Red Hat Security Advisory: OpenShift Container Platform 4.14.49 bug fix and security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2024-9675 — buildah: Buildah allows arbitrary directory mount CVE-2024-9676 — Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) CVE-2024-11187 — bind: bind9: Many records in the additional section cause CPU exhaustion CVE-2024-11218 — podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile CVE-2024-21626 — runc: file descriptor leak CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-50302 — kernel: HID: core: zero-initialize the report buffer CVE-2024-53197 — kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:21a5b0e831890bb277442f6c4635c2d598a485eea8f736892277563de6e3ee15_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:3c2cafa6f1cfa4487fb6eb1ec9f353c39bb1e704f71da8bab0745a4b62997f16_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:55d068ad182cf798d47f5c38cda535ba7f9b4d25a47fa8c04ccfe21c502a027a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:ee1d73e7acdc4583c76ce5131f80f47eefa9c9f508bddf316a2dce47a9f767f7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:23ad248c1e7c56e79afd04e5939f955b2f276b19f326a6f839872de082456166_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:60e3a23e140594933b80817deb356a52fd5e4017580357b8dfebb9ce22792e81_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:67fe0f118c58b07d962ac11b0f696763aa8fb814c73f0e507a69478c29131ddf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:f4a4a1a6f31185a1150a2d632765dc70de5937a79bea68d9d38f42f2a43ca0f7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:a9aea5be045a5723ad0531ec8a585d746a88176f9cccd0c8ad2ccc910789562b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:ab79660bda2d70f8334e5e65961a81fe1c0152e2a05047c687d9a326e24cacdf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:b84ecdc520d68f7817a25db96fc75ff84fcd68a324cf6a0872e435e4f0a8a65c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:c7012ebead21f62b9a1b1cc3342e3bc20a3ea22279e1663849e9f9019484ae3c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:41ce83f30cb477bf197a2b98a2ae80f55efadbee1e68694602e104821d6da656_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:69f4e98a65f1f680a68c541e086047d0f7e9e181b438545ddf71a91602d87317_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:706a4628550eb383fc16ec561fdd28b8faeb11979e8b3d71abd0f2ef425fd2ef_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:c59867b0b71a36e0faec8869ae6d975e87c58109216346e47fe8d2de919744d8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:09fe5a2f0df83f39db4f2cf90904837b780f4ecfd84e4fd66fbcd7457f423288_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:408d5227dfe23d300d2658341a99b5914f53954cc9b9bef5bcccbed3f0ab6cc7_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:7e378345a732782426e072dca8c2378fec283fe2cda647607bd4e1c926db5e51_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:add0d742cda27eee33bf88d6a31165885bae3ca8e6b8d2b84e1c845916e5a891_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:6d85083a73ab240b27373b35ec4bd3ad92fdfc2952352275129b0ab1285143ba_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:852ee0e7791e1d82326e90c262c7c182876e05fba867b6e768d5a5db42dc5472_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:95cfbf37df51653dc83d3e6f7e357a5131d0c9291f73909428947a8158ea694b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b695b856a650a53bc3f0aad1b34ecf78069b8901e5a678d6076b9ac30a0830d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:43b97e3fa3d473bd9f32bbbddf4980104c99ec5bc4fcc6fe69bbd8057388e13d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:4cf586f22bef0269da4bdcdf2c93d51135f7a3397152c5f5a7ed67abfc51d266_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:6cf48948249f638340580caef87c57da7a4ef779b264fe319363bbd921c9f399_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e2dbb5aa181734880973f672a8a9852b9853dd98f704d4f88537436f84ead2ae_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1d067ba714f5105e77a908a3f57faa9ff237e7f2011249cdff1bb0dcf13a05d9_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:aad28ca69006c0cea18fc7487ab220bc5b627168dd49f112183428cb6bb32b62 (For s390x architecture) The image digest is sha256:5cfdd7e18af6e04ea3e69ad513655ad1a3e2917addb59d64e3fd027f6744b693 (For ppc64le architecture) The image digest is sha256:b05ebaa64e24c93704a8879e0fc9561029433aa1face919c5a1283bac316723c (For aarch64 architecture) The image digest is sha256:0650436dc25bbe30f2b037e49971c135e0787fc6e20826f6c30cf71ea5880a74 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Users can set the option `minimal-responses yes;`in the configuration file located at `/etc/named.conf`to mitigate this vulnerability. Workaround: Mandatory access controls should limit the access of the process performing the build, on systems where they are enabled. SELinux enforces strict access controls by confining the build process (e.g., Podman) to specific domains like container_t. This prevents unauthorized access to sensitive host files and directories, even if a malicious Containerfile tries to exploit the --mount flag. Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks. Workaround: To mitigate this issue, prevent module snd-usb-audio from being loaded. As the snd_usb_audio module will be auto-loaded when a usb device is hot plugged, the module can be prevented by loading with the following instructions: # echo "install snd_usb_audio /bin/true" >> /etc/modprobe.d/disable-snd-usb-audio.conf The system will need to be restarted if the modules are loaded. In most circumstances, the sound kernel modules will be unable to be unloaded while any programs are active and the device are in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2025:2710
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2024-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258725
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317467
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2326231
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2327169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2334412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2342879
- externalhttps://issues.redhat.com/browse/OCPBUGS-42971
- externalhttps://issues.redhat.com/browse/OCPBUGS-46606
- externalhttps://issues.redhat.com/browse/OCPBUGS-48084
- externalhttps://issues.redhat.com/browse/OCPBUGS-49753
- externalhttps://issues.redhat.com/browse/OCPBUGS-50477
- externalhttps://issues.redhat.com/browse/OCPBUGS-50631
- externalhttps://issues.redhat.com/browse/OCPBUGS-50662
- externalhttps://issues.redhat.com/browse/OCPBUGS-51044
- externalhttps://issues.redhat.com/browse/OCPBUGS-51045
- externalhttps://issues.redhat.com/browse/OCPBUGS-51363
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2710.json