RHSA-2024:6013HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.15.30 bug fix and security update

Published
September 5, 2024
Last Modified
August 6, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-1737 — bind: bind9: BIND's database will be slow if a very large number of RRs exist at the same nam CVE-2024-1975 — bind9: bind: SIG(0) can be used to exhaust CPU resources CVE-2024-4076 — bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content CVE-2024-26147 — helm: Missing YAML Content Leads To Panic

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:0c6de28f155a9461f5b4a95014003983266c3b2dcd5b704b671e6303202eda6f_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:77bf8a21f8c69b792b63e6cb5e113de9b806652b6597d060a8c05b9abd1882e5_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:bfcb42fd81d194396d510fe8bbf658c7f3db1c8580901b5281226763fe8723a9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:d691fb987748a5adbfa6e0778b57a5bca877f4889cd5e1ee3845e55f04ae8017_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:4458ce583bed32947d7c52bd00109568574bc1cf9ef5b32f0a539a8059df1db1_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:4b8e41ba0a07199cd04c4a534aeb83693a6c6eb92fd2d3d66cf45e5e42bde76e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:64f9ccf294107ae3b33c6dec19ac2e645ebd0e092def5dc27b5f81fe54900e46_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:9223e5214ad15ab3e3ac4c30d1ac1e5f7cfb826b6ec4ba9f5a40978fc4e22c68_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:0a9811229cf3afa39335f1fd9fd348da10c62bf9f221a9fbf6d2ab6b37234f6e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:14e3131e7bf1263327a4605566128588e84c6ed4f4ffdb09b3c553272343d774_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:26dcafb9deef8eaf1f52ab9253fc3eecd57f8fed7ee1b4bf14a3bf2257d2fe28_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:befd6256933535089c0b9e5133c5f7b0c249e237230a1508901e3b9e67f4cc9a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:09dadfe1228cca1dbf8b5ddc02020b3e69a75446fb9b9ecbf1a68a244b199126_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:2bea6c851a39e75d6dbcee915bc38b5565c672bfb9a6b29fbcc1bdcb9d208197_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:64a352704ada5ab7805cf1d7a0574c3962b49dadf2f318bd604ba3e8111eadda_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:aa6f9daef7994f22493b9faa3ee8d4c0de40addddac1cb836db471a4ad25c5c2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:4abf0c83abbc276384ea923010fd5f6434f532f5fceb7629a81cab0952190fce_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:58638426a5728d622ecbbd7cf507b67c63bfff8ea3ff83936f0362b080eeff62_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:a8e084870282ea622075998d2e24b4d500fa6ccb3922dafb530702da5ed65146_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:fb010f21addd97e37eb36b680104459b17ef1c11edabc2559cd0b49602910f2e_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:0afe7c199a8f0b3e2160b7102f35c8448b3970e79361b32f78021bc472e5eae0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:577b5454e226cf16568a69c7895257a308326f21f7ee3dc42c8dc38caebb90ac_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:5d280bda00cab0d7f74d5e644883e44ece7c732b839557898cb5a5c6bcecf219_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:b83af03bccc71c09bbe677ee70684b64b30ee65468cc6b200b0f5697c8d35b15_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:632cd2c2c13132c812c644f2a78abf6467dcc3c542982f42640cdacd2b405aaa_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:ac7b9a53bf8c0f1b12e4ce67216a07e5a15ea6bfa432371fb5f23c520402248e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:dbe395decf13c7801f96b37e76552558a09ddeca3e705edbe5658ed249bc3127_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:ffbb4f4d7a5323ef2f42a325564d36b25afac45ad2d75fee754bdfeffe704b68_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:007fe6387e97af94489caf66eceac88d5a0267d81c243144b0803cf53458cadf_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:29d88fadd452261fc8a0bbbb5d920a7fe5b8b7a0050f673a7c47059f03daef28 (For s390x architecture) The image digest is sha256:59557a8caba9c7f7e1fe4b39545d1aa33d12ed9e6b4ff1f118b0ae16087ac577 (For ppc64le architecture) The image digest is sha256:890a9bc6f7f9c65e6d98d677085228b462a00c096afd08082f4a7f56441679bc (For aarch64 architecture) The image digest is sha256:7dd6c863983390d4a975c7a01ce12eabbe1bed9fee07d36faa000e98f3cc9e73 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic.

🔗 References (19)