Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2018:1233 - Security Advisory
Issued:
2018-04-30
Updated:
2018-04-30

RHSA-2018:1233 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: OpenShift Container Platform 3.6 security and bug fix update

Type/Severity

Security Advisory: Critical

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat OpenShift Container Platform 3.6.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.

This advisory contains RPM packages for this release. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHBA-2018:1232

Security Fix(es):

  • source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go (CVE-2018-1102)

This update also fixes the following bugs:

  • Image validation used to validate old image objects, and an invalid image could be pushed to etcd. With this bug fix, validation has been changed to validate new image objects, and as a result it is no longer possible to upload an invalid image object. (BZ#1559982)
  • A panic could occur due to concurrent writes to cache. This bug fix protects writes to the cache with mutex. As a result, the cache is safe to use concurrently. (BZ#1549916)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Container Platform 3.6 x86_64

Fixes

  • BZ - 1490989 - Maximal ebs-volumes of an ec2-instance: 52/54?
  • BZ - 1549916 - [3.6][Backport] internal image registry was down due to data race
  • BZ - 1554866 - [3.6] subpath volume mounts do not work with secret, configmap, projected, or downwardAPI volumes
  • BZ - 1556796 - [3.6] Mounting file in a subpath fails if file was created in initContainer
  • BZ - 1559670 - [3.6] Fail to update EFK: 'namespace'
  • BZ - 1559982 - [3.6][Backport] oc adm migrate storage produces error as signature annotations forbidden
  • BZ - 1561236 - Kubernetes Patch request - "CreateContainerConfigError: failed to prepare subPath for volumeMount" error with configMap volume
  • BZ - 1562246 - CVE-2018-1102 source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
  • BZ - 1563317 - Mounting socket files from subPaths fail

