Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Red Hat OpenShift 4.7 RHSA-2020-5364 Moderate: DoS Fix Available

red hat
Calendar Grey February 24, 2021
Dist Redhat Esm H88
Red Hat's recent announcement highlights essential updates for OpenShift version 4.7 containers, emphasizing improved performance and security vulnerability fixes
An update for cnf-tests-container, dpdk-base-container, performance-addon-operator-bundle-registry-container, performance-addon-operator-container, and performance-addon-operator-m...

Solution

For OpenShift Container Platform 4.7 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.7/html/release_notes/ocp-4-7-release-notes

Summary

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.
This advisory contains the extra low-latency container images for Red Hat OpenShift Container Platform 4.7. See the following advisory for the container images for this release:
https://access.redhat.com/errata/RHSA-2020:5633
Security Fix(es):
* golang-github-gorilla-websocket: integer overflow leads to denial of service (CVE-2020-27813)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Configuring the system with non-RT kernel will hang the system (BZ#1923220)

References

https://access.redhat.com/security/cve/CVE-2018-20843 https://access.redhat.com/security/cve/CVE-2019-5018 https://access.redhat.com/security/cve/CVE-2019-13050 https://access.redhat.com/security/cve/CVE-2019-13627 https://access.redhat.com/security/cve/CVE-2019-14889 https://access.redhat.com/security/cve/CVE-2019-15165 https://access.redhat.com/security/cve/CVE-2019-15903 https://access.redhat.com/security/cve/CVE-2019-16168 https://access.redhat.com/security/cve/CVE-2019-16935 https://access.redhat.com/security/cve/CVE-2019-17450 https://access.redhat.com/security/cve/CVE-2019-19221 https://access.redhat.com/security/cve/CVE-2019-19906 https://access.redhat.com/security/cve/CVE-2019-19956 https://access.redhat.com/security/cve/CVE-2019-20218 https://access.redhat.com/security/cve/CVE-2019-20387 https://access.redhat.com/security/cve/CVE-2019-20388 https://access.redhat.com/security/cve/CVE-2019-20454 https://access.redhat.com/security/cve/CVE-2019-20907 https://access.redhat.com/security/cve/CVE-2019-20916 https://access.redhat.com/security/cve/CVE-2020-1730 https://access.redhat.com/security/cve/CVE-2020-1751 https://access.redhat.com/security/cve/CVE-2020-1752 https://access.redhat.com/security/cve/CVE-2020-1971 Read the Full Advisory

Package List


Advisory ID: RHSA-2020:5364-01
Product: Red Hat OpenShift Enterprise
Issue date: 2021-02-24

Topic

An update for cnf-tests-container, dpdk-base-container,performance-addon-operator-bundle-registry-container,performance-addon-operator-container, andperformance-addon-operator-must-gather-rhel8-container is now available forRed Hat OpenShift Container Platform 4.7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

1902111 - CVE-2020-27813 golang-github-gorilla-websocket: integer overflow leads to denial of service

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

CNF-802 - Infrastructure-provided enablement/disablement of interrupt processing for guaranteed pod CPUs

CNF-854 - Performance tests in CNF Tests

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here