Red Hat Security Advisory: OpenShift Container Platform 4.14.36 security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-0874 — coredns: CD bit response is cached and served later CVE-2024-1737 — bind: bind9: BIND's database will be slow if a very large number of RRs exist at the same nam CVE-2024-1975 — bind9: bind: SIG(0) can be used to exhaust CPU resources CVE-2024-4076 — bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-34069 — python-werkzeug: user may execute code on a developer's machine
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:41bffba9f72bef9b62351600165c95123726c4f6fbb035cdf4405126c072f602_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:81d7612f476ecbbe3e1a2b2feb28ec4d841cd5040abb30f581794e8c623c3527_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:a5a2ec57bfb6b25449c109ec6b3b125d717de05be72d961d90b8573e10b8428e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:bc83be6ad3309153cc83e3b9810dea39d8c49c998f72ac4c6cfd2268434e87a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:0f2c1a3a6c23f27a9aed6c66a7360ad6ab7295d3b83eb2b8642600a8c54337f8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:6163b9e300066452ff69068692e36e6d31f52bb8a40060351de05cb0368f064f_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:70aa9964d7034005f268a67d8a2823dd66d540c6a5b88efeb03e30d72a39440f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:f51695748edee297de2d02f11f103913eef36203b4acd2a81cced4c60fcae2a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:00be182d126fe6716d004973a9712218bc84465f000c90ab997b66a32ebbb4b0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:54e6fa66b40f4fa1b99aadafdacb2c4d8535ac5f2fceb5fdf5f5100addff4af0_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:6e36a67f48087dd1b9af15ea00c5472986ae7571a321f231a45469f3879a3664_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:76d74bfb235114e79e8bea69457ada175b02c5c288d02d2f22639f99e0291b58_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:70512c910e4aec149ee5085c1a34c2eede3171b3167afc4b4caf23661490ea76_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:a110038403c3b55f8134517e742eb26f57f42864feb9dd708eab65a4885bfdd0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:c6cd1daa07d2a477e79078dac4e48f1f9ef10a067bdd82e9e380e15607a22e4f_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:cc5bc51f82528be44f843cd5a2bc999f7e6eae624190675ada22d17de2860e54_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:258309d62e0b7a8e1e7cb7bf2f43c90652b411d2954975eae15fff857601c9c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:341901fdba6d264b0df647b4bc73a54ecc1c5ff3aada4dff0963a3ceb9911c4e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:42e7ccc74a314182dc274d886d7942e77c7013839e665a646a8b2fa743b73750_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:fa9940fc569b2acb59ea55379d3c9f0fa3628a6118d48ff54ac86664c23cf291_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:0801682a96e41dcbbf712cb6f5b8d5b569d7315c24a9fcc4151d68a55289714f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:11992befd56e4e4d061948caf27b16db38f7d818158a538833edb80cbdb00573_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:1ab923068c2b9d508b1fac4f257da5890ddf6c19522e81656b200efb9df01207_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b155a7ac5ed41a41ff446d0f459f0b981e99fc15503266bae4053197ce7c07d0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:1c22664b30abc940a964754ce76574198e6edf0ca160a956859c26cf4a4ced0b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:37602235071fb6ffa1db90073f9320cb25688ed36b777dc6bc23e8d2cab0c5b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:6d1138b483c755fb19f3882963dadf6b3a15a06d7dcf56a6f7779880c4b1f053_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:f0d1681049d7ab768447ab83e69654dce8a3ee20ae465e1507a70831a9936fd3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3ab35fb8688f5f2358cb367c6b73f18c5be9da6e15b51a5da3f6699e63144d10_s390x as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:4bc4925e8028158e3f313aa83e59e181c94d88b4aa82a3b00202d6f354e8dfed (For s390x architecture) The image digest is sha256:788a7a0fd2d808d1107d7ffc6731f799bdb8a41ac01ffab2afdbcb83b3390ffa (For ppc64le architecture) The image digest is sha256:f5c4474b162b3be7f693c51572d21dc5b1c8e14861049f2c426f4cce0a6bb4d8 (For aarch64 architecture) The image digest is sha256:0bad0cf89c81b99f44e8db697ff63c8b1acf973dc57cf138eadfd7708844027e All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (43)
- selfhttps://access.redhat.com/errata/RHSA-2024:6406
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298904
- externalhttps://issues.redhat.com/browse/OCPBUGS-30414
- externalhttps://issues.redhat.com/browse/OCPBUGS-32258
- externalhttps://issues.redhat.com/browse/OCPBUGS-32706
- externalhttps://issues.redhat.com/browse/OCPBUGS-33748
- externalhttps://issues.redhat.com/browse/OCPBUGS-35223
- externalhttps://issues.redhat.com/browse/OCPBUGS-35846
- externalhttps://issues.redhat.com/browse/OCPBUGS-36161
- externalhttps://issues.redhat.com/browse/OCPBUGS-36180
- externalhttps://issues.redhat.com/browse/OCPBUGS-36223
- externalhttps://issues.redhat.com/browse/OCPBUGS-37076
- externalhttps://issues.redhat.com/browse/OCPBUGS-37221
- externalhttps://issues.redhat.com/browse/OCPBUGS-37673
- externalhttps://issues.redhat.com/browse/OCPBUGS-37728
- externalhttps://issues.redhat.com/browse/OCPBUGS-37754
- externalhttps://issues.redhat.com/browse/OCPBUGS-37823
- externalhttps://issues.redhat.com/browse/OCPBUGS-37966
- externalhttps://issues.redhat.com/browse/OCPBUGS-38053
- externalhttps://issues.redhat.com/browse/OCPBUGS-38263
- externalhttps://issues.redhat.com/browse/OCPBUGS-38371
- externalhttps://issues.redhat.com/browse/OCPBUGS-38378
- externalhttps://issues.redhat.com/browse/OCPBUGS-38544
- externalhttps://issues.redhat.com/browse/OCPBUGS-38624
- externalhttps://issues.redhat.com/browse/OCPBUGS-38786
- externalhttps://issues.redhat.com/browse/OCPBUGS-38791
- externalhttps://issues.redhat.com/browse/OCPBUGS-38940
- externalhttps://issues.redhat.com/browse/OCPBUGS-38959
- externalhttps://issues.redhat.com/browse/OCPBUGS-38972
- externalhttps://issues.redhat.com/browse/OCPBUGS-39160
- externalhttps://issues.redhat.com/browse/OCPBUGS-39176
- externalhttps://issues.redhat.com/browse/OCPBUGS-39230
- externalhttps://issues.redhat.com/browse/OCPBUGS-39413
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6406.json