Red Hat Security Advisory: OpenShift Container Platform 4.13.53 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-26125 — golang-github-gin-gonic-gin: Improper Input Validation CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:3edb553de45af2953978d6a7dff25ad4227969218bef98b3cb6f849c3ae88765_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:489ef5997a6add039eab5fb70ba244ff5c8740a3f38902cfc7bc065f3038415e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:c695292656b288f36f2e8ee2f8bd3b36609971c7eef553a553737f2829f77be9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:f4d53c18c45fad5ab85b96e57f6d1144a919d2f5500fe50d0f5ab30b9d622b61_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:10681e1b52d10caef85f5dfb03fab75b2b30458824e5bafaa964a47fb9132fee_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:16d7b1116d151687bb556d45dfb25bc03cb82047eac015f8393f434fa4663472_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:923af82c8b39b514dae79aa0eb27f902a9851a8c14d6854d850cb81bf9ddac87_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:ce490095ec84821d61c9b2dd4e66d4390d7863b8044c1c5a946b441ffc3d0134_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:2d0db412489787261b3df74bdea5032b4c57be3448fcf79f1758aa09ded53432_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:435d81dc96eceb3377e49dd841624bebfc0ea68cff1b43c4ba3894cbc3857b08_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:50e15bd0f207963e7bf7bcc979626a96015ed14c6f3a0f3616cd3cd4193d09ed_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:ccb403d905e25859c732c7caf16ba78531d14404ae5361c30eb2da475b0a59ed_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:006404454fce6b76874eb5a24815022286422af0f7803e2340dfe8c03a00f692_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:3c490b92d8488f869e1859bf30803fc373017e145d8ced1e78456494a403eeec_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:a450e2a5f0d78906cac3d36e4b8a9861ec42b2f121d056ded774d01ffc3035db_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:d80d45710999bf26c40eeb0175ecff96aea9323dfd4e47afcea7b61c3eb5c38d_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:2ea68e214d96c5e4f75566524a46d6dea39dec9a27894fcd8b6fe01eb6d10431_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:8af2305a0be7edc9e7fa7904456ce53b8d4586b687f0f8d3f1596648e1ec2b6a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:a4e516fdd99def4c3578c9232199c56f182337f55b63ac73517b8b109b71406a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:d16444d33ee6c6f071a0b289ac07b58f942c1375b4110452c5680f17b3295be4_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:dabb0afbfd570aa0d30de11f7f6ce4f31b66c7843c4a29d1d9e6ddeb0e4fadf9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:4146acb3ba32c7d8fd61de46432e021895319de838dfdccaf16b980ae6d6fc27_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:6cf0ab19f566c7c5ecfe20ecfbbc3fb07794d852926706a82a6643e99a9e60af_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:861e4222e1a327dd6290f1e25201fef1c2d6e54b7c3b494fe0b4c42b04baa3f8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:b01292112e87415e1956c6dc8dd9b989958aaee54012d18350790cb7283c7bd8_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:469999c99e774259d5728ed8e1926a76b35421bf5f138366c16397649b6c2ec3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:6ade2fb4c89a2028cb1c2cc5e1fae41ca25a22c48ef04b128fbd660bef6a0c05_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8fe183e9b86f6676e35aa3822769a05a4dff14c1b7474743083e5bfd676b93ed_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f8821f1eb365d7bd437ad9510f40deb48600c9cad20718e1753a7df52870a6fc_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2cd63d8088289bab588f01341ef372833faeb91c4ef67ce859c75c860f7d4bfe (For s390x architecture) The image digest is sha256:8f75e7c8e75ed81d2e6115720035307824886430fde6beb003dd0666e5f49348 (For ppc64le architecture) The image digest is sha256:9e4e45f515149bbbc0e93dd64ff61990b1a891ab4d8730a9b104f4a708460208 (For aarch64 architecture) The image digest is sha256:f46774bb82cbf8de035d8a7644b866cf98b451b106c24ffa409719162789ef5e All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:8688
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2203769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310529
- externalhttps://issues.redhat.com/browse/OCPBUGS-42673
- externalhttps://issues.redhat.com/browse/OCPBUGS-43095
- externalhttps://issues.redhat.com/browse/OCPBUGS-43856
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8688.json