Red Hat Security Advisory: OpenShift Container Platform 4.15.25 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-6409 — openssh: Possible remote code execution due to a race condition in signal handling affecting Red Hat Enterprise Linux 9
🎯 Affected products135
- Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:25aa214b6155b0a388b378df47b871a0b04ad2467036ca12da7c89b646f22537_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:406d65a057b1b6f0b05e690c4655055449359a3b8d64e3c8072113cfa00d4445_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:54c5e9e961acda64ff93650d83018fc185134c6f0afff3e0faa95a3ec714ef43_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:5c759539cd24c4e4b19260ae8098e0d258b1064c2bb5c381cd2b683ec8faa319_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:3efd6ee4339844d013ab3c9af7bb50a7f764fbb6af6b9cecae14b4f68444cc10_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:651c625cf90cbc7277729285cc1d8c523b7c767662033d6a99a86d7c6cc6cb68_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:7f12f07ae7ccf1630aa1bd5dfa19f1a5a359886e7d179937c5cca3eaf13decdf_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:81b6e1260ec896ce9296a172aad4c7b1c4f3243b425f90766fb0e0a448e5c081_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:81d517bbbb997583f73de4eb756dc940559de9720929e5b9f7e329a3982081db_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:98f82fcd37ddb0922586380de985dbfa7a07821718a81a415fa18f4ceb8a2dba_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:9b6e2fc546e0860ca5be5fd4f7cc1fc99e06caa7a38bee073c9f846c7535affe_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:d9398f953a549c562cd6b86defe580ded69d42348d4798d8796fac4d95879185_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:479df6cbd0c119c7a408299a2b788b9913b1b447699abbd38dfc4c7bb5708bfc_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:8c423ddf81d95efd96f2bc1f90e609426a38dcd58ca82b5ad9fa6523ced8512c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:e2bc4ff39d4f1662e33d844ecd514ecb8f4f9a8e8e12c3e0c6e6a98aa562ac6a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-installer-rhel8@sha256:e463ad06cf9ea6df54235e6541c63cc95964616188dddfc1621980890c788bc8_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-runtimecfg-rhel9@sha256:1f231ab02e530229b494a0b08c85e2216f9684be8904f96e23be2bdb35b09213_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-runtimecfg-rhel9@sha256:2f1d4306b99f34825d629feb972acd3d536e9244b2306e64ecf6a1007c18410b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-runtimecfg-rhel9@sha256:ca7eae1b08761d5b71cf0c8d469aea51144993ade95d99ee96088b7ba9e407e9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-baremetal-runtimecfg-rhel9@sha256:e6068d20d90e3fe29ec93cae0f7a3b9575f97c3fa1df0f9f7e5bc3ac31a0ac82_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-credential-operator@sha256:417e09896cd39cafb1880a812f121384a2de836fe3d28ed93a5f8ded0f570426_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-credential-operator@sha256:77da26c0d33726d66704e8421acf75f924eb2255d608373cf3d4f9a52b5d01f1_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-credential-operator@sha256:e02130e597a01094ea55a9d2f6d7c058e61406bf9260d2a360fe064e954c5bbd_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cloud-credential-operator@sha256:ff51c079ec7819c99da20de1448eeaacd16e318b39e2d4a0b41e73bb6d42c48f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-cloud-controller-manager-rhel9-operator@sha256:302077282a4f5a96343ad7a854e83e240992311e9e5719407aa0f9626a3435b3_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-cloud-controller-manager-rhel9-operator@sha256:547b7bf7a5f479b60865282763062dec68a9a010c49484078ea4a15982cd74a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-cloud-controller-manager-rhel9-operator@sha256:7b618958082257a3d9b4821bbcafa235fce403f10b93a37cb0bf72f6797be4de_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-cloud-controller-manager-rhel9-operator@sha256:f5e2d88bafaf160284efad9566092ff255cd0949426877300d82d414aeca0530_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-cluster-config-api-rhel9@sha256:4ddbedc3fe8ace7360ebe8eeec1437ede37c773f28c4fab48e69ad60fd9bf08a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- +105 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:81874cf1470a55c07baa9ffa0722efd3819c8ed54c15244713d3c20b231eb516 (For s390x architecture) The image digest is sha256:8ce860bf1a7abb3ac033daa8e0e29b147b694fadf04ad7fcc6476aa66f40fb48 (For ppc64le architecture) The image digest is sha256:294a17de9476ae1d89f0258f196c8825b3b122010ac89846e1e3d8085352b42b (For aarch64 architecture) The image digest is sha256:8800b38e920e726cecf55edce79e8c94d310d6a96058a34cd4dd666119e74397 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: The process is identical to CVE-2024-6387, by disabling LoginGraceTime. See that CVE page for additional details.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2024:4955
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295085
- externalhttps://issues.redhat.com/browse/OCPBUGS-35837
- externalhttps://issues.redhat.com/browse/OCPBUGS-36278
- externalhttps://issues.redhat.com/browse/OCPBUGS-36563
- externalhttps://issues.redhat.com/browse/OCPBUGS-36821
- externalhttps://issues.redhat.com/browse/OCPBUGS-36885
- externalhttps://issues.redhat.com/browse/OCPBUGS-37061
- externalhttps://issues.redhat.com/browse/OCPBUGS-37196
- externalhttps://issues.redhat.com/browse/OCPBUGS-37198
- externalhttps://issues.redhat.com/browse/OCPBUGS-37205
- externalhttps://issues.redhat.com/browse/OCPBUGS-37306
- externalhttps://issues.redhat.com/browse/OCPBUGS-37419
- externalhttps://issues.redhat.com/browse/OCPBUGS-37458
- externalhttps://issues.redhat.com/browse/OCPBUGS-37524
- externalhttps://issues.redhat.com/browse/OCPBUGS-37549
- externalhttps://issues.redhat.com/browse/OCPBUGS-37554
- externalhttps://issues.redhat.com/browse/OCPBUGS-37629
- externalhttps://issues.redhat.com/browse/OCPBUGS-37677
- externalhttps://issues.redhat.com/browse/OCPBUGS-37695
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4955.json