{"id":21147,"date":"2022-03-01T18:58:27","date_gmt":"2022-03-01T15:58:27","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166173\/RHSA-2022-0655-01.txt"},"modified":"2022-03-02T12:26:07","modified_gmt":"2022-03-02T08:56:07","slug":"red-hat-security-advisory-2022-0655-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-0655-01\/","title":{"rendered":"Red Hat Security Advisory 2022-0655-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Low: OpenShift Container Platform 4.9.23 bug fix and security update<br \/>\nAdvisory ID: RHSA-2022:0655-01<br \/>\nProduct: Red Hat OpenShift Enterprise<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0655<br \/>\nIssue date: 2022-02-28<br \/>\nCVE Names: CVE-2021-39293<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p dir=\"ltr\">Red Hat OpenShift Container Platform release 4.9.23 is now available with<br \/>\nupdates to packages and images that fix several bugs and add enhancements.<\/p>\n<p dir=\"ltr\">This release includes a security update for Red Hat OpenShift Container<br \/>\nPlatform 4.9.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Low. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">Red Hat OpenShift Container Platform is Red Hat&#8217;s cloud computing<br \/>\nKubernetes application platform solution designed for on-premise or private<br \/>\ncloud deployments.<\/p>\n<p dir=\"ltr\">This advisory contains the container images for Red Hat OpenShift Container<br \/>\nPlatform 4.9.23. See the following advisory for the RPM packages for this<br \/>\nrelease:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/errata\/RHBA-2022:0654<\/p>\n<p dir=\"ltr\">Space precludes documenting all of the container images in this advisory.<br \/>\nSee the following Release Notes documentation, which will be updated<br \/>\nshortly for this release, for details about these changes:<\/p>\n<p dir=\"ltr\">https:\/\/docs.openshift.com\/container-platform\/4.9\/release_notes\/ocp-4-9-release-notes.html<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* golang: archive\/zip: malformed archive may cause panic or memory<br \/>\nexhaustion (incomplete fix of CVE-2021-33196) (CVE-2021-39293)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s)<br \/>\nlisted in the References section.<\/p>\n<p dir=\"ltr\">You may download the oc tool and use it to inspect release image metadata<br \/>\nas follows:<\/p>\n<p dir=\"ltr\">(For x86_64 architecture)<\/p>\n<p dir=\"ltr\">$ oc adm release info<br \/>\nquay.io\/openshift-release-dev\/ocp-release:4.9.23-x86_64<\/p>\n<p dir=\"ltr\">The image digest is<br \/>\nsha256:1c13f0926c37c122eb5c86afd754c007f38977c8fc32d7da090490f556945afd<\/p>\n<p dir=\"ltr\">(For s390x architecture)<\/p>\n<p dir=\"ltr\">$ oc adm release info<br \/>\nquay.io\/openshift-release-dev\/ocp-release:4.9.23-s390x<\/p>\n<p dir=\"ltr\">The image digest is<br \/>\nsha256:24e3fcc5f5f28df01668ad412afbc002a110709da52803fe19d6e1ef785fa654<\/p>\n<p dir=\"ltr\">(For ppc64le architecture)<\/p>\n<p dir=\"ltr\">$ oc adm release info<br \/>\nquay.io\/openshift-release-dev\/ocp-release:4.9.23-ppc64le<\/p>\n<p dir=\"ltr\">The image digest is<br \/>\nsha256:4be36ad64852e2f241b78a3481474cd2cf124da8ec2d9263edf4264bfbc8c7f4<\/p>\n<p dir=\"ltr\">All OpenShift Container Platform 4.9 users are advised to upgrade to these<br \/>\nupdated packages and images when they are available in the appropriate<br \/>\nrelease channel. To check for available updates, use the OpenShift Console<br \/>\nor the CLI oc command. Instructions for upgrading a cluster are available<br \/>\nat<br \/>\nhttps:\/\/docs.openshift.com\/container-platform\/4.9\/updating\/updating-cluster-cli.html<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">For OpenShift Container Platform 4.9 see the following documentation, which<br \/>\nwill be updated shortly for this release, for important instructions on how<br \/>\nto upgrade your cluster and fully apply this asynchronous errata update:<\/p>\n<p dir=\"ltr\">https:\/\/docs.openshift.com\/container-platform\/4.9\/release_notes\/ocp-4-9-release-notes.html<\/p>\n<p