First published: Wed Aug 11 2021(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation (CVE-2021-3121)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>You may download the oc tool and use it to inspect release image metadata<br>as follows:<br>(For x86_64 architecture)<br>$ oc adm release info<br>quay.io/openshift-release-dev/ocp-release:4.7.23-x86_64<br>The image digest is<br>sha256:fb00f5e16a2092c3f15113ad8de0d2e841abdb43c9c39794522fc79784a3efb0<br>(For s390x architecture)<br>$ oc adm release info<br>quay.io/openshift-release-dev/ocp-release:4.7.23-s390x<br>The image digest is<br>sha256:5e633adb1d47cd2c0a000caa02d937074cab4e3b601b99d71368604c3109c632<br>(For ppc64le architecture)<br>$ oc adm release info<br>quay.io/openshift-release-dev/ocp-release:4.7.23-ppc64le<br>The image digest is<br>sha256:7adfc7d4513763ac62700f3d5eb7fd9050b925de8e9ccc5b2bb6dee593522c5a<br>All OpenShift Container Platform 4.7 users are advised to upgrade to these<br>updated packages and images when they are available in the appropriate<br>release channel. To check for available updates, use the OpenShift Console<br>or the CLI oc command. Instructions for upgrading a cluster are available<br>at<br><a href="https://docs.openshift.com/container-platform/4.7/updating/updating-cluster" target="_blank">https://docs.openshift.com/container-platform/4.7/updating/updating-cluster</a> <li>between-minor.html#understanding-upgrade-channels_updating-cluster-between</li> <li>minor</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:2977 has been rated as critical due to the lack of index validation in the gogo/protobuf plugin.
To fix RHSA-2021:2977, you should update your Red Hat OpenShift Container Platform to the latest version that addresses this vulnerability.
RHSA-2021:2977 affects Red Hat OpenShift Container Platform deployments.
RHSA-2021:2977 addresses the vulnerability CVE-2021-3177 related to gogo/protobuf index validation.
There are no documented workarounds for RHSA-2021:2977; the recommended action is to apply the available updates.