Red Hat Security Advisory: OpenShift Container Platform 4.16.10 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-1737 — bind: bind9: BIND's database will be slow if a very large number of RRs exist at the same nam CVE-2024-1975 — bind9: bind: SIG(0) can be used to exhaust CPU resources CVE-2024-4076 — bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-24789 — golang: archive/zip: Incorrect handling of certain ZIP files
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1ebb97b6c688eadf6f7eca3a0931edb78125b27c26f2d3b5fb9272c54daa1c1f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:a24ce30dff0b550a7142d64e943cf7515073fc17f1a06b22933d576334786824_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:b841b6becc2d96b38f9de113ddf90424719e9b8ecc65b8a6664db26d329cbefe_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:ccf6b5430e507bd66eb2dc3f0b4ca3ab4d2a68957d7b17a016b0fd573608ddef_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:41554028a833a4c948fc584e042a1ec93c3bda95028ab413ef2bcce433135919_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:6fe9ced9f99b5f3d86405b2717e2b2290e470307e25440232d001c7f4ddf719a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:72f2c0c4efb9bc36f49a90cb26e000c0ce499b5a9bc808f9319da3a5d0f8cd88_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:eb942cab7108152683a1829fa9e212f042c0d2647aca494fdbe053ff5ed52641_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:5be3dbab130d64565bfb65d64c28331ae327a427e33e3f54a6c57375ee7759b5_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:87bf616a5c147daa6d7dc0f302bd5acea6d7b939edb708f0fcbe316112d4d553_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:c7cf862c09ed15d78a78187d1fcdb3a112757a9945cb4a76418d8f6b7a8c1da2_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:e3f58ebaa541d4b3eed561ab2bafbf895783e2f459ff62f5d3ef92a71227bf79_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:1bed1b0f22a05091b7504d7216ae56b0085937a33e8eda39aca7feaeb4346c42_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:9c1847f469289a26f0cadd54bd1b09540fe0d78b59f4b51063c28f6e447ef121_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:b98814a2af23e89c4ecd1a345c1643958071a3cd7296cd4e01d16778a11fa34e_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:d0d409926c965ebedd9904cc1c5c4865cbff15c4d9603087fa529bef8aa3ef77_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:37924fd6fd6c016d9137e395ebd46046ff95d104d2785d8f646d047ada3fbaa4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:3c5a1e8b79f5ec7699cdcca81eb90d1711f0e961b9f609b1fd1041fd9671d458_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:66d1fdd2b231a474a434a3aa603fed39137485c8f5b51d84fdd712f4b225638c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:74080d808555b289deb48760b9073b0c07f3f73bbe2c1bcf4edcae248623c67b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:5c9f702505d14daef25437ae45d443b87d3596c2c99646a03561eceea056403c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:980b50ad0cece99ae1da24b043f0ff60030e4608f67231ad3fa31fea7390a2bc_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:dc47d671fe521d3979f37c8de53d59ff447a996e1df6265385ca8b4b94649471_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:f68260bb9ddad38a884f5ae217149a3bcf13ba8d470483e5ca160b5704e0f52f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:15371279b276cf7775ab63f6520e642aa55521c18e89f6879c7e4be977acaaad_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:1d8b6f503bb93e9c299145aa0aed202ca43c35e82ef9750192d41100ef9f0459_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:57a214425d365ebba3a13eed8278ac79e84b6bdbd980dd9430cc202a1361fcbf_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:c473536d670e942423a5a07aab1bbe15eb9746f518d575e062d93a333cdc14e8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:4e28c29d63f69abb5fe7421712a4999916057da4d5b235d64d0f15cca53b4cc9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:793bac91943944692d72a61c47a3102edb70fb2948cdf54019f06376a87298ad (For s390x architecture) The image digest is sha256:925fb39b1c42a1b59aeb91cd3c12b4ca6f358459914809381fd6d7def577abdb (For ppc64le architecture) The image digest is sha256:a46a00e18fb14fe10a00bd87d579e0229b4aed46dd66b5f93d6e161164660d61 (For aarch64 architecture) The image digest is sha256:9f20082482f4b82e3c39bfcd3eb7be7d0a1f5171cc22e6af42ae2df6ad1d74ad All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHSA-2024:6004
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298904
- externalhttps://issues.redhat.com/browse/OCPBUGS-36510
- externalhttps://issues.redhat.com/browse/OCPBUGS-36601
- externalhttps://issues.redhat.com/browse/OCPBUGS-37048
- externalhttps://issues.redhat.com/browse/OCPBUGS-37430
- externalhttps://issues.redhat.com/browse/OCPBUGS-37526
- externalhttps://issues.redhat.com/browse/OCPBUGS-37939
- externalhttps://issues.redhat.com/browse/OCPBUGS-37954
- externalhttps://issues.redhat.com/browse/OCPBUGS-38054
- externalhttps://issues.redhat.com/browse/OCPBUGS-38196
- externalhttps://issues.redhat.com/browse/OCPBUGS-38259
- externalhttps://issues.redhat.com/browse/OCPBUGS-38627
- externalhttps://issues.redhat.com/browse/OCPBUGS-38704
- externalhttps://issues.redhat.com/browse/OCPBUGS-38788
- externalhttps://issues.redhat.com/browse/OCPBUGS-38803
- externalhttps://issues.redhat.com/browse/OCPBUGS-38818
- externalhttps://issues.redhat.com/browse/OCPBUGS-38826
- externalhttps://issues.redhat.com/browse/OCPBUGS-38894
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6004.json