Red Hat Security Advisory: OpenShift Container Platform 4.13.51 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-7409 — QEMU: Denial of Service via Improper Synchronization in QEMU NBD Server During Socket Closure
🎯 Affected products116
- Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:5904200c4d1c2ef0553b39b3a1712987590ed00ed4b3272a563c1e75973045d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:632dbf7e3b28ae7a98695c4eab352d90ea378f6ba8ce90f3b503609e0bda85ff_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:bf0217bc4a5a3a5091db5e8f767c1abbf49cb93085c44b55ca05c2c742dd3ef0_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:c30b2173cedd3c74d049d7edf8f37844c12ab9284d1a15aca82f2069a645e762_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:06ad4b82bb0662e243d08b7ae2e598686f4736d934b96cfc83b59e690e79f083_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:4ffd852728ab1aaac63aa535a25cae28fb66aea04e4f081cf604c7d346797e59_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cc906d9dca1bff0f6bb19f76d37dafc0acac1568675f5d666a32041e5978bc2b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:e5ddd8af515985b901e57801e609b650d86814313f6d0d1c501d8c6cd27f3043_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:24db35465b0c40b0c755f8cd11ed5ff075374bf794748898533a403ca1f20331_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:3574f29ed9af4fa0f68f5a3698771feb5860711be696775cbde21c5e47cc9616_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:474d8942c27d97b8d053c05acf2678059b0ba4a80c7f014e675a908dd925b048_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:aabd29f21bad05cfd9749dffa4994a068c51a89d0aaa29ed31b0d95b80cf5e76_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:09df8686cff798099d6950e2160d6fc3234b17bb58907a73fd19e6a561c1629c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:1b88df3d6465fc0d24e9f959bfdb7382d69230518bc1235dec2925c8b2154559_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:6c405df8a16a1fb65a964b45e3d3635f9b73afac815aefbb6fbb81de25700725_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:a866c3472ea874f7e3318b06fa147fe760361df70b023f7b04a93d364ceeaf5b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:184ab3f70521a4755ed1b01acdbcdabc8c1bcedf56d3723dfb92304db2c8905c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:5e57e8efdfca16f7af9a924b482726daea1382bed39039b54d7334fb1fba8d28_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:8d3c5b829ea634183ddc4532846c024c8cd8494478634def511f3848b5c158d2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler@sha256:927d386c1917b6c0b8b12b7c19e171f03864d876e7f9f89be92e8fc750db5e8b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:1ba57e918e5e4d7bb5de764a6cf3cb8bb44e9dabdcd715772642f3c074bb62c2_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:39f19a90529202270b8715b99038b3fca921a1ba1d53a6563f5d303c85584f95_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:543c2fb7a3a0f1cc16c563d88c4b7fe22df2da8e4da0ac919486e2b17bfc43b1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:a339ab49a0e6527345ef7ddcc735412afb0ed6d8cb47edc6a6b5fb4620b6f228_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-openshift-controller-manager-operator@sha256:64d4edb0d770337cb1274e5f6061771bed2e78f8ab1c8da12ba0275c8ef7a391_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-openshift-controller-manager-operator@sha256:765d003dc914f380d57ce582f59fcad029723b46a87dfc9b3da52703f780a9e4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-openshift-controller-manager-operator@sha256:ac442fe227fcc45a02306c6e46c3e98d5181a9a61c2a4b7b9a34dc85a52cb01c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-openshift-controller-manager-operator@sha256:d01c45289f255d46c1f7aa3fb1ea46fe4a065783cbd34fbaf98355759524083d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console@sha256:4b2085cd5d1272a2f50a669c8524fec0c3dc0e722abcf8db5178ef9896e22636_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- +86 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:d1ed95ba10801de2a7d2a7d8f6859816b019c49f9c3bd78b08f631ac18431e74 (For s390x architecture) The image digest is sha256: 520e3222fc410884b77fd458bf20ce2d1cfbc0a3b33c1712b49d98633c1ecde8 (For ppc64le architecture) The image digest is sha256:770b3e96984c3eca3ad2c3c3b91425233fd879609e978f32779a954cf7702aee (For aarch64 architecture) The image digest is sha256:57e29afafd634b078ea22f725f48e0e9eb838c333c8c906e74674aa556002deb All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2024:6811
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302487
- externalhttps://issues.redhat.com/browse/OCPBUGS-37921
- externalhttps://issues.redhat.com/browse/OCPBUGS-38254
- externalhttps://issues.redhat.com/browse/OCPBUGS-38264
- externalhttps://issues.redhat.com/browse/OCPBUGS-41515
- externalhttps://issues.redhat.com/browse/OCPBUGS-41594
- externalhttps://issues.redhat.com/browse/OCPBUGS-41723
- externalhttps://issues.redhat.com/browse/OCPBUGS-41786
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6811.json