-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat OpenShift support for Windows Containers 5.1.2 security update
Advisory ID:       RHSA-2023:4835-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:4835
Issue date:        2023-08-29
CVE Names:         CVE-2023-3676 CVE-2023-3955 
=====================================================================

1. Summary:

The components for Red Hat OpenShift support for Windows Containers 5.1.2
are now available. This product release includes bug fixes and security
updates for the following packages: windows-machine-config-operator and
windows-machine-config-operator-bundle.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift support for Windows Containers allows you to deploy
Windows container workloads running on Windows Server containers.

Security Fix(es):

* kubernetes: Insufficient input sanitization on Windows nodes leads to
privilege escalation (CVE-2023-3676)

* kubernetes: Insufficient input sanitization on Windows nodes leads to
privilege escalation (CVE-2023-3955)

For more details about the security issue(s), including the impact, CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For Windows Machine Config Operator upgrades, see the following
documentation:
https://docs.openshift.com/container-platform/4.14/windows_containers/windows-node-upgrades.html

4. Bugs fixed (https://bugzilla.redhat.com/):

2227126 - CVE-2023-3676 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation
2227128 - CVE-2023-3955 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation

5. References:

https://access.redhat.com/security/cve/CVE-2023-3676
https://access.redhat.com/security/cve/CVE-2023-3955
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJk7gY6AAoJENzjgjWX9erEUaQP+wU4my4rzFBFp7Z5C2ofs3nn
7TvEeLB3KI9qPqM4RgLVzybQBZPAlBVWiLtRJeqgwiRX1odZLbAtN1Gr42oL8eGw
vqmCo1KKaO/oVFFZsZv7YuyThiWEZ0a1Rswg9Cai5bEeFOI7+8HlylEtwTiSUmWx
22ysenpUOeQPMgOTaVE0XNDwuSEukrmNo391stLAfSyAx3p9wiX3tNO25y+VvNLj
3CD0yHyWqC0lkyK2gXzsv4lt2BFoZNpXPvGji+NeO1HLs3Ni81B4CmRbxREPep3h
/mfqSaTCnPOGz5DRb8a4f8SRvGlck7on1I7Strlf1infSZuDtnv4Bt9MzV1CfbMi
T89euKSKr/vCqelRXBuSyRgjsgTlqvP5aFFVF4o/ngDOC5y5/rLjg6enUrQdD6BB
u+T5/nBU4yzb84SD5RE9KCPWUbXmb5F7ksCXDyciwanN+G4GBKFiCrsE28kK9C78
ZcP4z9ypfRFjBtVgHrMhnWhvXRu0S5bIs+1zXw027cmsN5X9dA2NV+ROMICPqJZm
aQHJAWLoTd5Gxdqj0itUN7W/TfIO7kf4kvJezgkC8YRdaQWpmLNQ9xbEV6rTm72a
LBoENzd38TIK8BKj+I1oTVmPpQk0y6yXjxDLTUSDGvp+z3ibhkBO9oFaLJDxG24y
4SLyqK+bCiTx33pq0ayS
=r8uD
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-4835:01 Important: Red Hat OpenShift support for Windows

The components for Red Hat OpenShift support for Windows Containers 5.1.2 are now available

Summary

Red Hat OpenShift support for Windows Containers allows you to deploy Windows container workloads running on Windows Server containers.
Security Fix(es):
* kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation (CVE-2023-3676)
* kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation (CVE-2023-3955)
For more details about the security issue(s), including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For Windows Machine Config Operator upgrades, see the following documentation: https://docs.openshift.com/container-platform/4.14/windows_containers/windows-node-upgrades.html

References

https://access.redhat.com/security/cve/CVE-2023-3676 https://access.redhat.com/security/cve/CVE-2023-3955 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2023:4835-01
Product: Red Hat OpenShift Enterprise
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4835
Issued Date: : 2023-08-29
CVE Names: CVE-2023-3676 CVE-2023-3955

Topic

The components for Red Hat OpenShift support for Windows Containers 5.1.2are now available. This product release includes bug fixes and securityupdates for the following packages: windows-machine-config-operator andwindows-machine-config-operator-bundle.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2227126 - CVE-2023-3676 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation

2227128 - CVE-2023-3955 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation


Related News