RHSA-2024:4010HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.31 security update

Published
June 26, 2024
Last Modified
September 18, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2024-28180 — jose-go: improper handling of highly compressed data

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:641d48a9ef5eba24a516a09d5247b3e711483ed371fd99c1070a5e1826ff5587_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:b59fca7e35627ad3170e8bd040eb3c1e2b63cea8e481f149c554222c3bb77f56_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:c16fe69de0945cae4c2f5fad69ec11f22c39462e6ed6346ecb160e4f54251dd6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:cc3a9b5df196984590d7940fcff250a0faf107bed61386d00d56bb3c62922b31_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:2bce6c40c85148c12c7212ddd26a2980bb7e4100b7c110750dd44f7a2b8933eb_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:b2067a73b26c7f9161b330d3798f3354cf0faf695f7455ca579c445a21671c01_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:c71acf9cdeee69532242cdafb7283e5ecdd5e83acbead7e49c94fe34f0b8b760_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:e707f457cac47dfe96ccb8007143d8209a9c2e0955d0f2271c521f0789ce0847_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:18da50e82b7ad279113a7b4e2bca37773dd2d62f7ea2a190e9125c4ff98d9092_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:19aae96d146eb7566d16345ef833aaf1a05b58a734dfc272ba805609de58b057_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:67bbb0fffb67c8c9f4f04da6fe1184af6237d4d570e97be7c39d7fe9f470bb7a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:768f76370bf40f1a33be3e49cfc61d7b6d1056f20f7223c052a9fbe56eed73a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:34e6dc88d5f79263cd9f7f298825f5597b103914776b7dee86c5e023ceb533c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:4681a30bf2971849b78a7cd066c66f368ad9c95cf8421d57a0b7cad9d7f56f89_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:5b2312b82cc1fc4481bfc7d7ee2bd50c984e0aca9005cf4b22e3ae690fbd05cb_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:ea2dfe9ac7a5f2fa68a95c0bdbcddcd1211ac7d8fc2f8fe31a364c72200368ee_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:3e988794302a8e9b99927be0077354c6a3956ec990e593174fa1608f0b7771ee_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:4bf45c0a64e53df80613a0ce09679ead2a39aa0583ab4d0bfdc30a8e2923e76b_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:aad97156425b30a41a532a2f0bbdaf9a7f95f1659ce67b2e9ad2e96692350e72_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:c1fcf483a52ac3f77674e23100571665089228d30eec34d99ef8b880629b0510_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:405523abdb6da02aa9a7b4fef1a17109535662cd2b2292fc92eff5a6aafd09a5_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:7ed66aa6168841354cf3324dd3985feb4697bd1ee5cf34560a80f4ba46014e3b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:816855d798fb88cfbc65454aff1c7e5cd69ef64f52c6a04b2c7b65476905c303_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:ec594229c085ec915b69e74352e5d53769668f32713ef0275e0fa889a8d9c840_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:5a9a2b9cb7101a673b8be42fccc7ff68ac1d4cf82d8fbd17d55d95b219481792_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:68993e8fbe327e8e20ebb45822669256515cb902e5950cb0eb758bc5af9a2632_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:992419d35fcacdbc61ac4d1e9d40ff0dba1f613409d01519eec18b6cd4e408fe_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:de4e6f5e6bc27adc154614ec973f9c4f2c27fcec2a34a1a2b901f795216d6bea_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:099b6b1674f0edecabee42a3f0e1573c8cc0b55a9debc7e6376c8c8f1a967731_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e4424eeec8a386241a5348d556bdd6dd82ea68f4f19f30f71d18963fb5924e9e (For s390x architecture) The image digest is sha256:18f2061d6755cfe769b710dc6123cdb0e3dd35d0fbbe768f8a0a4dcdbe6f112c (For ppc64le architecture) The image digest is sha256:806422d328acfd09684dab98482fb60bb3e4d224927a13d9e12a71226e122e5c (For aarch64 architecture) The image digest is sha256:fd2c3b924ed5e03ff6f38f86a8d91e220a30c19f685ade0f3adc739f5b94ef89 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 ~~~ NOTE: The crypto-policies workaround requires RHEL 8.5 or newer. Customers (for older RHEL 8 releases) who cannot immediately update crypto-policies packages may manually configuring Ciphers and MACs directly in /etc/ssh/sshd_config and ssh_config (as used for "RHEL-7") method documented https://access.redhat.com/solutions/7066001 ~~~~ Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)