- Issued:
- 2021-08-16
- Updated:
- 2021-08-16
RHBA-2021:3121 - Bug Fix Advisory
Synopsis
OpenShift Container Platform 4.8.5 security update
Type/Severity
Bug Fix Advisory
Topic
Red Hat OpenShift Container Platform release 4.8.5 is now available with
updates to packages and images that fix several bugs and add enhancements.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.8.5. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2021:3122
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-rel ease-notes.html
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.8.5-x86_64
The image digest is
sha256:7047acb946649cc1f54d98a1c28dd7b487fe91479aa52c13c971ea014a66c8a8
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.8.5-s390x
The image digest is
sha256:8df1865fd1c39d92fc51fae82f4283e88ad2af259dd1a5b024598154b11ca2f0
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.8.5-ppc64le
The image digest is
sha256:7abb488ba5ca69227eb8ab1ec56f690d09e2933927b8e3761ba2d8ff6b435845
All OpenShift Container Platform 4.8 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.8/updating/updating-cluster
- between-minor.html#understanding-upgrade-channels_updating-cluster-between
- minorKubernetes application platform solution designed for on-premise or private
cloud deployments.
Solution
For OpenShift Container Platform 4.8 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html
Affected Products
- Red Hat OpenShift Container Platform 4.8 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for Power 4.8 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.8 for RHEL 8 s390x
Fixes
- BZ - 1920670 - [IPI baremetal] Keepalived - priority 0 advertisement message not being sent when the container is Sigtermed
- BZ - 1932658 - test `DNS should provide DNS for the cluster` fails on vsphere
- BZ - 1957133 - Unable to attach Vsphere volume shows the error "failed to get canonical path"
- BZ - 1960577 - Managed cluster should ensure ptp pods components have system-* priority class associated
- BZ - 1963730 - kube-apiserver failed to load SNI cert and key
- BZ - 1971911 - Should not show getting started links when add page customization disabled these entries
- BZ - 1972258 - Event sources in Developer console lists also action and sink kamelets
- BZ - 1973696 - Set a specific time range, but Dashboards display data with a different time range
- BZ - 1974267 - oc logs doesn't work with piepeline builds
- BZ - 1974877 - [release-4.8] Add egress ips to anonymizer to 4.8
- BZ - 1975137 - Sync ironic containers with latest ironic code
- BZ - 1976144 - Unable to uncheck the optional workspace checkbox in pipeline builder
- BZ - 1976765 - AlertmanagerMembersInconsistent fires too quickly, causing serial-test noise
- BZ - 1977754 - (release-4.8] Gather all MachineConfig definitions
- BZ - 1977782 - Editing a Deployment drops annotations
- BZ - 1978090 - 4.7 -> 4.8 upgrades fail on "[sig-network] pods should successfully create sandboxes by other" for pods which eventually start
- BZ - 1981548 - AWS Elastic IP permissions are incorrectly required
- BZ - 1982778 - Thanos querier probes are timing out
- BZ - 1984074 - Reduce CPU overhead for ignore-listed NICs
- BZ - 1984242 - Import from YAML breaks console when three dash separator at the end
- BZ - 1985356 - Console's OperatorHub leads users to unrelated install plan, if subscription does not have its own
- BZ - 1985908 - Tuned affining containers to house keeping cpus
- BZ - 1986023 - OLM dependencies not fixing version
- BZ - 1986581 - Web console doesn't list all the registries credentials in a secret
- BZ - 1986992 - cluster-node-tuning-operator needs to handle API server downtime gracefully in SNO
- BZ - 1988478 - Driver Toolkit ART / OSBS builds are failing because of extract-vmlinux
- BZ - 1988991 - 4.7 -> 4.8 upgrade, node-exporter can't rollout
- BZ - 1989152 - [e2e][automation] missing file for testing release-4.8
- BZ - 1989587 - Authentication operator fails to become available during upgrade to 4.8.2
- BZ - 1989711 - Invalid olm.maxOpenShiftVersion properties have unclear/undefined behavior in OLM
- BZ - 1989779 - Install plans permanently fail due to CRD resource modified or similar transient errors
- BZ - 1990370 - Router HAProxy backend balance option is blank missing random argument in haproxy.config
- BZ - 1990650 - Add necessary priority class to marketplace components
CVEs
(none)
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.