RHSA-2024:6824MediumCVSS 8.3

Red Hat Security Advisory: OpenShift Container Platform 4.16.14 security update

Published
September 24, 2024
Last Modified
September 18, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-43803 — Bare Metal Operator: BMO can expose particularly named secrets from other namespaces via BMH CRD

🎯 Affected products121

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:31e5005e80d4f31e953e576306cf7c67257d1ea0e67f23df0becb17ff8c4d5c2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:78828089c880e1c7187e0e61948628721a5d686fc0f13e9804e60897c78594dd_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:9cb0e38af3d7b3bc79cda54f50146969ca4f52834a13a74df50736fa0b89162b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:fc4a33a78d59e8230791781ea5926e9a201a45d70d71fe53194b82fa0bf582fb_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:7ba513237c24c05214b5f84dea3ebd2f5acfce6f3e874ef47b8be6d74b850fcb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:a8cffde8f3ea7e5f446475c77d5815f7f6f7a8b5bba6fa85f23ed54a9e6153bb_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:d4eef75db4b42fb328435312624fd481eae6a60b9741c7b1727a88f09e50f5e3_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/network-tools-rhel9@sha256:e386bd6b25eb9d12e1ea380e8e19bde61b6d717fc4085c2ff495625bf7b6599c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:1adc2d2ab97d3478b695a3a68dbfcdd845fbf80d9d2a945c3e0254d9e9439c33_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:1c4b4c5a60dcfdda7efff3ff7f872818705838efce31e0b39373d020b30ad4f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:40f530a556977bfa19e58bfde7101e622424de65a0a9949da8b26d87c49dee7c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-api-server-rhel9@sha256:5a7a7e5ef9f32ccad34f0ebe3c09bb6297b99673e80ef3474d93e161ce2dd0b1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:33516a841e32c04c6e4ec752143831098c9a72ede3f36c1ac0fced5326142c2e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:44729e4283cff8f8406b7a1f28530eacda8156de7df8477f3911d5b861b3a6e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:714d0b45472e190849c890c80e257b64c4a685d0f0368629082d602566c11d42_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:b9f05ac7b5a6314c855a2ca7883aec45b71d23a8a7aef5e5477d33c26f085560_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-installer-rhel9@sha256:2bc033a4f5e23f63bfbb83a5f84cf917c0add171af3b01f958e3a20e9bb07742_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-installer-rhel9@sha256:41196df24c4f256b46b53463d022a8632b6ffea5d397c1e0c6f8cf4a434babd7_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-installer-rhel9@sha256:ac0755e6b6d19452c63af18f4082a387981dbde70b597902a5aa213a27a4082b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-installer-rhel9@sha256:ce79dfdb1ae435829bcdac0f51a7a25ba299fb7e7845b428489f31eb7ba0f04d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-rhel9-operator@sha256:112b3425320153e99d849c7504fd15fbf4da3c1a368ede93a57c8cd6d9eb727e_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-rhel9-operator@sha256:556e01f12bf0a0e8ca58180117e18a850bdba719fd75dd24b27b5f990cb86b5d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-rhel9-operator@sha256:668064a51555749931487c8a86a47bedb98bfe4d54bded3da613e73b848e52be_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-baremetal-rhel9-operator@sha256:de5033d11f6c639de1b06740b31945162aae8646c8e7b5e484c852f26e92a17d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-image-registry-rhel9-operator@sha256:0a8fffa32447a35c1cd0ef3a463e2af132a9e9aa03a8d65b43c1ad6f0eab9832_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-image-registry-rhel9-operator@sha256:4b5f20bf03294e377f8e8784cc8ee976bab1c8243947c39bf52c4bc77e0b3695_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-image-registry-rhel9-operator@sha256:600bbd69fe2ab78844231034820273f9716c23f86fc1d9cb81ad7d80f2cc78ab_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-image-registry-rhel9-operator@sha256:ac0c984e3c435668f91c9d042f9634b6f4e02d63a76bc8943bcda8b5a73eb44c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/ose-cluster-monitoring-rhel9-operator@sha256:15bfcb901bd2f36f622dde8f25206642c26972f99ddbcaaaa4b2c1896ef4eb87_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • +91 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:0521a0f1acd2d1b77f76259cb9bae9c743c60c37d9903806a3372c1414253658 (For s390x architecture) The image digest is sha256:10935ec4eff66bc610801300a4376e6d733631e93681ef1dae5f0962fec98681 (For ppc64le architecture) The image digest is sha256:dbf7aec1bd0a24fd5a23d6ac927d101b7e0cfcb8d4ccb8c440b2ed17a0dd9705 (For aarch64 architecture) The image digest is sha256:76eb80594e33fc9300a0f36e4402e5232681eddf948b995a8d1acfd2fc7d72f9 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The Operator can configure BMO RBAC to be the namespace scoped for Secrets, instead of the cluster scoped to prevent BMO from accessing Secrets from other namespaces.

🔗 References (28)