dir=\"ltr\">Details on how to access this content are available at<br \/>\nhttps:\/\/docs.openshift.com\/container-platform\/4.9\/updating\/updating-cluster-cli.html<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1996751 &#8211; [4.9z] ovn-controller doesn&#8217;t release the memory after cluster-density run<br \/>\n2006044 &#8211; CVE-2021-39293 golang: archive\/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196)<br \/>\n2014003 &#8211; MetalLB integration: All gateway routers in the cluster answer ARP requests for LoadBalancer services IP<br \/>\n2038406 &#8211; Send custom profile metrics through telemetry<br \/>\n2040530 &#8211; [ovn] CNO should gracefully terminate ovn-northd<br \/>\n2040594 &#8211; Services of type loadbalancer do not work if the traffic reaches the node from an interface different from br-ex<br \/>\n2050271 &#8211; Latest pipeline run should be listed on the top of the pipeline run list<br \/>\n2050911 &#8211; Machine config operator reports unavailable for 23m during upgrade<br \/>\n2052307 &#8211; Failed to create cluster in AWS us-east-1 region due to a local zone is used<br \/>\n2052553 &#8211; Admin web-console inconsistent status summary of sparse ClusterOperator conditions<br \/>\n2052710 &#8211; ZTP missing support for local image registry and custom machine config<br \/>\n2052929 &#8211; oc adm must-gather &#8212; gather-network-logs doesn&#8217;t work in IPV6 environment<br \/>\n2053149 &#8211; oc adm catalog mirror throws &#8216;missing signature key&#8217; error when using file:\/\/local\/index<br \/>\n2053581 &#8211; [IPI-AWS] cluster-baremetal-operator pod in a crashloop state after patching from 4.7.21 to 4.7.36<br \/>\n2054139 &#8211; ICNI2 pods are stuck in ContainerCreating state<br \/>\n2054608 &#8211; RoleBinding in project without subject is causing &#8220;Project access&#8221; page to fail<br \/>\n2055100 &#8211; Remove dev preview badge from IBM FlashSystem deployment windows<br \/>\n2056631 &#8211; [4.9] EFS CSI driver can&#8217;t unmount volumes with &#8220;wait: no child processes&#8221;<br \/>\n2056638 &#8211; [4.9] EFS CSI driver cannot delete volumes under load<br \/>\n2056826 &#8211; console-master-e2e-gcp-console is broken<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2021-39293<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#low<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYh1JHNzjgjWX9erEAQhHiw\/\/b+sOPrk39IzEavMbe6DVgtf1eIXVWwUT<br \/>\nX0BX8aolpT63TnLhOxOyk+xPRH5MzOBiKVlHinTD7pmwCjLGvKdDLNhJisLBx3Ht<br \/>\n7n0a5TEJfTvM2k4DSi\/VIpNrn7nQJESyYMWJln+ncSJHIqhpHzG5qhbqpS3YpQyP<br \/>\neE9AUXWccFHGIJC0wUsIdrTWr+STKeqf6NeimjjhwZ\/TUNdfeTmPIsaoo4fNPNOu<br \/>\nmiPC+55eaS8ghU4i7J3C4KrcLu0k0uk3XwAugxP2rIUhBVT460fdL9Af11dzxFm0<br \/>\n7ICNQxmvPNhmN\/uMhlbX+61md8F+tATTN23\/l1+4OiVpFiZHcDXEbzV9jgv\/DDpo<br \/>\nqtaInzwkoDdv0T2IgtbL6r\/9PrA5NAzHIaqyDzteXDxs0OP\/yNO6OQTyE6LNynj\/<br \/>\nDrpF5cfRqm1JDz2dNLlgJWbx7QG\/IFrz76ieaBr01PVO4ajcUjw3y\/Q3yPVEXuGX<br \/>\nk6BGsrJAb8PLk9Tybr7Ez0cjKyDqcmnfHdf6vW2DyUcLCJayWsuvT+cH3mLjvbDJ<br \/>\nbwl5KUEL8uRcPEI2DEWfQmsi6RdOIev0qkWzxG0qi30z1CXAkVez+o4fNoxy1jXv<br \/>\n6EvV4Qwbow7kcJBgkt+kaUJkd3ouDOYf10e4Ix1CiFKkV5ts6rEPQCOcVUdo9K9s<br \/>\nTpK3IEToEYo=sRVh<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n<p dir=\"ltr\">&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: OpenShift Container Platform 4.9.23 bug fix and security update Advisory ID: RHSA-2022:0655-01 Product: Red Hat OpenShift Enterprise Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0655 Issue date: 2022-02-28 CVE Names: CVE-2021-39293 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.9.23 is now available with updates to &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-21147","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=21147"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21147\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=21147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=21147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=21147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}