CVEs

  • CVE-2018-1102

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 3.6

SRPM
atomic-openshift-3.6.173.0.113-1.git.0.65fb9fb.el7.src.rpm SHA-256: f7b8ccd3756b8371d1a665bdb319029936a035cf9e14cd00107fc3a038d0afdc
rubygem-cool.io-1.5.3-1.el7.src.rpm SHA-256: 70c243ba4b910b52d7878072e0904b25927df698af33d379c2cba89f7cc07d1c
rubygem-excon-0.60.0-1.el7.src.rpm SHA-256: 8910c3189ec955b193980aa76bcc2f65adeec2363751dfdb69cf3fb6bdc46545
rubygem-faraday-0.13.1-1.el7.src.rpm SHA-256: b73cc4c8dd5da17f3b1adcbb2bccc5e096b4192dc26e5a8c501d13fea5760a93
rubygem-ffi-1.9.23-1.el7.src.rpm SHA-256: ee71910d3d29190cd52bb2a06646076645c53fa6d219cc3891ed470f8bebb5f1
rubygem-fluent-plugin-kubernetes_metadata_filter-1.0.1-1.el7.src.rpm SHA-256: f5e994c4a16dec7eede38bf5dcb919138295807101f9b787b802eaa6cce7fb09
rubygem-fluent-plugin-systemd-0.0.9-1.el7.src.rpm SHA-256: 1099d8a2fe2e7ae0f4b8e62bd9885408c6b0c5836f37803430444a53229ec975
rubygem-minitest-5.10.3-1.el7.src.rpm SHA-256: de70fb3fd1a9567bfc50198d8ab088977937830d13ab70558ba48d3c3a7f872a
rubygem-msgpack-1.2.2-1.el7.src.rpm SHA-256: 654236d9e28e213957dc205ba0e46adf5fdb4b139f52ab6a84c87bea601483aa
rubygem-multi_json-1.13.1-1.el7.src.rpm SHA-256: 6cccf1c19a5566e594999d8a65ba9980ed198c2312e71d468e4bf94b8b2ca24c
rubygem-systemd-journal-1.3.1-1.el7.src.rpm SHA-256: a62ef54d9674f00efe0e00eacc2fe25159985041b5ab97067d1101add63787ab
rubygem-tzinfo-1.2.5-1.el7.src.rpm SHA-256: cc8fee6efc0a9b4c447f5e7abcdd3a627f2eb023c2a245963c080fe475f9d5fc
rubygem-tzinfo-data-1.2018.3-1.el7.src.rpm SHA-256: a97d921b1a5f3ab2ae8aad911ceac963ea0bc9dc6f2ef050dcd8a408e851d4f7
rubygem-unf_ext-0.0.7.5-1.el7.src.rpm SHA-256: 312ecc9a80e241544accadccab80ae68c4bda2603c12d3c8b6019d00cf0e2278
x86_64
atomic-openshift-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 50a3aff33952b3c6b6377420c2349e13f6006be5da009e87c0411e78f315c605
atomic-openshift-clients-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 6ab08bbc8e7768d3b0f0a08d3e70152ed77c004a7f32cf3a5cd1163e33e8fb76
atomic-openshift-clients-redistributable-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 25cca65d51f56cdb3b8991223a0821fb32cdf2b2a229902711de66d9d26776aa
atomic-openshift-cluster-capacity-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: a23c6fc240a3bb8078e5a72f35f9419de67c24c7c254f6363084461d6c5066df
atomic-openshift-docker-excluder-3.6.173.0.113-1.git.0.65fb9fb.el7.noarch.rpm SHA-256: d7693bc0629344f9dc01520e922cfa2c18a0dc4cd7ec65f6037fdb30e894a08e
atomic-openshift-dockerregistry-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: db0a9692c7831ae6d05446801e7d1a8151d3c5dbb9e014f2f2927eb45dc9b73c
atomic-openshift-excluder-3.6.173.0.113-1.git.0.65fb9fb.el7.noarch.rpm SHA-256: a065035653aa2f1e92f6dacf1b69cfcd5cfaeb3e0606efa42997b81859e951b8
atomic-openshift-federation-services-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 2f4e27c810f71520897607fa08cfe92f1808e13d7d9f8a5efd9a09a73b951b8d
atomic-openshift-master-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: d9e1f145d872a7d7de9bc96bd6c51c84cf3cd6a52c43c6139011fab60084d8f0
atomic-openshift-node-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: c8e6169a5d7208d350ca40ceab5979a05f4c730c1a46dab514e0008420e8de65
atomic-openshift-pod-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 62ff37839e47e80f31fa2c734ebf94f33aa023205fbd96236a4554163950675d
atomic-openshift-sdn-ovs-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: e65ea7d95adf2d4fe80ec1edf8448706903adee1406334118005a30c03b137e4
atomic-openshift-service-catalog-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 984defe34a1d2d48f1a652dd6ede0d83c6f50d460a14c48db573bbe995f53d91
atomic-openshift-tests-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: aad379d46352ed9d778a1e05d88de7b5e5f9151fd05ef7d5b9d5ad7448e932fa
