Red Hat Security Advisory: OpenShift Container Platform 4.16.18 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:27d4d778f0683f98b0918045e8bd03762286cd78e1d7f4824e752a2f597f0354_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:2fe82d0c331f6340dc978bce3e090d8bde25c181680c463d1bca00dad521fc48_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:68a1217cdecda271578497d4dbc60a97c2a98d25f36d7f6024c57f0aaf20a617_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:b2126933d2cf2b8731c4d134b74d6bfa21251a6fd00e652832302374394675b2_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:94615157692b997882e5398b4cc15ab2f0285459f4fc98016308d91f1db9f0f7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:a1442aa4c599501853601c8dc85a35196d2379e0c07f100d4a883cec920d28c0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:aad1d9acebc54640caa6cea0b88bbded4609c81805fb16322d7442c90cad6470_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:af722baf07cfe218de1bbc72fb3a9ea5f485eae169c6101dcb53fd22b17fd51e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:4d18efe5b00e9b8207298f83516d1b5257ca8801d0f8ef816dff290cbc7eb566_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:73bcb0279325ec2e068cd0af4214af7b384b03cec5e6f7f629e50f6e84c88f74_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:842330b26e3160f5b46f7fde754206ba96ad217d13946b7f72640d19bd81e5b1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:fbc0361d3a2c4ca306dd8e65a3f99d53e1b82bf41cf9b07725ddbc931ec5409c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:a659df32b2c45e4a4e416ca6de4bfecd4eda4d1a60fa930cc2ec9a5856ad9ea8_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:b9a94e30a776c9c2960338c74d41880bf9cfe081a1812d913ff697e739198498_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:f9d139bd3976a409ca393fce72525955ffd258513ed933606e7eb3e01caa7484_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:fc8e8cd7b5c8e3c3e387cb43dc1d9739997f79b722543b237fde9c4966af91c1_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:551111b069ee98c13760f73dbe191a40e6a847dd7ec731a000da5945c69f5aa1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:88d05ff400ef9654d5d5dc737657c57f4a9bc8a54cdb0b207faedc3336caf515_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:c8bd34fe4000760fddefdd9ae56dc7eb6e2740054c4d60b049d9674bc1f994dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:dbaa9fe1fea34c05b71b9112d4769053f8b3e8da038ec0c062d7ee953c189d8c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:283dccc67a7f13e506e1700d76498ecc43ea670112712bc1fc2ed5eb98e4848f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:801e6fd4113f83a234d4db40f0b17db5bc4edda810bf16899b742422f4fb1e75_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:a67f7c1b1238579438fb5b411b90d666350a395d3fdbb6ec506d4d8b1d8295fa_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:c9b97ce61d0c58139205170766682eb1b7fa40871bae73e90717fde5949ad4f2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:35882065a9af841d879d075510854d4f157a888e6cd26aba4d3df1b9160637c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:75057744e792fd14c9a27e832052cbabc94f877040416fd1290b43670df9c1b7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:cf4c3f16000d26e1d39d0c0c040c978737671451a055f5e88898d9e1d3d59d20_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:fa134f93baa1c54a3f02a07ca5cd50e7176b790f702c7043da1702d8ec50d413_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:072e0720599a3d10764b1adbf1c120c51180981409913a4a268d292e3d1a4c47_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:3f14e29f5b42e1fee7d7e49482cfff4df0e63363bb4a5e782b65c66aba4944e7 (For s390x architecture) The image digest is sha256:539069342e21f9a41efa9fe21003e478cf548a1ecd591adadae3b3514bfdff2d (For ppc64le architecture) The image digest is sha256:9ea793675dc34a2924887d4cbe2e0ff70d26679f1b3e1785aeee6cba73cdc826 (For aarch64 architecture) The image digest is sha256: bcbade4f6aa446a3501f7ebc1a80d2e21369d5d1cfe0609b386a9f2512e42c77 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2024:8260
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310529
- externalhttps://issues.redhat.com/browse/OCPBUGS-33692
- externalhttps://issues.redhat.com/browse/OCPBUGS-33693
- externalhttps://issues.redhat.com/browse/OCPBUGS-39415
- externalhttps://issues.redhat.com/browse/OCPBUGS-41364
- externalhttps://issues.redhat.com/browse/OCPBUGS-41805
- externalhttps://issues.redhat.com/browse/OCPBUGS-41904
- externalhttps://issues.redhat.com/browse/OCPBUGS-42014
- externalhttps://issues.redhat.com/browse/OCPBUGS-42369
- externalhttps://issues.redhat.com/browse/OCPBUGS-42420
- externalhttps://issues.redhat.com/browse/OCPBUGS-42432
- externalhttps://issues.redhat.com/browse/OCPBUGS-42724
- externalhttps://issues.redhat.com/browse/OCPBUGS-42933
- externalhttps://issues.redhat.com/browse/OCPBUGS-43056
- externalhttps://issues.redhat.com/browse/OCPBUGS-43063
- externalhttps://issues.redhat.com/browse/OCPBUGS-43104
- externalhttps://issues.redhat.com/browse/OCPBUGS-43105
- externalhttps://issues.redhat.com/browse/OCPBUGS-43308
- externalhttps://issues.redhat.com/browse/OCPBUGS-43433
- externalhttps://issues.redhat.com/browse/OCPBUGS-43467
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8260.json