Red Hat Security Advisory: OpenShift Container Platform 4.17.2 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion CVE-2024-47211 — openstack-ironic: Lack of checksum validation on images
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:3429f650f15d5e464b390786f73cc4ae5bff27d2c1669002cbaeeffc89ae67b6_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:3c94a2720e1d59df5698a00ebeb63f488022e1863d184ad91961be56b3816df6_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:7bf4280f76cd840156e1469731bde12772cb1a0b7822f05cae0672a3208ab91c_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:c7d25082478a03bb5fb77ec8a3b00059e17b343e1e7be4ec63185a8e52fa12d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:16a8c621b040fff0ed80ad83392497565ab58bfd6a8a33da44ca4527cd9966a1_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:262043bce5ffc99c3372c9fc67b979b514bab5dce6a3c45b7f8045b242cbb30a_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9b3a2bec274531a9daafe2a2e42a9ab38ec3d481bf5810f52b28656c4a83bca5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:d3a60b3f791ff12413bc1a9606af3b81cd6a7cb1ae2fe44d4a0c3f91d0c61293_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:5ec271c75dbe3a2a960016cc301b77d1391c42da08ef021b2e67db8de56777f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:6331b417c27dd65feeb614687a611f6b9f471fd1d0b3ab58a64bad3523700e0a_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:9bcd03fd638e54ba1123fd2866157ae470d86a573853eb4268366ebff513bec1_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:c02c117e5bbab084969a7233d07e0dbcd260bd6c9d972981f43269b52be917d7_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:0edc7a2879473ceed70aca3634c6726827c75056af6eb0de75145c4f805835ea_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:74faea354000316d19367678d630cafb78604cc49cdb6ee8e8e5aeab91fe6d1d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:a044145f94b808d9632d7b86478361aebef2baafdb01ba98377fec64a4e79971_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:bd029dd550bfb42ba4dd471f50af50fbf4d9b83b9a768e05218a44529bd31e3e_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:2faa5c47e79776ad71398ddbdbea317a434477f5fbfd2e9981cfdde0d1049f34_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:3bc79d7140fd68051205ff7b2a288f658fb0a96218a7d5909b8ea58b20cb0c09_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:aebae913b2682ee3bc9b5836e393b4cd7abed152f9339ecdea8dec54d168a434_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:f84cc4ce5a5f0fabc24d0660ca0bc8e0e451397c407102953f8fb2a2b946f70b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:5ef3281821813e646f1f3c98aaa927cd23af8d10eaaad857ef1c5ba995bf305e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:608a4491922ab8a486f57072ec9b6008a54aaf7d44118f7359e1685081e9975c_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:afa5aee857a0f8db16db870cf87e5a5af3c1639105fac7ddfca36965f73965da_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:bed3ee7bb9a4bdeb7de5c3e96cec2061472343e9637d9f5d0fda834ab237c99f_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:75a8fd13633e95b80fcc2e43139a62a7f846c507ede533805f2b2c36b4ac160e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:9eb9e058b71f697b36b9418145cafd0b4e0f946db7b0b47f8424b44a1bc4a21d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:b1c03da0218a07d23a3fb2cf63f7a7d8bfddd467b71812be03df87c791822902_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:efd9c4fcf604106ce70ec49b72bf4f2f64a4dc7a1413ed16e9e4bca706e2ea2f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kubevirt-csi-driver-rhel9@sha256:c5430ebd7ad28e86b2bbaff3be3e02b11b26bff7f5e2338bc52378ebbc478723_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e63e11532f9ee550219f076530ce449a5e2ce6f6179e5ccdaf55ce68092e7021 (For s390x architecture) The image digest is sha256:15561e9bef74ea74bb2bdffe9070614b6d1d0c1f77d436770d2f96240d8b85f2 (For ppc64le architecture) The image digest is sha256:c65c528b7d7e09dfbe91dfc45d782687155ec7f07f83030922f349ab0be94d2b (For aarch64 architecture) The image digest is sha256:7b544fb8fd674d403030cb26fa41780896f578aa83a23c35474918308aef4a1f All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2024:8229
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310529
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315010
- externalhttps://issues.redhat.com/browse/OCPBUGS-36453
- externalhttps://issues.redhat.com/browse/OCPBUGS-38116
- externalhttps://issues.redhat.com/browse/OCPBUGS-41552
- externalhttps://issues.redhat.com/browse/OCPBUGS-42176
- externalhttps://issues.redhat.com/browse/OCPBUGS-42349
- externalhttps://issues.redhat.com/browse/OCPBUGS-42607
- externalhttps://issues.redhat.com/browse/OCPBUGS-42716
- externalhttps://issues.redhat.com/browse/OCPBUGS-42784
- externalhttps://issues.redhat.com/browse/OCPBUGS-42803
- externalhttps://issues.redhat.com/browse/OCPBUGS-42806
- externalhttps://issues.redhat.com/browse/OCPBUGS-42839
- externalhttps://issues.redhat.com/browse/OCPBUGS-42842
- externalhttps://issues.redhat.com/browse/OCPBUGS-42953
- externalhttps://issues.redhat.com/browse/OCPBUGS-42954
- externalhttps://issues.redhat.com/browse/OCPBUGS-42958
- externalhttps://issues.redhat.com/browse/OCPBUGS-42974
- externalhttps://issues.redhat.com/browse/OCPBUGS-42996
- externalhttps://issues.redhat.com/browse/OCPBUGS-42997
- externalhttps://issues.redhat.com/browse/OCPBUGS-43009
- externalhttps://issues.redhat.com/browse/OCPBUGS-43051
- externalhttps://issues.redhat.com/browse/OCPBUGS-43069
- externalhttps://issues.redhat.com/browse/OCPBUGS-43112
- externalhttps://issues.redhat.com/browse/OCPBUGS-43227
- externalhttps://issues.redhat.com/browse/OCPBUGS-43312
- externalhttps://issues.redhat.com/browse/OCPBUGS-43321
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8229.json