rubygem-cool.io-1.5.3-1.el7.x86_64.rpm SHA-256: 0b6f1e3cb06ee09402cf34f0d1c8709113fda9f4ee74ef0063e7b3fb142f4bd8
rubygem-cool.io-debuginfo-1.5.3-1.el7.x86_64.rpm SHA-256: 3f4c44e1787926962cde7802565f79d607ba3f7dab465fa8b9fc070533f0c617
rubygem-cool.io-doc-1.5.3-1.el7.noarch.rpm SHA-256: 3399c4ce615194f8359dcac1f022e01d9f1951ccf357d7d6acaadcab7021d61d
rubygem-excon-0.60.0-1.el7.noarch.rpm SHA-256: 45fe7eb18a8729bceb03026ab8e83d09a9f1dc27ab1b9871bfe29f6ffc65c79c
rubygem-excon-doc-0.60.0-1.el7.noarch.rpm SHA-256: 35010ef3ec841b72e5a92fdb3909e3c1c6a712e9b2492832d83142bc0ee29b1c
rubygem-faraday-0.13.1-1.el7.noarch.rpm SHA-256: f59c7dfd8432e70378ae85d4519262d33079bd576107f654361e10efbd24107c
rubygem-faraday-doc-0.13.1-1.el7.noarch.rpm SHA-256: 369defbbdd6701f948552e06241b01f9e97da5c6acb49a146b3f6a2275ad7e98
rubygem-ffi-1.9.23-1.el7.x86_64.rpm SHA-256: 903dc364c0dbcde9b2bcf309ee73f67604930a30ce497226764721f743fa0f65
rubygem-ffi-debuginfo-1.9.23-1.el7.x86_64.rpm SHA-256: 1d1e91f67b0ae96daa432e1930d169e2e5a069c3ad1c46c7db89878f83c455b9
rubygem-fluent-plugin-kubernetes_metadata_filter-1.0.1-1.el7.noarch.rpm SHA-256: a2029520af4f335d0d00ef08a350c13be1d3459963f126c1f6f0613a30c0095a
rubygem-fluent-plugin-kubernetes_metadata_filter-doc-1.0.1-1.el7.noarch.rpm SHA-256: 4200af4edf60b98bd7dde7d1b4424fab9efbe8106ba653da714acf0051becbb1
rubygem-fluent-plugin-systemd-0.0.9-1.el7.noarch.rpm SHA-256: ab77669c688151d4b98e0bf02bb7db7290d5f0686e2419df2fdf62ecb8a6bf3c
rubygem-fluent-plugin-systemd-doc-0.0.9-1.el7.noarch.rpm SHA-256: 39bdbbb203ceb4ded18ceeb2740ab5ab333e81c51fcc4e19c6150301902154d4
rubygem-minitest-5.10.3-1.el7.noarch.rpm SHA-256: 13dee02b161885852ff60c5e5393afa80cc2f713061d58a40c044c0d38ae7339
rubygem-minitest-doc-5.10.3-1.el7.noarch.rpm SHA-256: e47433482dd5983780ccfca8e9953c9fad397f9adbf2d6697e42ada59f14890e
rubygem-msgpack-1.2.2-1.el7.x86_64.rpm SHA-256: 00dd5930910c68234d42b1779589a5989ccf3d5db4d363e1120880c75affffb3
rubygem-msgpack-debuginfo-1.2.2-1.el7.x86_64.rpm SHA-256: df360d69224d74f92831cfe69ed2b06f7294d89ecb779fd348e698a25167962d
rubygem-msgpack-doc-1.2.2-1.el7.noarch.rpm SHA-256: 31bb83eda01fdbcdbd315e855a86a063a2b0bf3fc4f571dcf41cf77afbbcbbbf
rubygem-multi_json-1.13.1-1.el7.noarch.rpm SHA-256: e91c5532fea84729c4f6d029dccc05851001cae919c50852ea310d2a85bf63f7
rubygem-multi_json-doc-1.13.1-1.el7.noarch.rpm SHA-256: 654c0acf88b9a794c380c8f20e9701c3fa434db24c3ce3ba062cc545b340eb28
rubygem-systemd-journal-1.3.1-1.el7.noarch.rpm SHA-256: 98aa50a1d89d2cdfdad4e3afd22eba16957f9b26f4eae345bb66398a14e04ffc
rubygem-systemd-journal-doc-1.3.1-1.el7.noarch.rpm SHA-256: 1d621280206caf8a7c2868bbb38218b7702ba129dd150a5379f59876eaf0b4c0
rubygem-tzinfo-1.2.5-1.el7.noarch.rpm SHA-256: f92bfc8c526f8d0fe61bb50976c3da66ff29215c70a1afd52ab798a98bba771d
rubygem-tzinfo-data-1.2018.3-1.el7.noarch.rpm SHA-256: 47532db32192b1d701fc6d798b2891fbc8210eba117848c3da6cc2a2b9dd6034
rubygem-tzinfo-data-doc-1.2018.3-1.el7.noarch.rpm SHA-256: ffe68a2d9e75c2f9e9fbe7e69cfcf9a347593ef0257fcd3772143b34c60e7a54
rubygem-tzinfo-doc-1.2.5-1.el7.noarch.rpm SHA-256: 134f5ea7e1957ce5107856df4d021ff69471e990d6217ac97a9cc8f87585a951
rubygem-unf_ext-0.0.7.5-1.el7.x86_64.rpm SHA-256: 0ef0c9cf413ca0e3702b94e0e7359b84de15a91ce705412bde3f2fd0b31cf49e
rubygem-unf_ext-debuginfo-0.0.7.5-1.el7.x86_64.rpm SHA-256: ed49afc331190abb20d794d3fb900a72a0099169e194f3e2cab46da3122221bf
rubygem-unf_ext-doc-0.0.7.5-1.el7.noarch.rpm SHA-256: cc52de94d50404f7088f0edbf7b7732f2cc9dda35780ae094e94996dabc04896
tuned-profiles-atomic-openshift-node-3.6.173.0.113-1.git.0.65fb9fb.el7.x86_64.rpm SHA-256: 312607ef47a724c2e3cb0f04e7ac169991c402311ff4b333869ccb73542579c8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility