Red Hat Security Advisory: OpenShift Container Platform 4.13.48 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6409 — openssh: Possible remote code execution due to a race condition in signal handling affecting Red Hat Enterprise Linux 9 CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-36971 — kernel: net: kernel: UAF in network route management
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:0fd48182153dd12a953b569f7de8e883a386f83117506df7372c9d11a460b105_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:3748bc12024828860643016731653fe01290bb6cfc236a15fe123e4cbc2ead5b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:71ea236c12839090cb78b7eff1ad628284bbe3aba09797a8b647f2e053ccc874_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:b8a18601804ef5888dfd40fe87a1e147f68b3cfe0afbdb0e09462f9402546703_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:06d92b0e772f02885bde80e93abe75566d6af808da2cf27ba0dbff66b15cfa8a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:2810535343d4067bc799065d71cb7dfa15c9c17424873087838aed488ed4f4f3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:bccfd9cd626306fdf3b2a9d78123cd00b13ed594d52188fc958543296e49cff4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:ebb53907e6996162f543d49c4e49fbd454fb22fcba505c506e1a94be93cbef2c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:4300030a3a1933f7e536b80f8dbe1f7fdee66b974a11d44a7568810337f3e140_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:66d555d837b3cac9153128936832b0350f5df66b9a9d5d08b30a6e3cafef2faf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:93215fd022549d457199b6924e8a283441466c2fb2f32f66bd9f23692ad4d651_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:c33bf1233e1d1212066cbcc719e6256a675a942f8c91a6db3b83fba793aa84ed_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:302a128b27a0e8f65d42674371f8572483a3a43fcbbd0f44a6014046a89a4831_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:7aa3534cddf315bcb6fdbb5d8ae8e18540a8f0cae36a9bfdff5970ec519b3c60_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:9a097ffa9c1bce7fbab1b754d25e3cf4253758df8754c25d4cbcf7d655f924a4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:da4c83ccbf9548e9f5dc27e6fbaeed4d3e12db8eca3651f8fe04b15461ea588a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:0529bf3520a065711ae55bd9d8bbb774ca384c702a309df16e3e5384f4ae82a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:412e0c8cac64a7f1c4649a89d8ea98cf3233a9fbfaedf0691a944a4ad182cb57_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cfcbdfca0c4fe3a9856663bc67b3d9dfaf5cf240191f4314960196fdb712bbb4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:f397b8b6a302ece79eab0f3a7198f219ca39786410cf36cd8ea691f95894ad75_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:35f5d7e7277529701d3b6cf69ace3ebc797a4c630ec1d21a6286826a88a092d0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:386186a97e110fadf0c809c4046b4136ccffd907c1f0ee731ef265e1df019c91_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:99dbd0cbeda1a219651bb01f81f75bc3da55ec7433239afbf0fa7ab33e839ffd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:a44ca56c69938311a0bf70375645bb59de283cfc4012c7f90347e35f07d150a3_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:f56384eea8a08532f9b286d416185584974737114816d97a8900d268ce59d6a5_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1877d8a72a6329264c16c670c3c3d2515806b47eab594261d4ae3374238d6fa1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:34e1a3077a54eb240503c5d388b97927e9b7f4a3d0ffc8aa68777f4ba4f8a851_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:36be23595fe3687ebc91a94a86a10fef4660f0f5fc38b4b9f89c611620860516_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8224e41439569f14946318d7365521163a16ee6e9470bdc7e181a9e05f5722ad_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:7235b8e139da4ba4c17c2b4b9864c05c93c5f55f7c2f561e7f9796c7e6589917 (For s390x architecture) The image digest is sha256:04865553b69831321134ca4e61be8ad02548ccfd41a2941c09bf357d5120dbde (For ppc64le architecture) The image digest is sha256:471fc8ffaa8d14e5aff88b91dcf378291aec41ab524aa88a1562f4767bf57b62 (For aarch64 architecture) The image digest is sha256:83ddfc54da02ab4f523d181c7e9eeb24b3deef3bf6da3052e6db894f246c7a99 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The process is identical to CVE-2024-6387, by disabling LoginGraceTime. See that CVE page for additional details. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:5444
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292331
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295085
- externalhttps://issues.redhat.com/browse/OCPBUGS-29124
- externalhttps://issues.redhat.com/browse/OCPBUGS-35259
- externalhttps://issues.redhat.com/browse/OCPBUGS-37119
- externalhttps://issues.redhat.com/browse/OCPBUGS-37168
- externalhttps://issues.redhat.com/browse/OCPBUGS-37421
- externalhttps://issues.redhat.com/browse/OCPBUGS-37783
- externalhttps://issues.redhat.com/browse/OCPBUGS-38295
- externalhttps://issues.redhat.com/browse/OCPBUGS-38372
- externalhttps://issues.redhat.com/browse/OCPBUGS-38403
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5444.json