Red Hat Security Advisory: OpenShift Container Platform 4.16.4 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6409 — openssh: Possible remote code execution due to a race condition in signal handling affecting Red Hat Enterprise Linux 9 CVE-2024-24788 — golang: net: malformed DNS message can cause infinite loop CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
🎯 Affected products171
- Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:2137d90a610e0216c7293bcbbeb41b4a412cb739316f58eb4da33faa5dab1a40_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:43b2ac9bc951547e72343bf726b2525d329d9887d977ff93da59b0b20eddab06_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:5ad87db06c4c2fe73ae1e369f0bc3c920f0f30f8c6bffb330d85c6b383dfc531_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:7e8a2fe048b792368cb7c11870e9df3dacc48d15c0483f265beb516d2cc030f1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:032d9a44076594618bf4c8dab58155843b576533f43d161f7168db733df000e4_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:e268960009e2e76c2bb237d48e72060add7671da5a4382dae705c8cc5929def4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:e8ecb0f7bf4d3f1780b5f243aecaff0eb2f04dd904cc06c279303ae53a21163d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/egress-router-cni-rhel9@sha256:fae02b2056795831f7f0aae6fdaf9c6c4d526b366885c684b2230b1a23636307_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:1e212752938d852218e493ee0144c2d7b9b4c6a6e927daf631927a81dfea3486_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:2a69adb78093eeb7c0d6f0c2d005d20e0e86c79ad84692e9fea0b864225429ed_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:c65769076c6d31a5b1330e74e1baefcbd4ee46de210d21b1a41e412bdbbe30e3_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:ed018dd82ef7a393fbdffb58d57ab611ca941153094f98c8a8ecf93c9a615049_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:14b18392be04cc3c9951d4e38d57a4f21cd9f362a21b1649738ceb039f724924_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:8fd025a52f324f3ffbd766a5b0b2c9ce876b6c78be08c06dd0e43b4bf2ffe592_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:b41af8fd48b1eea4e45b4ee510d5fc161c6690b964633ac4fd9ef8ac292703db_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:f06115e8b8a9a9e3c4522c2b45075129aefe0c6f06efacca1b45f54190a14da6_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:177a6dea4587e93c70af9c38482ff85aea550a14a36356d9a00cc0c71e2b55d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:964854ff024dc816fc274e81573c10e67f4ee4175df02f6f4d34c76980a36bc2_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:9aec1663fcccb0832f6b0a3007973da0191b114271a1c399997c08f77442dcf3_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:a74899959393fe5ce186afd37b6742db53a0c15f31b97653ed5c4b9f3e8c36a9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:622ff58fd9c852f0d743b6f3b8b608a67dbb70cb702493a9605f0291450c5ad0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:6ea63bb505c427f4428c0e42089fbe3b4151df2ba27f9a74b11c1005d57863bc_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:999cb53d6ae27b89f7b278f2272dc63d1c721e85f451bd9bd901948557b8db69_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:a28f34ae661883b4b7b2d4355e71f9c508c14e7a22b7ce1903ac13a2aa22de57_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-utils-rhel9@sha256:041d983c6807129d0e0cf371133f8a1c0d5fde78a813c60aa1f293e64004fb43_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-utils-rhel9@sha256:10976b66e42c8de99c8dfd3908ea9cc91959852365d6d96e7a6f5bd0e15b5fc8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-utils-rhel9@sha256:40fb3c9722ffc46c2f507ca92d3e780a327e75ebc23fd788361fca436754edb8_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-utils-rhel9@sha256:7cfdfc82fd18b39ff513f562b063eab7474f17cee1a3729c989627dc93aa7434_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-baremetal-installer-rhel9@sha256:2f73ea1f9d08f1669f05f73c71f4678d2d3949ce0c404745e8c0a1fd2486334c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +141 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:633d1d36e834a70baf666994ef375b9d1702bd1c54ab46f96c41223af9c2d150 (For s390x architecture) The image digest is sha256:3acd5a5030ccf39daf86d1109c3aa00f1f48d5f62054a37c779e7c62178468ad (For ppc64le architecture) The image digest is sha256:0d92c8189470fa0031c85e8f77e24d780ab3da4313b6454e88ad3bec909f269b (For aarch64 architecture) The image digest is sha256:c853f47f5e8f8d8afb943f5a75757b6870c0b8bcf4507a1bbe4ad53e9ef3fdd6 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The process is identical to CVE-2024-6387, by disabling LoginGraceTime. See that CVE page for additional details. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (36)
- selfhttps://access.redhat.com/errata/RHSA-2024:4613
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295085
- externalhttps://issues.redhat.com/browse/OCPBUGS-32887
- externalhttps://issues.redhat.com/browse/OCPBUGS-34012
- externalhttps://issues.redhat.com/browse/OCPBUGS-35303
- externalhttps://issues.redhat.com/browse/OCPBUGS-35310
- externalhttps://issues.redhat.com/browse/OCPBUGS-35311
- externalhttps://issues.redhat.com/browse/OCPBUGS-35836
- externalhttps://issues.redhat.com/browse/OCPBUGS-35864
- externalhttps://issues.redhat.com/browse/OCPBUGS-36147
- externalhttps://issues.redhat.com/browse/OCPBUGS-36317
- externalhttps://issues.redhat.com/browse/OCPBUGS-36450
- externalhttps://issues.redhat.com/browse/OCPBUGS-36463
- externalhttps://issues.redhat.com/browse/OCPBUGS-36673
- externalhttps://issues.redhat.com/browse/OCPBUGS-36704
- externalhttps://issues.redhat.com/browse/OCPBUGS-36720
- externalhttps://issues.redhat.com/browse/OCPBUGS-36759
- externalhttps://issues.redhat.com/browse/OCPBUGS-36764
- externalhttps://issues.redhat.com/browse/OCPBUGS-36775
- externalhttps://issues.redhat.com/browse/OCPBUGS-36777
- externalhttps://issues.redhat.com/browse/OCPBUGS-36841
- externalhttps://issues.redhat.com/browse/OCPBUGS-36854
- externalhttps://issues.redhat.com/browse/OCPBUGS-36862
- externalhttps://issues.redhat.com/browse/OCPBUGS-36890
- externalhttps://issues.redhat.com/browse/OCPBUGS-36907
- externalhttps://issues.redhat.com/browse/OCPBUGS-36959
- externalhttps://issues.redhat.com/browse/OCPBUGS-37063
- externalhttps://issues.redhat.com/browse/OCPBUGS-37072
- externalhttps://issues.redhat.com/browse/OCPBUGS-37241
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4613.json