RHSA-2024:5433HighCVSS 7.8

Red Hat Security Advisory: OpenShift Container Platform 4.14.35 security update

Published
August 22, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-36971 — kernel: net: kernel: UAF in network route management

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:1955ad81b690cfcb20cbfba1f96a0655e221b321ebcc35bb517a018b4f1d8494_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:58203881fd5e454878ea1b8325c90178aeede97aa22ae4e361b58e62a7024940_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:668668d28bade7a2b9c561783d87550b68535676c247c16e177b7ea0c6a75c45_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:7755865efe297bce2d18efa25e1060705b8ee0be31e1934c447706005ec2cae2_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:4391a03568aeac11ee72432e94b1fbe8f990c2fa0cd7278db802fb64a4b51530_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:cee80b384e3fa43040710936345621783897f892ab9143109f52c23d169c8c28_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:d309fbd0723d541bb5d22a3e17d554421a8d69757044d0e0e46a7d17aefb0b5f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:e6e0da2280baf81d78bf195088a3079b8c6117a89452659a5ed5c80c8da6d23e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:525cc0f5bff3df933a1ea193cc98c100d483968a57d27dfbb85596aa43e566b5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:565d97028187fbf95562a11f1a6499e568793ca99ddf0aae0d12036b9851ee2a_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:99240f0409384a9598ab167da77ce02e1f74517972123897ba966cd37e7e2918_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:b93d71846df140890f987864cc547c6f2cd07b5df541c0ecac77ad2c9486d1a7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:9aa552663005a09da9979b2f7582223f47e3f01b00118dfa3cd611694a48fa59_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:9ca375797f3e74e59a173dd735530135c699b66bcc6d237f2134da3d42b23675_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:ed80fa88a0de4787ef757d8793ae47c96de4e77424fab44345bf711f00b478e9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:fb0e30ba827a02a94b78506622759f76253ea34e41d548b1ab0594acbf8a21ae_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:8e78f4bc0796012bc8cb4c82c3b12fd4af9bb577edecb8d79f74d62bf7156297_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:c8f6511c2f50e30c73f416579fc6f5b5ecc2dd247f85eed990fe90f8898b5ca4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:ea27f453897483df40fbfee186f56ca84509972be4f412ef4dcdfc5e413bd41d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:f8522227854511cdeaf19db87eb8189ce3cae254e9ad29bceaf48ac70454e75f_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:1d195cce1f1a331be4ff718b14b06a40c5da9e251fa5002729632cb56ee6be9d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:1f8c0a081139a5a0c923b4bee35a9a707250e76b53722d52695d3b22ad514e04_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:7762f08aa57d3c9c9da83e23e198edbdf4d841666c66b28b6f304c982db696b3_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:e554790a43f3faacd7d2066c0a3fdb51ef3e9481ffda562ec069a33869842486_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:2fb6bae93d2a61f746b78712d6df84c9b654d67e5633a3925f27d5d85b4d146e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:6f1316a8691ec612ef346058b1fa61f5e15cb818c4039d7c9d6ecf6a71b258bd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:b0a9c8d862ec0946e31cc72428cda822db8e60f19d2ace7b95b613c7a3bbda26_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:c2475194f29752a9873da050928a81b739089996928cb5f5301ce22d1fa3c0e8_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:54d61858fddfd3a70571eabb668062e346ac14f2f31d2cee7b8199f375479fdf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:883088e3e6efa7443b0ac28cd7682c2fdbda889b576edad626769bf956ac0858 (For s390x architecture) The image digest is sha256:ed3773f137bb292cd8e2b5e8f33c659216e5eae53efd4f515df7b8b6cf8488fc (For ppc64le architecture) The image digest is sha256:b7eec1dc05c406eebbc27d99b084dfd276d60131e406d94c6f6efe2f60d0bb17 (For aarch64 architecture) The image digest is sha256:60a9293af28a32a62181989ebf6706ac55a660b251de6bb9e58e5e9de58b1128 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (24)