Red Hat Security Advisory: OpenShift Container Platform 4.14.40 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-29401 — golang-github-gin-gonic-gin: Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:2023d38e41bb9a593c52af1edbdba52e10968a1a69728aabfc8ed0dbbddbb0b6_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:3cb237af308d52a84080e6c63eed0bf6fec3b0f1986e94366974beb9fd6661d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:bf3bb7ec29750935482cb8dad66de70ce44d1c4f6b21d46e2f1b55cf1d7b71e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:e882a0327bef858c170d4976d34cae4a38133c8c4fbfa13df9a8ca46e96de9e4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:21435b08465be75a627b9eb2791925ea086988c1f9292e377d9d1f9b39531e77_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:3ee0f627f254c042c3c6f388994f43d49d0dde5c96671305d2616adc50dc3e77_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:71b945c01b632c577caad131424e41f2aa80f21e3d693c647eaeb4b03ef45fd2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:861a81770bdd6023f8c975b3df38ce564170360db3cbdff6879436ab2f32468b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:7370e9827a579280bbb9b667e81cab756a07ef48151ca7eac4bf24f58ffd03c5_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:8957e8bce7ffd85e13cf29da4187b3e399ece01add9a37364f58791922ebc416_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:89f7c354c821404224cf2ccc99f7c34fcd90a7da8c460435327486f55dfe019e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:f32c4e074783ffe7ca59a795b824e94e6977adb3d80e10c2098254934542c63e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:6203675a60bb831e8c1a89b2e985a201536b69fd6c002b732d09f4b3d89badea_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:6d328aa7ba141c341527db53ca09b3a1231c5159594161eb12b3dfb8b3ee5aa0_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:bdd3fa132067dc17fa5149814a84a3fce54a9438e2a244eecd86b69188e96656_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:f81c330d06ecdaab7d983f646d33f1c49565edbfffc153accb1b58b1d4b2c7b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:46fad24da9259b3d42a42e4e1f543516f89cce43064aecfecb71b8a5cbcbf0bd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:497e4aed173627dd58455973a3f29c376c0f695b078acb5b64fb2d1ba97b9a06_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:5dd2933702cef88eb73e4fd5f59ab2f21988f99ca4fa866318851c180f0ca054_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:d64953495c0055c89b263ce2eb707a12d06c467de68de0babd4dc34c27f942af_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:219936bd7238619648be289379d842e6b586835f80ec2b34e728e281338d1bca_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:46ec9f4d04abff0e285bc8524ffb32d2683bca27ae07a4ae1bbbe5edf04da8ee_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:be813773b0b489a0c1bf832c8ec505f8d327e686d3810636d68e7ca38f1e30a8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:ce9771e46f6fdb16ef4ec2a202e7021bbce19042181bb0e3191bb8588d82d598_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:20ef244d3722b44096ebf2f11f4747499e8d8b4655332c284c4b4ba5c00a70f1_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:3d02a58760c7a999f642909e5a29079e83291b97adbffcfa69a42d1b9b0f9aae_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:6dd32d7fa63e05ef305bb0197b140bc0f2fc5e9e9d0bf98c33079ffb9faaac60_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e988d8f643a86fbdeb36fce9282e4e2a5474c0d6434ba0459f16f6b9c4f151ae_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:58b1665e4560cce0f7d512ae3016ecae6dfe6a19fbb2e888097d400070e5c18b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9871f990d9f956d735e85e2040101377d5fd7cc4e62e8f54feb62650190216c9 (For s390x architecture) The image digest is sha256:851bac58b8ba11752792467aca680d41a1b306ba9e4973dca4b79d4adba93e55 (For ppc64le architecture) The image digest is sha256:cbd719c4e8627d894621ffbfca8adc31669ccfd63411889b58810111bcf34b00 (For aarch64 architecture) The image digest is sha256:9cd61312dbd5619bed52ea20afb0fb6b6634f4c76394fea5b5187fc4083e8027 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2024:8697
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216957
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310529
- externalhttps://issues.redhat.com/browse/OCPBUGS-10337
- externalhttps://issues.redhat.com/browse/OCPBUGS-39086
- externalhttps://issues.redhat.com/browse/OCPBUGS-42935
- externalhttps://issues.redhat.com/browse/OCPBUGS-42952
- externalhttps://issues.redhat.com/browse/OCPBUGS-43058
- externalhttps://issues.redhat.com/browse/OCPBUGS-43368
- externalhttps://issues.redhat.com/browse/OCPBUGS-43484
- externalhttps://issues.redhat.com/browse/OCPBUGS-43505
- externalhttps://issues.redhat.com/browse/OCPBUGS-43628
- externalhttps://issues.redhat.com/browse/OCPBUGS-43688
- externalhttps://issues.redhat.com/browse/OCPBUGS-43821
- externalhttps://issues.redhat.com/browse/OCPBUGS-43916
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8697.json