For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.7/html/release_notes/ocp-4-7-release-notes
Details on how to access this content are available at
- -cli.html.
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the RPM packages for Red Hat OpenShift Container
Platform 4.7.0. See the following advisory for the container images for
this release:
https://access.redhat.com/errata/RHSA-2020:5633
All OpenShift Container Platform 4.7 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
- -between-minor.html#understanding-upgrade-channels_updating-cluster-between
- -minor.
Security Fix(es):
* gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index
validation (CVE-2021-3121)
* kubernetes: Ceph RBD adminSecrets exposed in logs when loglevel >= 4
(CVE-2020-8566)
* containerd: credentials leak during image pull (CVE-2020-15157)
* python-rsa: bleichenbacher timing oracle attack against RSA decryption
(CVE-2020-25658)
* atomic-openshift: cross-namespace owner references can trigger deletions
of valid children (CVE-2019-3884)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2019-3884 https://access.redhat.com/security/cve/CVE-2020-8566 https://access.redhat.com/security/cve/CVE-2020-15157 https://access.redhat.com/security/cve/CVE-2020-25658 https://access.redhat.com/security/cve/CVE-2021-3121 https://access.redhat.com/security/updates/classification#moderate
Red Hat OpenShift Container Platform 4.7:
Source:
conmon-2.0.21-2.rhaos4.6.el7.src.rpm
containernetworking-plugins-0.8.6-1.rhaos4.5.el7.src.rpm
cri-o-1.20.0-0.rhaos4.7.git8921e00.el7.51.src.rpm
cri-tools-1.18.0-3.el7.src.rpm
haproxy-2.0.19-1.el7.src.rpm
jq-1.6-2.el7.src.rpm
oniguruma-5.9.2-5.el7.src.rpm
openshift-4.7.0-202102060108.p0.git.97095.7271b90.el7.src.rpm
openshift-ansible-4.7.0-202102032256.p0.git.0.bf7d9a7.el7.src.rpm
openshift-clients-4.7.0-202102032256.p0.git.3951.0e656ef.el7.src.rpm
python-botocore-1.4.57-5.el7.src.rpm
runc-1.0.0-82.rhaos4.6.git086e841.el7.src.rpm
noarch:
openshift-ansible-4.7.0-202102032256.p0.git.0.bf7d9a7.el7.noarch.rpm
openshift-ansible-test-4.7.0-202102032256.p0.git.0.bf7d9a7.el7.noarch.rpm
python2-botocore-1.4.57-5.el7.noarch.rpm
x86_64:
conmon-2.0.21-2.rhaos4.6.el7.x86_64.rpm
containernetworking-plugins-0.8.6-1.rhaos4.5.el7.x86_64.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.5.el7.x86_64.rpm
cri-o-1.20.0-0.rhaos4.7.git8921e00.el7.51.x86_64.rpm
cri-o-debuginfo-1.20.0-0.rhaos4.7.git8921e00.el7.51.x86_64.rpm
cri-tools-1.18.0-3.el7.x86_64.rpm
cri-tools-debuginfo-1.18.0-3.el7.x86_64.rpm
haproxy-debuginfo-2.0.19-1.el7.x86_64.rpm
haproxy20-2.0.19-1.el7.x86_64.rpm
jq-1.6-2.el7.x86_64.rpm
jq-debuginfo-1.6-2.el7.x86_64.rpm
Read the Full Advisory
Red Hat OpenShift Container Platform release 4.7.0 is now available.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat OpenShift Container Platform 4.7 - noarch, ppc64le, s390x, x86_64
1693905 - CVE-2019-3884 atomic-openshift: cross-namespace owner references can trigger deletions of valid children
1886640 - CVE-2020-8566 kubernetes: Ceph RBD adminSecrets exposed in logs when loglevel >= 4
1888248 - CVE-2020-15157 containerd: credentials leak during image pull
1889972 - CVE-2020-25658 python-rsa: bleichenbacher timing oracle attack against RSA decryption
1910081 - Placeholder bug for OCP 4.7.0 rpm release
1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation
Get the latest Linux and open source security news straight to your inbox.