Red Hat Security Advisory: OpenShift Container Platform 4.14.39 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-29401 — golang-github-gin-gonic-gin: Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-2961 — glibc: Out of bounds write in iconv may lead to remote code execution CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-44082 — openstack-ironic: Specially crafted image may allow authenticated users to gain access to potentially sensitive data
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:41c70d130dc25470dfada5dcba9a87c1f4aa2df1f45615d0189eae73e415eb2a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:c072ea0dff629ad07cbe35200342f63786d50a9d87e0abfee147c668cd4f31dc_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:f0e7482a87884d76e26616719a811a2928ce773a8795134aea9a29f622b5581d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:fbd6881e0357090514f3a8a0f0ab87797115d23ded3dcdedbe612109f45cb5b8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:3ac553ab0ae91d3c1bf4f6edd3140559c525ab2359c3c9ccfe9f9445d7562f15_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:a40a4fc813ff2f01c67259d6729fcca6434ad940a1ce7362ec5b72dca5c6c985_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:a45d10f890167fd6544e31adb88bd85e75242b56a32ad28b44b90b524756cdc9_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:e7591c245746ebe8f4d208b6c2b5fa4dd8378b0ec34294cc33bff3057f578099_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:2fd4cbd33591bf26a109aaf47eec6c854051f7feac759e8197a6e4869b05cfab_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:8e8416e14e104eaf23c4609bba6a0db5c737a076b2545b7b810463c1801a1e48_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:9d4180adf9598f1072e2bbfd1f304dfde4886771634815433acdf8b8484d84de_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:ad390ce67843fade6ab1db2fd189be0db921939f768adcf7e06fa1597b340afa_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:3739dffe6253bbfa85e06783e625cd11ca55bd63861fc4871032581dd1006f6a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:8344017458b9dfab5aac0a807f6c45171d4e83cd52600b8abfff6acaffbf3f56_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:8a28240da5729a79f81a40a7622b3145b3107da17911952bd595da3d2041b8c2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:ae7c29bcfbaebaeadcb9c31fbbb1343be7805e0a118e60cb6c99507a71f41413_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:0eb152760ef80e7103825d7fb55d5bc473e13f94d55a515befd09c3f9a94aa26_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:9eec785c92d4f3e91986ee40a8a2229b16d8ce39e0e39e404e6b2082d58d8371_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:cacf3c25ba3b2abff2303e2da51599ff41bed7dfa4f28ce99abf37451fecfce5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:df5e483a2da59cc7a579f10ed05aebd07b888e2f2913acdc74f2f92e3d3bf555_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:189b7fbc41ccf979a994554d8d636b1210a7dcd41a6579524b070ac1ddf3eea8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:2c17b6c9acef434f2a3f2fbde6e8435fa8b0c6da3200ac82bbdde12b79bbc9d9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:59689921da29ddd29978599861e7f71010b7052eccb9a69700cbdf71d75a877d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:93829096b2c648cbf7a45723b1788a5c2a27196314a6887467773f2b8bbba8e7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:5387e337c1fb9dce9f9ef9b2367d42b2b055dc353e3780de34a73f6944720508_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:74ece8e2ee08e7bdee9a011193cbe201153111bec0442a2059785474bd9d2685_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:d1d85a0c21675126e2f9dcad70037a723721d516282effe233bbf0c6dfde4529_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:d4c1e10f4062931c7f28efb27c83244fd06e2295deaeca99c91b2e118541deb4_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:053ed98b61ba3f96ae313b54331a63a15c127d5a78ca1633504891004ceb6ab9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:da153230f1e6745e4f06759698bd993f61d90dcea3b9cd2eb5f6905f0603741d (For s390x architecture) The image digest is sha256:6128ebf5fa6dac7f07be335c5c53189b579e1a26fda47c5d3f32cd56134a25b1 (For ppc64le architecture) The image digest is sha256:efb272ea5e85dd5b92bd997db5e55e886721ab81ff20d9b6b25c86ddba7f5228 (For aarch64 architecture) The image digest is sha256:975e6b5f19f216ae8869de84ffb653ff41cea85632e0e10b3e3376b1b760082e All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: This issue can be mitigated by removing the ISO-2022-CN-EXT from glibc-gconv-extra's modules configuration. This can be done by: 1) Verify if the module is loaded by running: ~~~ $ iconv -l | grep -E 'CN-?EXT' ISO-2022-CN-EXT// ISO2022CNEXT// ~~~ If the grep output looks like the above, ISO-2022-CN-EXT module is enabled. 2) Disabled the module by editing the file located at /usr/lib64/gconv/gconv-modules.d/gconv-modules-extra.conf and comment the following lines. For RHEL 7 the file that needs to be edited is /usr/lib64/gconv/gconv-modules. This step requires to be executed by a privileged user: ~~~ # from to module cost alias ISO2022CNEXT// ISO-2022-CN-EXT// module ISO-2022-CN-EXT// INTERNAL ISO-2022-CN-EXT 1 module INTERNAL ISO-2022-CN-EXT// ISO-2022-CN-EXT 1 ~~~ For commenting those lines just add the '#' character at the beginning of mentioned lines: ~~~ # from to module cost #alias ISO2022CNEXT// ISO-2022-CN-EXT// #module ISO-2022-CN-EXT// INTERNAL ISO-2022-CN-EXT 1 #module INTERNAL ISO-2022-CN-EXT// ISO-2022-CN-EXT 1 ~~~ 3) Update the iconv cache by running: ~~~ sudo iconvconfig ~~~ 4) Check if the module was disabled by running the first step again. This time ISO-2022-CN-EXT should not appear in the output. Please notice that disabling the mentioned gconv module may lead applications relying in the affected module to fail in converting characters and should be used as a temporary mitigation before being able to fully update the affected package. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2024:8235
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216957
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2309331
- externalhttps://issues.redhat.com/browse/OCPBUGS-25727
- externalhttps://issues.redhat.com/browse/OCPBUGS-32266
- externalhttps://issues.redhat.com/browse/OCPBUGS-37353
- externalhttps://issues.redhat.com/browse/OCPBUGS-37552
- externalhttps://issues.redhat.com/browse/OCPBUGS-39019
- externalhttps://issues.redhat.com/browse/OCPBUGS-41246
- externalhttps://issues.redhat.com/browse/OCPBUGS-41836
- externalhttps://issues.redhat.com/browse/OCPBUGS-41918
- externalhttps://issues.redhat.com/browse/OCPBUGS-42517
- externalhttps://issues.redhat.com/browse/OCPBUGS-42518
- externalhttps://issues.redhat.com/browse/OCPBUGS-42533
- externalhttps://issues.redhat.com/browse/OCPBUGS-42567
- externalhttps://issues.redhat.com/browse/OCPBUGS-42603
- externalhttps://issues.redhat.com/browse/OCPBUGS-42757
- externalhttps://issues.redhat.com/browse/OCPBUGS-42828
- externalhttps://issues.redhat.com/browse/OCPBUGS-42986
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8235.json