Red Hat Security Advisory: OpenShift Container Platform 4.13.55 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-6597 — python: Path traversal on tempfile.TemporaryDirectory CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
🎯 Affected products193
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:398132e5921f84f7b71ecaad586f6d67733a7f91866c86979f234d29409468e6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:f56ff2c0d758c2d2c60fcc53d93dee45d2eb77759f26bb86bae3043e610fffa2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:19b3940761f20eb04015204d4d78ced736d0c23ef41d88e9f0b2420ab22d2ea6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:5567f3f30e06a46422d6fe8f6522e37dd5e539ed37aec00918356145c7188cf4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:a1c6316cbcb379502ac14eba49b8ecadc8a2f73c14aac42a8547b9a51f74f3d8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:187216e06086b0a643b51b349cf585bb190972169ca046a6afaa5b2ffd5b63c4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:8b7cab07dc2d1467f07a804c89e0bff185568cb71b01270c09c306ce5462a578_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:379197577be4aa25e4b0a8f21cf8d0ca1c4cb0a70ab3669de63be67823b70899_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:7f0596b86edd1dfa21e816f4ce2e906a93d0af171c4d20f67ad48c0faf174d39_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:beec61cd9c4a3a376271fb1bbcc884322a309b0cb43fb99d72877d35bb579cc4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-orchestrator-rhel8@sha256:056e4c5804e0c16f35d30e52aa349c0e78315e5bd2fa6d40c566d291f9ec0191_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:d6833200429b394441481829858a98b5cb41df0bd090cd4be69e5ffb3cacd127_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:ede3f47a83d3446239f889d9c6f8c141bf5900709b81e1dee5f7919141220f8f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:cd78eb2d7d81d692f4a00746d89cff2ac561f32e203d1a4c90dbfe55d7cb2605_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-alibaba-machine-controllers-rhel8@sha256:1a2cd30c3673d510b2f515cb4a194793fac9b892b82504509b02cf50b3938746_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-apiserver-network-proxy-rhel8@sha256:36e5fd2e20f1e4972059af3659716927d7e6821f4744dac77ca7e8210f735397_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:2ab19b15ac3f3f23318b50b2c17eacf214c29194c59a58df49c841299049fdbf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:236ad9004079cf81a0149895fd242222c5ba6dae82d1cd75ba1912990290864c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:d02ecef713fe23336db12e61ea432ea6b77b52a2c295dd5d829c5a0e5f33eea3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:034f2c3d8acbb25a15ae222fb93d346af4879184de4a58821215130524f80da0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:24336b45111da0d318462a450184a54e2d688b796ba423c1728c7e65b9ae9654_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:91de902a83254a9795859b979cdd0b086bb72be98a7ef269de2c2c810c124cd0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:37141f9113ebbe49e438c9a915a588a7aeb35fa0377891cf5dd49fa654d67270_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:37c6a80c6fe301dd03511caafa97f6e94d31ccdf3e92de231358edac727d7398_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:bfa00b83acdbf66b37246a2f5f541601c13e8361bdc554034a7416697d62b076_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:47897d53987eac00d65937fd8674a5f16de99557fc17fdd6eb7c2939ca89a0e4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:c5a8dd924df3eb315618dff58cde105b3b77ee0052f25e7a7235ac7028d5e37c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-file-csi-driver-rhel8@sha256:fbe90a20f3460c857f4f56d2ab6db6675502f16682de8cb3c589560616b83f1e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:8a9434bfa39b6a3f52edaa6023f871a7e547d1ddcb4239c3256798cc8d68eb41_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +163 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:fb687ffbbe6fcb4b551518c5e910929bbac6baf5b5b1bbbc286fb2da9dbd5490 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2025:1116
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2276518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://issues.redhat.com/browse/OCPBUGS-44356
- externalhttps://issues.redhat.com/browse/OCPBUGS-45332
- externalhttps://issues.redhat.com/browse/OCPBUGS-47507
- externalhttps://issues.redhat.com/browse/OCPBUGS-47540
- externalhttps://issues.redhat.com/browse/OCPBUGS-47632
- externalhttps://issues.redhat.com/browse/OCPBUGS-48259
- externalhttps://issues.redhat.com/browse/OCPBUGS-48547
- externalhttps://issues.redhat.com/browse/OCPBUGS-48559
- externalhttps://issues.redhat.com/browse/OCPBUGS-48655
- externalhttps://issues.redhat.com/browse/OCPBUGS-48656
- externalhttps://issues.redhat.com/browse/OCPBUGS-48836
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1116.json