173b6637f8b63ea4333ea_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:581b37aaf5186e2b4932ff98d2245686ca85236e13a9852d07bba7ce61a66543_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:6c5415d0149bd45045c6439be33e736f644c41d3354d9682ad32e3a3bfc0708d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:8c9da33437b63e4eb8a61972e6a80aeca27432982baa66bac9d91f2bcdbc0138_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:9fc917ed910aea0131df2c27a42bafba49c6411d0b37dc9248e266f86bedda34_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:c131a0227e32621ce5db774c27fceaf703a1762ca839dc5515d7274540794135_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:d31bc4be3ca910a4701cbc8f85339accb32a7b94728f0e6daeda9eba6d7857fd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:e124406b1b1f3d79704fb0258a7f2c2304957a8ba0822da2c642f5257e86c0cb_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:03089d57ec92ddcfa54059a4f489882067ab92b04ab34aaebaf96397250a89c8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:31dcf5b77fc8db526e56f4957477cbe91dbfdcf878cc8de7fe2351bf7bb824c1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:5e4265e1a9eb66d184c96fed1728c8ba80f69949c0faf389674452aa0d91bb34_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:b5c6ee24b714fc7e99ba7d193a2fafad466b088e2f12255b6f14412287acfa18_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:2e79b3acc148f33a57ac8b1eaa894fd86e480db81214228ecb466c46fdd17665_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:9d2b03ac7babf2bb3ce2302e35eb54473816ff00ba6c152dc8c235bc679a978b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:ab6088e9ab235d406233975242598954a7700e50c97ca13178512d70de15ab00_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:e9bfb5c298a5a6db699fb477113cf4da634c49f8e51b8a38d2be92a4eae1ca30_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:03048e3aac93e257d4d9d8b5ff7b27f9af50806cc022e71c033aa671580aa5a2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:1862244dec0864f423f69e65965434cc3b126008b01a60c2b0503384b29340db_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +129 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:5432
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://issues.redhat.com/browse/OCPBUGS-37653
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5432.json