RHSA-2024:5439HighCVSS 7.8

Red Hat Security Advisory: OpenShift Container Platform 4.15.28 bug fix and security update

Published
August 22, 2024
Last Modified
August 12, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-34069 — python-werkzeug: user may execute code on a developer's machine CVE-2024-36971 — kernel: net: kernel: UAF in network route management

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:0d151a90b0fb9871f31f3c657bb75173bb80b075259528d07bcd3bd170bbbb5b_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:3bfcc3fb5bb2e12692d592b925c8fc83890206bd43651faed73c9afce5f0ba69_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:ecea767224b1921e36a06d157067b89ff7e8a055a0a85c637be7de9e4eab64e4_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:f802e0c2cd3a2041c47e17dccce2f18bca5ebc8e1bb24a44e7f9361b8a7eaeba_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:404ecfe91d1d602a7346dd3c22877b7b055c08f8bf2a5b15539c44842e8ed530_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:4dc44241fd0c0f08bc3a5fc5075826e87bb250891992947bcfc35109076892b2_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:5816ed7af84ceaebdf2b5dc85d2846b936d03477727d13b62defe25d68044d11_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:ea7cb926bb255affa426c8b93e91120dc1c615c42fe62a8abd155147ac603eab_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:808b3bfb78eab532420d66208157f6b9845e1cc0a12e8a131364e46be53fdfa2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:8be958d30a53c5220f7fade2e56e69fe6c70342b7896a7a22e083aacafcfaae7_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:a1198eac46347a24715dbaa1707e3a6db96a7b80386f073693e8eef590e29908_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:c966f08c9dcf261d862e86a4df395b65c5accc0b0ebdf974cd60367c2f5a3419_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:154cb93b641660e95b282fc6d71bb8874ddab609334ef62c248604556691dbef_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:396a1f91dfcd657048a6f3fee6b655f427f072c7572e0c69a52ba1b6de82f012_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:a9d355d7557708c8b1968027e6f39a72e3b50bdda3283f61a38fa57c166981bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:b6dd8a2373d41a5c295199155c5d1717bf6facf0c34793c8b0240718ec938e98_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:145bc4ff4fa5095da717e22d349bdc1ab26d2578f2f4f65b873176752a89cfb8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:1b21e93139c00d9c315d8a08113ab5dfcbb3c8f057cf82b750009c142e7c9dd7_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:6eddd7155cf4a428d6490ad838b51baff5476f8e1a3555ed8ceac2443d8231d7_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:d62358b14a0dcf32efc835285ca07c2bfb6ab2f8f8939b291affd143d8a7ef0b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:24d798eb8425e249b73ffffe5edc3158b29ef50fb2feabde778ecef186a6dca5_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:2fffba3f604594a8e2b462c24561ac6af1e34bcd173c56fd108a1a758e4d62d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:7c1a201ce1b500defd9643fa3c5c52fe0a5092df37658a90c1e4ef33704757de_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:a9b21e26b86bbb2b7697e41a1f323fe7c65284da2f9e2ca1181bd97997a9e141_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:1d9b2f9d420be800dec606b8ef6ebf7ee759934020175413ccda03f1b4f42b61_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:45c520b4ef668dec27166d855e1398d899394ffbadf182100e81c71c11cb3073_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:6c9c96b52239384c6a51ea290c385f6520432fd363799840767757d2817122ef_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:ca4a030d43bae9cd94af117727f0c50eac8815bdd8a25801f233d9ce271f8118_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:4ca16709e83c591ce280876ce63369d103917319f0ea940c625a92f6f664961c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:994e0e5355c10a38892591ad48a7fd4d41a8f1e4822ab288f703d1eb37e8ba30 (For s390x architecture) The image digest is sha256:b0a4bc15c8af9e4925ce0137972c21fde4bc476a4c0c48464ed632fc30d42fdc (For ppc64le architecture) The image digest is sha256:d395f1136fdefcd2a830ed6e1ee284d737ddf7d84913336686ba6625d9761f50 (For aarch64 architecture) The image digest is sha256:5119081ac1580de244c981650fbb3e2bd697638307b28f6002ae1af5c38b472d All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (16)