RHSA-2024:8425HighCVSS 8.3

Red Hat Security Advisory: OpenShift Container Platform 4.15.37 bug fix and security update

Published
October 31, 2024
Last Modified
September 18, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-28110 — cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:57ec712064fda526c8327504d4aab2105c3061263afd1e7359b8bd5912bd937e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:776c1fa03c3c056a388dc7b902388e2912b52839172f67baa3dd22a618f7ef63_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:b211ffdc84790531057f33b19ee4ac8f8e6a56b04abd21df0b0a2bd9f6d03884_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:f1db1a5799bae2179e81c3a2dd373eb0ea94bb708bd415edb1e4f40d020e0e7d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:0470a1d535217fb169e3fac66db104d9aff883441f0d13991eff6bd5eb03be97_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:4bc0fbbe61938e49282127d465578a83163488ef093f599002bebca41d92b7d9_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:bfaf9c5a28a522222ec518b2947c2ff26e7ffa9a1fd3c6eba80f9075bf633c44_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:ec51e87d1ebaf50a1181cdb705a084ff2da587fc1ec1139f1cc862547ea92cab_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:6b3519d8bf265f896c5cc84aac79a0c057164266907b96b3c0104ea493aa3c28_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:98e8907b9c2f2bf24ff7bf65f54dc3ee185c6161b6ee41826f291479466d88f7_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:99c88e5543f5c9cca20d6ea934cd248136acc07f0cd202f3d0a50553ab4b2de1_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:cf708dabb5be8235860cd207fb8ed7fd59dad072c45390d073388680935e35ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:558e5c7dc5ff18477cb0f78f56bda47935d6bbb2d8abc920b96b39a63271c7d5_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:b4db69ddd02e99de3a0b1a5ec230678452d2fab127f4220d1d02cbbbedd3fa02_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:b704737cde303ce05b66b32e9015cdbb680b966ddc7c1ea1fc925c2a65f7bb49_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:f38d0dd4250269b0737adb19a13030877c6567fba8b66a766548b049cdd26e85_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:3e83c7a82b6eb0a0899e05c32cef71d15b39992d8bdd56defd957e34c877b051_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:83206b2326818440446ad973afa229c54b9256139aaf7840ef4bfb8e82c1e436_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:a8fd3aa91215dba24752f1420a8ee715da2080bb175634d65fb0cdd05183177a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:d34dc63b45a2e0f8e0fc87b2e5e116fa78891026bbb9c6c45a0707d8c593a03d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:33fe5c4a28390f09144e1f3ce43404c20a88f7c7c4c387991f565608808729b3_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:d44ddf03bf0ed9cb0ffc792034b145048847468a91bcc350fc90d256cfbdf36b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:dfe49265393a56e9822c82fad5339f76d5a55d9b094e76f26a2ecf52dc112564_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:e29a3704c4885041e87e8fada48d2e383ab06f734ac4bdf352a27abd009cfc7e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:6f2bb55934db2b0d98720563449788e50edf20b70eecf01c4aca8568b44f02a1_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:b37fbd35a8be89c9e70047196470ba75ccf304b5fa6627e3dca98dcb0d2ea970_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:c0dcc9eaa82161f66d15ec5b54025fad181807e5ba0eee31af2d003b33591047_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:e0c311ddfd2090d5cbb5ad8f6a2dc2ad8a06b446b0c529c60f92be2c9c5a5642_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:52dfe130cde7c324a84c38664113506c38bb143e5ed751aa634646c244deea56_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:da7da5023f153df1417ead29ed0a6e0998c3016a4173ca1956cf05da918b6ccb (For s390x architecture) The image digest is sha256:e128f95fd4c5edb0fd632f21a9536a0d83ee160abc3c207209e63811db61f1b5 (For ppc64le architecture) The image digest is sha256:b28ec45481140342793dec40424d8c775f6cceabc626b1591f62da8eea206648 (For aarch64 architecture) The image digest is sha256:4a2cb3e13cdf9d41c5514355c8596e61883b4870b89876f906d5ec44653138be All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (31)