RHSA-2021:0030: Moderate: OpenShift Container Platform 4.4.32 packages and security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): kubernetes: compromised node could escalate to cluster level privileges (CVE-2020-8559)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.This advisory contains the RPM packages for Red Hat OpenShift ContainerPlatform 4.4.32. See the following advisory for the container images forthis release:https://access.redhat.com/errata/RHBA-2021:0029 All OpenShift Container Platform 4.4 users are advised to upgrade to theseupdated packages and images when they are available in the appropriaterelease channel. To check for available updates, use the OpenShift Consoleor the CLI oc command. Instructions for upgrading a cluster are availableathttps://docs.openshift.com/container-platform/4.4/updating/updating-cluster-between-minor.html#understanding-upgrade-channelsupdating-cluster-between-minor.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0030?
RHSA-2021:0030 has been classified with a moderate severity level.
How do I fix RHSA-2021:0030?
To fix RHSA-2021:0030, update your openshift and openshift-hyperkube packages to the latest remedied versions.
What is the impact of RHSA-2021:0030?
The impact of RHSA-2021:0030 is that a compromised node could escalate to cluster-level privileges.
Which versions are affected by RHSA-2021:0030?
RHSA-2021:0030 affects certain versions of openshift and openshift-hyperkube up to 4.4.0-202012052258.p0.git.0.0fd57a4.el8.
Is there a workaround for RHSA-2021:0030 until I can apply the fix?
Currently, there is no documented workaround for RHSA-2021:0030; applying the update is recommended.