Red Hat Security Advisory: OpenShift Container Platform 4.16.1 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-5037 — openshift/telemeter: iss check during JWT authentication can be bypassed CVE-2024-26147 — helm: Missing YAML Content Leads To Panic
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:07b1329751cdcc5c6c5197d282c6eb3b1b8a44e600da838aad44887a506d222d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:51ca6d4dc8f715b9eecddc77eb75586dbd142f5c03c5df7cd5809e41da571bcf_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:9c14011ee04665ed4f5fcad0c94fb23633755c7d0e0ca0d080163ae0d655f73e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:f56755503c2a7356322491dabbf8d551b7912e0437c296eb9df8a1206eb7662a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:382c99f645be391e2ca70d31c2874f8083bbb0ab6afc638208f620c4adf5c671_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9db6bf58816fd8eb9019853fd429bb0058f805ff8b6ec99973c90036ace52d61_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:9f2a825967d7a7f529f52a9fdbaa985b775e500aea103cd70c076adbdeeb81ac_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/azure-kms-encryption-provider-rhel9@sha256:f0547a7a583deaf80bba044fbcce6ebacd7c9ab67b5a989e544811f9dd14b2fe_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:0685ab891eec6492d051554b38e794f7babc8ecca4c43d6c5658558faf339279_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:51b3b053a4c2256d9d393dd81037b9d6b7d8d58ec0c98a92ddcf73faa266ee18_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:579dee6cd81ff505c0627f375b4d53ed15ad753f06f3bd30d531fd3fd4a18685_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/cloud-network-config-controller-rhel9@sha256:8818320344f4e61db012c18309b9d9563aa7ae5a0d6e9f4f818b34f5de786ffa_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:2698f5bc7d6da50a231d0e2573098afed799b8dadcc2653609661fe6412725cb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3ed3598d73310291659ad4261bb67ffe39822662a51178d2fa9fb1ca098e2a45_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:517de50ae0b596373e92c170fcd63f268c3bd9a083688898601a6324db19903c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/container-networking-plugins-microshift-rhel9@sha256:d65c43d99ec11581692895d3ff9ccc21c257c65c103bb53bb23b903c5e5b665f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:0fd0e3b6856d3c33dc272a2e9fe26124aff25321fa4bfa1097f34345f3288c1b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:8c87edb2ccb4f638798dd1e07479df928ebbd4c03c9aa8732f45ea61ef8dabd6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:8ef92caba7bd5d6ab3a139da782bf5651c2a40802eaa33b0c7899a7e897e007b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:da1e8ae5b82f21defd459889349658f194f3310f5bcc4e289f51af62dbd2f8bd_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:8967ef61c5b89a43a8131c031a5989f39ef58f6a1792dff7bb3d99352125f14e_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:8e99ba4aba3c2fb28ae58403fbe30427936a8b31afb0090a96b4090fb237bbb1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:9923cd3aca903659b526ee1265bcbfde29f0d6345baf6dc0400e809455a6d3d9_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:e1c1544b025db8aac159901bb2b3ad6fc0b350514c9f20a9f8230f3c43e0700d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:407ea92f8ff23305e0be6386a30d48d0d34036b48c2ea4575a7e6fe7cc98824d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:611b4598f3a6f1a61343a1910ec4c2db6fda70eb296d9891074850c867d13ed0_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:73cb6ff3257c0ab31fe98f7be4512b907e0658103ea020dd710a7c55ffc8eac1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kube-metrics-server-rhel9@sha256:cb1d3cec1962a61018814d753809bb979820c9b7b98e45195b8b5ed7a7b75c57_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubevirt-csi-driver-rhel9@sha256:102371cfad10c5dc137c29d930a8e1a0655f0d729fd1457401522d1827c8c3f4_s390x as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:c17d4489c1b283ee71c76dda559e66a546e16b208a57eb156ef38fb30098903a (For s390x architecture) The image digest is sha256:b24f28935370ec725cc326cf2cea24b0996b57552cfd009bed00314e4d8f0d2a (For ppc64le architecture) The image digest is sha256:ac0d87fc7c9a78d68d0111fc061d5599e6d46a90fea4f8360f70ab1f0cd36d82 (For aarch64 architecture) The image digest is sha256:819d7a86c4280cde30d59b44d4b6abafb5e12f65c4b2d2ee604581547ba2e4b1 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic.
🔗 References (39)
- selfhttps://access.redhat.com/errata/RHSA-2024:4156
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272339
- externalhttps://issues.redhat.com/browse/OCPBUGS-19007
- externalhttps://issues.redhat.com/browse/OCPBUGS-25164
- externalhttps://issues.redhat.com/browse/OCPBUGS-27190
- externalhttps://issues.redhat.com/browse/OCPBUGS-30978
- externalhttps://issues.redhat.com/browse/OCPBUGS-31275
- externalhttps://issues.redhat.com/browse/OCPBUGS-33864
- externalhttps://issues.redhat.com/browse/OCPBUGS-34214
- externalhttps://issues.redhat.com/browse/OCPBUGS-34261
- externalhttps://issues.redhat.com/browse/OCPBUGS-34717
- externalhttps://issues.redhat.com/browse/OCPBUGS-34837
- externalhttps://issues.redhat.com/browse/OCPBUGS-34968
- externalhttps://issues.redhat.com/browse/OCPBUGS-35049
- externalhttps://issues.redhat.com/browse/OCPBUGS-35056
- externalhttps://issues.redhat.com/browse/OCPBUGS-35281
- externalhttps://issues.redhat.com/browse/OCPBUGS-35373
- externalhttps://issues.redhat.com/browse/OCPBUGS-35435
- externalhttps://issues.redhat.com/browse/OCPBUGS-35446
- externalhttps://issues.redhat.com/browse/OCPBUGS-35471
- externalhttps://issues.redhat.com/browse/OCPBUGS-35472
- externalhttps://issues.redhat.com/browse/OCPBUGS-35476
- externalhttps://issues.redhat.com/browse/OCPBUGS-35486
- externalhttps://issues.redhat.com/browse/OCPBUGS-35493
- externalhttps://issues.redhat.com/browse/OCPBUGS-35500
- externalhttps://issues.redhat.com/browse/OCPBUGS-35515
- externalhttps://issues.redhat.com/browse/OCPBUGS-35527
- externalhttps://issues.redhat.com/browse/OCPBUGS-35529
- externalhttps://issues.redhat.com/browse/OCPBUGS-35531
- externalhttps://issues.redhat.com/browse/OCPBUGS-35557
- externalhttps://issues.redhat.com/browse/OCPBUGS-35570
- externalhttps://issues.redhat.com/browse/OCPBUGS-35748
- externalhttps://issues.redhat.com/browse/OCPBUGS-35755
- externalhttps://issues.redhat.com/browse/OCPBUGS-35838
- externalhttps://issues.redhat.com/browse/OCPBUGS-35873
- externalhttps://issues.redhat.com/browse/OCPBUGS-35973
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4156.json