-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat OpenShift support for Windows Containers 8.0.2 security update
Advisory ID:       RHSA-2023:4885-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:4885
Issue date:        2023-08-30
CVE Names:         CVE-2023-3676 CVE-2023-3955 
=====================================================================

1. Summary:

The components for Red Hat OpenShift support for Windows Containers 8.0.2
are now available. This product release includes bug fixes and security
updates for the following packages: windows-machine-config-operator and
windows-machine-config-operator-bundle.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift support for Windows Containers allows you to deploy
Windows container workloads running on Windows Server containers.

Security Fix(es):

* kubernetes: Insufficient input sanitization on Windows nodes leads to
privilege escalation (CVE-2023-3676)

* kubernetes: Insufficient input sanitization on Windows nodes leads to
privilege escalation (CVE-2023-3955)

For more details about the security issue(s), including the impact, CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For Windows Machine Config Operator upgrades, see the following
documentation:
https://docs.openshift.com/container-platform/4.14/windows_containers/windows-node-upgrades.html

4. Bugs fixed (https://bugzilla.redhat.com/):

2227126 - CVE-2023-3676 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation
2227128 - CVE-2023-3955 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation

5. References:

https://access.redhat.com/security/cve/CVE-2023-3676
https://access.redhat.com/security/cve/CVE-2023-3955
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJk7+KuAAoJENzjgjWX9erE3lMP/2jePX7S115czncgIpDraYAR
x8aCx7Kyk6iIRDHIXYM3TOIRLDJHVX7/3oFxl4cCAd4/DskE5jchlrw3QWVC8qfp
InGscpQWdAJN+jtRz8IpJLpR6YYJ79/3lMHkCZQ05zcFG0yEv2VBTTpffOpjuAg5
kD2KVwbT7TR7Pfbj2chQ9rZW2yppBuYgXq6l5Ssma+HoHkgzi+dj+E6GtZyptJX+
7704STpEYHVRnooatp+eYpTkHwXdelQMZsD4PmjTWCEqC5UuuHUNMQ01lsnsY/IK
mUwUgIwG0Lp7qSGunzS39kQqmE/KFVZ+BCjinx00OidBuSM6Q2NNYxjlvljBdptt
kkhHcgYNCkD1Jbm2rM8Iz9tdLsW/+pru4gQ40FT0ZeW2FRD1cCinkV9k3301VSEh
MO9ocRTzrqEaVbKkpZy8c4wKNA049YnfoMvUSeasVpgOwhJbsuZzd6BVx2jcQkoQ
kSYv/JpHVn3p9vuqyUnmH3ANGrKSqsphDs3Z5sXykoMrcTHX5Va0913Im+dtHWw2
nHNBH82IGcSjtTB6ZnmYF1c7c7DEGTmodvwsktI4Q3K/kCE18W7QYJi66T+GZJGq
zGvn1xaKaazPpNfh2RDRq3w86v6MzpUWuEqDz7ZAVr1+AKaCLI8odGsQslajsjMJ
7yYr7+mVO9zmtqxzword
=0vpr
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-4885:01 Important: Red Hat OpenShift support for Windows

The components for Red Hat OpenShift support for Windows Containers 8.0.2 are now available

Summary

Red Hat OpenShift support for Windows Containers allows you to deploy Windows container workloads running on Windows Server containers.
Security Fix(es):
* kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation (CVE-2023-3676)
* kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation (CVE-2023-3955)
For more details about the security issue(s), including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For Windows Machine Config Operator upgrades, see the following documentation: https://docs.openshift.com/container-platform/4.14/windows_containers/windows-node-upgrades.html

References

https://access.redhat.com/security/cve/CVE-2023-3676 https://access.redhat.com/security/cve/CVE-2023-3955 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2023:4885-01
Product: Red Hat OpenShift Enterprise
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4885
Issued Date: : 2023-08-30
CVE Names: CVE-2023-3676 CVE-2023-3955

Topic

The components for Red Hat OpenShift support for Windows Containers 8.0.2are now available. This product release includes bug fixes and securityupdates for the following packages: windows-machine-config-operator andwindows-machine-config-operator-bundle.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2227126 - CVE-2023-3676 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation

2227128 - CVE-2023-3955 kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation


Related News