RHSA-2024:7174HighCVSS 8.3

Red Hat Security Advisory: OpenShift Container Platform 4.16.15 bug fix and security update

Published
October 2, 2024
Last Modified
August 21, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-44082 — openstack-ironic: Specially crafted image may allow authenticated users to gain access to potentially sensitive data

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:4e19e0fd7547e44b45ba8ac44e95f5762628770618648fa025ffac52dfa18002_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:5fd2e9a9961dccab88e32f456f0ae56a01b0024543cffd2ea8c8ebb4eb8aafe5_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:e07b9854fbd155b28467802a978cfdd979f3aae8ee857fb337f88a06ef05ff0d_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:f761059f67d83b04e279980dcc557272e6dcd2341f8b47526308527d97d1a1a3_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:00acf126ee1779d571380a24abf0fb82487a0f0bd40b8325b357546935403c28_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:44167fd8ab5b518fec48f1c12affd35ca56e05ebab948c408f6b8a5d3ff336d9_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:953c99a75d3de0474918f1fca1f881aa87eb19ea60b700eabf27f79f44fefee1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:c935efb2c72283c24c8c0d387d288b96c78c7a0bc10ef535981ca11ec1956341_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:1d6f45b57b318af99a3a491d6d419a357845c4ca418b44064323e073a8687ce8_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:2710db7b410898064e1af7cfd61eb5a61e60fca93ffb490a18d2a72287264811_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:af3d874fc294e1bde61a2bf6ec2372a6cc874dc139df7e2a993d1a38801e8766_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:dd1a63bc253a3f1a22fc2ec1dcb082edec761fbae666639e4662db7622f05e09_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:8850243294b47dced597598a5920a0612821493a2b5cf6eda13efc891a4bfca9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:da04bc5e9930f3ca38ea9eb1894c1b0ea6207a3d96c7611a31f28e2a0209e8f2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:dea97e37f58a133dba3502ffa86d423300d47781b5cda0df3c121b3ec5716521_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:edf49bd1b6d4d40cb19f0c98cb4d5a9aaae63acb1803a7cdaaf43499b0a7b0db_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:0ddb36f9f8262f94eaba4b49d0ad00de9a42343c05fd521c5f04526565715291_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:3732a1602341a8b12e9c8df4cbd58e8d76e8d26e3ce8ef35490c8e0f072a1c68_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:3cc13f2a17a3fd127c1d91fb13cf785872d981555ca2a5f7ce1dd552438e5cb3_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:84639cb458ab806f7ad5a656819817ef7750c59995caaaab1a486634a792f64a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:07f1f25873e98654695eea7e127f4b0743b97f0ab7f4841358e537de577fb9fd_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:0a0746f04ad254d6f54302bb0ba9de19f716dbf47975837f9716db362a1a58c0_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:98873530c90c3787ec689474cf81bd75dc4ee9ecfa19efd0e722cdd61fa04871_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:f8648e2d0341ab3334377f178a53163bfd1b109535bdf0a07b19159fb586e48c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:335728f88af4feac856cd8dd3fe3a0798b3501089bfd77e22ebcb9ae8e8412be_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:51a0e4723842a6da760f1088870f0be485abcbaaf59f273ffff6f24ca393a312_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:51b439d094905cfa1a8ab43dc31215a585e3249b457496f347227cad87358c09_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:9e3aca7c4c76ba84cf5fbb40434e98f6f8a42c1389f07fbc9d84c927cbe1b741_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:265b8bd716ea9cf683d870394243cf7b001fedfb4defc0089681c4170a5c74df_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:7a478e987f9f283f7a182080522d40768db50ad274caad8165a9b5e74ba38c43 (For s390x architecture) The image digest is sha256:6c84cd13d6cc90038d11cee892b9398e6e49e78fc4caef06b7e589debab7f198 (For ppc64le architecture) The image digest is sha256:e0ca664a081cc992abc2303d2cdafc08b0cb961d8c5f9fe2ff9e91bd41788809 (For aarch64 architecture) The image digest is sha256:436f1c88a1dd46dc3a2f46ca6139dc998f013a28e7714ad59258e5f7ab7556d3 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (23)