Red Hat Security Advisory: OpenShift Container Platform 4.16.16 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-3462 — Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration CVE-2024-2961 — glibc: Out of bounds write in iconv may lead to remote code execution CVE-2024-6119 — openssl: Possible denial of service in X.509 name checks CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS CVE-2024-45490 — libexpat: Negative Length Parsing Vulnerability in libexpat CVE-2024-45491 — libexpat: Integer Overflow or Wraparound CVE-2024-45492 — libexpat: integer overflow
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1d914e9e28bb05d936c22d20f021d31cf806285d5e4ae0e47c47b50c90c7e8de_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:7460081ddaf409891100dad0bbf264e09a2ed75a5daab332610837c6091ca6ce_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:a016229598f9b0d366d745218b71c543e7f9593270d2cd84c33f867d12ebb567_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:a0de020a0ccd742c5e9f8d2d84f4b6d4db25556c10eca46a2ac0bc4993aff352_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:1fac37363539aef403e06e813f7a5ac60ebbbbb0c9864e1b8a85eb643741cc53_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:8ba194f82251278d68ea2c4efdbe495a565ca1605d5957badcf0aeb6e1763b6d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:d451b83f32e3c46be6bd5731cfbd243e40d980573030e629302cb39ad5c37249_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:f203347886da20ec203893b3244b60963d8bd3e9d781e044058af632ffe2c8c7_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:2a78a4cd8f3cd0fa8e4f49da5f000c34ffc606566add5dac206643ad372016cb_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:a7f63d6643fe81281732276c56d1e75b5e6065989badbba43e8bfd885a7acac8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:ac969ee92e5460c05531dfae4c7c4694d4ed67b1e43ad91c146c3b19870c1f22_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:da1388214451d842de360b80338f8ac04589c2eccc9a66298af331cc480d8c2b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:39c760e13a3731b44dfd17109be09a631adf5b97ffd9cf22d79e1f7797412992_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:42870ac9c7fe192bb6db58baa6f90e908abf4070d15bfea2a75b2df142a891ee_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:6173ca8bbc49df94aac63f2c19bdcbfe80046c521f222971bbebff8156f10cc5_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:a9b8daafe5c03dc799737e6d6576f1115df89848a447ed273a48587b4b08a50f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:03e0df8700001711228ed9367748035616ab7fab965946147a1cde1cec08b540_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:5cf5d4a15f410aa6bb74d05715cf4eb5630478b6271554f30a8a716dfdfe5bcc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:c3057fd38677ce93ca4f448365bad8c03cbc3ab72bcdc1166b4b110116318c2b_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:fdd2b903bbb049ffc096e9f9cc5ff59c731eae5c9eff2c9f6ec2629675339bb9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:14ce0fd8a5527c9e26068573f675b729dd8fd24e74131b45ad4b3165536c80dc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:313afc1d9dd8e618f775baa4ce2e0ff019db8ebc2a88adc29ac2c342fa6d31f3_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:6ae37c1546e1153ceea031b5d13dec2b3eb43692367477ae288cd283ad61bda7_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:7e8886fea3e4be4af015145c65a53651a17daa26d9368c87d8636d30a8418e51_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:760da54b91af345d264b174b0acff51e10d421c4ecb6fc83f87fcd7449aa9ae9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:9ab35915fb07eeb57e157f435fbb78ca9d472ac0d3d8b3995e90ef373e207571_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:ac7dc0a2f37773d79e300b2974c08c42cdb80ca90fd4344c2896d906169a804f_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:db4109da15dcbd2918d25a7c8341c9bbe49337a0d064eedcebf468eceba72991_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:5fd9d3a1f4def9b40bee638ed2d20345b2a5b3c8de0067bca7e691042cde9641_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:bd78fab2d62370a0a051c4284239c81e97304cf4cc63b97c194b7a9e1ff3235d (For s390x architecture) The image digest is sha256:31016c82002f5facebac2579b5f74d564f05a22f3c1d09fcec7b5271fdc25d41 (For ppc64le architecture) The image digest is sha256:8f5b445a0c6ead7efcc437219a5e0c84bcc39c7845f517079cecf86ba3ce3408 (For aarch64 architecture) The image digest is sha256:a56716b3f6cc89ae530684346c3b47816b11c717bfe51c038af7163f138ccdab All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: This issue can be mitigated by removing the ISO-2022-CN-EXT from glibc-gconv-extra's modules configuration. This can be done by: 1) Verify if the module is loaded by running: ~~~ $ iconv -l | grep -E 'CN-?EXT' ISO-2022-CN-EXT// ISO2022CNEXT// ~~~ If the grep output looks like the above, ISO-2022-CN-EXT module is enabled. 2) Disabled the module by editing the file located at /usr/lib64/gconv/gconv-modules.d/gconv-modules-extra.conf and comment the following lines. For RHEL 7 the file that needs to be edited is /usr/lib64/gconv/gconv-modules. This step requires to be executed by a privileged user: ~~~ # from to module cost alias ISO2022CNEXT// ISO-2022-CN-EXT// module ISO-2022-CN-EXT// INTERNAL ISO-2022-CN-EXT 1 module INTERNAL ISO-2022-CN-EXT// ISO-2022-CN-EXT 1 ~~~ For commenting those lines just add the '#' character at the beginning of mentioned lines: ~~~ # from to module cost #alias ISO2022CNEXT// ISO-2022-CN-EXT// #module ISO-2022-CN-EXT// INTERNAL ISO-2022-CN-EXT 1 #module INTERNAL ISO-2022-CN-EXT// ISO-2022-CN-EXT 1 ~~~ 3) Update the iconv cache by running: ~~~ sudo iconvconfig ~~~ 4) Check if the module was disabled by running the first step again. This time ISO-2022-CN-EXT should not appear in the output. Please notice that disabling the mentioned gconv module may lead applications relying in the affected module to fail in converting characters and should be used as a temporary mitigation before being able to fully update the affected package. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2024:7599
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2306158
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308616
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://issues.redhat.com/browse/OCPBUGS-31878
- externalhttps://issues.redhat.com/browse/OCPBUGS-35850
- externalhttps://issues.redhat.com/browse/OCPBUGS-36816
- externalhttps://issues.redhat.com/browse/OCPBUGS-37654
- externalhttps://issues.redhat.com/browse/OCPBUGS-37689
- externalhttps://issues.redhat.com/browse/OCPBUGS-38687
- externalhttps://issues.redhat.com/browse/OCPBUGS-38797
- externalhttps://issues.redhat.com/browse/OCPBUGS-39377
- externalhttps://issues.redhat.com/browse/OCPBUGS-41709
- externalhttps://issues.redhat.com/browse/OCPBUGS-41905
- externalhttps://issues.redhat.com/browse/OCPBUGS-42012
- externalhttps://issues.redhat.com/browse/OCPBUGS-42015
- externalhttps://issues.redhat.com/browse/OCPBUGS-42057
- externalhttps://issues.redhat.com/browse/OCPBUGS-42113
- externalhttps://issues.redhat.com/browse/OCPBUGS-42382
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7599.json