RHSA-2024:0040: Critical: OpenShift Container Platform 4.16.0 security and extras update
Critical: OpenShift Container Platform 4.16.0 security and extras update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container<br>Platform 4.16.0. See the following advisory for the container images for<br>this release:<br><a href="https://access.redhat.com/errata/RHSA-2024:0041" target="blank">https://access.redhat.com/errata/RHSA-2024:0041</a> Security Fix(es):<br><li> ssh: Prefix truncation attack on Binary Packet Protocol (BPP)</li> (CVE-2023-48795)<br><li> golang-protobuf: encoding/protojson, internal/encoding/json: infinite</li> loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON<br>(CVE-2024-24786)<br><li> cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks</li> credentials (CVE-2024-28110)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.<br>All OpenShift Container Platform 4.16 users are advised to upgrade to these<br>updated packages and images when they are available in the appropriate<br>release channel. To check for available updates, use the OpenShift CLI (oc)<br>or web console. Instructions for upgrading a cluster are available at<br><a href="https://docs.openshift.com/container-platform/4.16/updating/updatingacluster/updating-cluster-cli.html" target="blank">https://docs.openshift.com/container-platform/4.16/updating/updatingacluster/updating-cluster-cli.html</a>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0040?
RHSA-2024:0040 is classified as a critical vulnerability in Red Hat OpenShift Container Platform 4.16.0.
What does RHSA-2024:0040 address?
RHSA-2024:0040 addresses security vulnerabilities and provides updates for additional packages in Red Hat OpenShift Container Platform.
How do I fix RHSA-2024:0040?
To fix RHSA-2024:0040, update the affected Red Hat OpenShift Container Platform to the latest version provided in the security advisory.
Which Red Hat products are affected by RHSA-2024:0040?
RHSA-2024:0040 affects Red Hat OpenShift Container Platform for ARM 64, Power, and IBM Z and LinuxONE.
Is RHSA-2024:0040 included in my subscription?
If you have a subscription for Red Hat OpenShift Container Platform, RHSA-2024:0040 should be included in your updates.