RHSA-2024:0642: Critical: OpenShift Container Platform 4.14.11 bug fix and security update
Critical: OpenShift Container Platform 4.14.11 bug fix and security update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.11. See the following advisory for the RPM packages for this release:<br><a href="https://access.redhat.com/errata/RHBA-2024:0645" target="blank">https://access.redhat.com/errata/RHBA-2024:0645</a> Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:<br><a href="https://docs.openshift.com/container-platform/4.14/releasenotes/ocp-4-14-release-notes.html" target="blank">https://docs.openshift.com/container-platform/4.14/releasenotes/ocp-4-14-release-notes.html</a> Security Fix(es):<br><li> golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)</li> <li> go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients (CVE-2023-49569)</li> <li> go-git: Maliciously crafted Git server replies can cause DoS on go-git clients (CVE-2023-49568)</li> <li> opentelemetry: DoS vulnerability in otelhttp (CVE-2023-45142)</li> <li> opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics (CVE-2023-47108)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0642?
The severity of RHSA-2024:0642 is classified as critical.
How do I fix RHSA-2024:0642?
To fix RHSA-2024:0642, it is recommended to update the affected Red Hat OpenShift Container Platform to the latest available version.
Which products are affected by RHSA-2024:0642?
RHSA-2024:0642 affects various versions of Red Hat OpenShift Container Platform including those for ARM 64, Power, IBM Z, and LinuxONE.
What types of issues does RHSA-2024:0642 address?
RHSA-2024:0642 addresses bug fixes and security vulnerabilities within the Red Hat OpenShift Container Platform.
When was RHSA-2024:0642 released?
RHSA-2024:0642 was released to provide updates for OpenShift Container Platform version 4.14.11.