Red Hat Security Advisory: OpenShift Container Platform 4.13.49 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-0874 — coredns: CD bit response is cached and served later CVE-2024-1737 — bind: bind9: BIND's database will be slow if a very large number of RRs exist at the same nam CVE-2024-1975 — bind9: bind: SIG(0) can be used to exhaust CPU resources CVE-2024-4076 — bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:1d9d03721b895b81f74a8c9ae9ff3f3d0c3065f47abc574107060191c78a0165_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:35be2b7c7aa2e561c8ba9f8d570998c7f6c55a927e5946b0c414aaa8a20a3b6e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:a09d6b37662648c7b1a9846040597c7b70ee21b415c309d948ab61a33be6a65b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:e08ad3b92a1a36ac9aff22a59e302eac4b2a1e6ea40b6c69358eaeb964ecc1c6_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:1bcb6927329808f0253ff56825d09da1d27f58a8f00963bbf179531564d5a015_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:64dac1a8d5c50920cbfcb93a5e6625e62b0cf2849740f6397bb9fbec709e2397_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:97c25932472c7ef183fe67b6ff0f2b8d762fcb9e83035607cdde47f6cd06cf77_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:b2462687be0675e67e9b80cd307734a01cd5aacca8c0e5aab259f0a935bf9cc9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:08dc1e506b82e7a510d383bbb6d29588081dab9342d13183e9e22d17356c0204_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:4dec3e44c108f1b6d37854e300684a555519668367b95d2bd89d232e164773ff_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:76aa04cf1a4cc9bf7bfd73a42e2d3527dae75de7be401144818d53100af7c1e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:e4e7f2ab6d2c0ab97430ed8ce8e61a2b815ef13ed407e6fa4d25d5fdb9b17267_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:35c8b5b2203a0e77e3cf81810ae0f0004a212b170d0486ba1f1f374da6390a4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:880cf8ab8d33ae69fa9896d9e9d5368d2a07de850b3f9d206803d109bf1f0553_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:917239eff49aba390a3b7f18ce2bca16d5a85414567af6b6770fe8c06ce5b681_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:daf55cbcfd4c44764a976db2a36f9ce7dbff3c30db2868e41ccefc705ac12f24_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:366aa57177a63e2fcb017f4a74f460fbb81d5addeb20f72e0861e0bc5e4a4f32_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:97d4af75821ac8d8ceddf6e48c56855e9690c9dee2cfd4572aeaf8d5037a54a5_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:bb76f968e3f2f27a741c111719f10f4cebb2b2a0b805754689854938d7346284_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:e994d8fc42c4b4e466341ad2c29fd4b2d8877d9215f94aea717ea6ee376d5a03_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:f33fa6426595f86b31bc110b9d89f683c029b7178346f0a2ccbe41ec83bfc295_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:078d7e8a31c88c3de180513bf0fed00c71a7273ad7eb6b7d19c202c430b59b13_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:41a28a1d28d340aae5f4f03afea0f8171d59bb2a8471783f25c1bd0a09afdd4a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:a6df4e931bb968c533f5a297f11f1088570894a64e8926dd942549000d6e24b6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:f7f3235448f813bf529d709a5cf7001e3c5c964c3b938b6c08f27bf2ee942aff_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:5e65394a67aaef3c2f2182e893bc99efd79973b0a37bdba6ac24afeac669985d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:859653c2025ec7bb85026e35eaab36732572686aad6f29a8491d77e407bb7f54_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d30cd1e311cd551a5d76795af39585c759e8f66b308e54fcd200c5a3a5311119_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:d9d20668d5da905ea14fa7fe199b176a67bb6100130ebb485c88357233e1ea36_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:ab6f574665395d809511db9dc57764358278538eaae248c6d199208b3c30ab7d (For s390x architecture) The image digest is sha256:5d0769628b09763b170b7be275971144dd74034da83b3d8d42ac24dba7b603f3 (For ppc64le architecture) The image digest is sha256:b32a1b7910754ca0babb0ee4c7099e0cd74ed35a05820a64472ebcebdbe57b8c (For aarch64 architecture) The image digest is sha256:4714b66b8fb0ceeca59fb6a696db81559002261bd4a03e7d55c5a3b766e96242 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:6009
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298904
- externalhttps://issues.redhat.com/browse/OCPBUGS-38608
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6009.json