Red Hat Security Advisory: OpenShift Container Platform 4.15.28 packages and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🎯 Affected products148
- Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:601646db6b5dde5068724d7a09ed9f8172d6ff965afe393f6e7cef3b68b676cd_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:6c22cbc633cc866bc0d013142523cd4019bf2268c846c147d9278d4dc4404251_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:a72e7f02410b0af96460881ff259e0591aa044509bb0acf51121fd351ab05121_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:cdc2ef5b973adc080ba8e33a9f488a46e55700707fef5e4f0a3cbf48167eca9c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:1703fa23f675581692686e299230be0033e069a81892a39c4bcece714b771c6e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:b5481d778c4033139fc2ca855d852345c8cf5bfa44bfaedc63a50bb5735d4757_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:c8a4f71c4ed9a5825236f0c9e8766fc411eb9959e48122e79bbe573855e5c05f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:fb432268450acd35f66e15df0a3fe3e97cb1488c1cdc4e29b69103a5a607e15e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:021c0c130ad2583ab762a8e77cd0acffd6dbc2ccc5a867c1340c13bfd7712f05_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:028e84b90bdefd532307e2661af429c9097cd1359a9be21d747b32badef2972d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:9a209617984d6eb3aa3274a5bc70a804c401a1ffbf3217f3121db59ca14efd3c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:e55f20e285384a793812514eb814049b672d69fb9f0be5c9b71a0d4c19e02ea2_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:7d6df439bd71ce94ed05cea653e54c82e2f85e135c024e59627056331e403c67_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:7e051fdd7eefa06680939bc582e771c52001059008ae797532725f85fa262ec3_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:93147f27874a5b79577d1bf72e15633570f4dc01c7a05bd8729a10447c56c793_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:a70b5d61f18324ac46f1795dac2531a18ac221f7302a4300ac98689b1d5fb7e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:2859a9fe7a13eb017203f1e8654e11a1cb1924f0bf1deeb63e18ac502a9cd607_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:2cde3483b335b744c67a3839c7cfc4f1645f5a0155f994064a61305f69e1cb47_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:5ee173c6712ec39cf787febac72df880b32b10e6810e3b2d2b727f087f3dc65a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:ceecb9d235a29e386e5fc134650d3923f985b3ab60001a6176fd077a2348fe5e_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:7e78a8c4af47493506773f5edee1481f21f9921d54882519368bb1399e7096b1_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:9b74f64ccae3b48e0247a9e4c96416fcc2cbf2161db6a4295a3bfc5004cf1027_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:c1f222ea1eabcbf5f8e00599216b7d0cc407e0550f13f58d36f9c308bcbea2b7_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:e5f9097ad7d1b14d9c7fb17b149cd4dbedee80d4335cd0f51517bec4b49e5dff_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:15fd7cdae565f850ac470f6b3cce25abd6b329905c7810feb0f3cdc2daf11983_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:a633f1c54a75efa97b434e24653ada11040410c5539b9cc7fbaccb858d3af6aa_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:c1fa79e34dcd0531f103fbd65fc70c12401b637dc91a93b7b95621fed6ce62dd_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:da558036cae52ffd95c567e054a5a980d0a8c5f821d9cff2b41e79cea35cfcde_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ansible-operator@sha256:16b62cabd7bf716c7a81d2ce4eb6903150a5da248d65f62f45310d2fabf063c7_s390x as a component of Red Hat OpenShift Container Platform 4.15
- +118 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:5438
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://issues.redhat.com/browse/OCPBUGS-38090
- externalhttps://issues.redhat.com/browse/OCPBUGS-38163
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5438.json