Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:3309 - Security Advisory
Issued:
2023-05-31
Updated:
2023-05-31

RHSA-2023:3309 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Container Platform 4.11.42 bug fix and security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Container Platform release 4.11.42 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Red Hat Product Security has rated this update as having a security impact of [impact]. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.11.42. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2023:3308

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html

Security Fix(es):

  • dns: Denial of Service (DoS) (CVE-2018-17419)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html

You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are:

(For x86_64 architecture)
The image digest is sha256:518177a34452837920f1e77944f6afa08864537260c9f742b8c88b6157e4f901

(For s390x architecture)
The image digest is sha256:c8f1891f3d4a93104a209b96987e07e2077b685238a246da12a656bf69be88c3

(For ppc64le architecture)
The image digest is sha256:19ad52422acbd24dde71ae5089471c541004e1c0bf4e13e081e5b65220600c15

(For aarch64 architecture)
The image digest is sha256:d87fcd39ad6fad29454ff9137ce521d7049cda2b391ccbdd34554427d60bd27b

All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.11 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.11 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.11 aarch64

Fixes

  • BZ - 2188523 - CVE-2018-17419 dns: Denial of Service (DoS)
  • OCPBUGS-10276 - [4.11] Lazily unmount /proc/cmdline
  • OCPBUGS-12231 - Pipeline Repository (Pipeline-as-Code) list page shows an empty Event type column
  • OCPBUGS-12254 - MetalLB operator 4.11 update fails with addressPool apiVersion conversion
  • OCPBUGS-12263 - opm fails to serve FBC if cachedir not provided
  • OCPBUGS-12279 - Developer catalog shows ImageStreams as samples which has no sampleRepo
  • OCPBUGS-12284 - 'gitlab.secretReference' disappears when the buildconfig is edited on ?From View?
  • OCPBUGS-12959 - update the default pipelineRun template name
  • OCPBUGS-13730 - Show type of sample on the samples view
  • OCPBUGS-13746 - PipelineRun templates must be fetched from OpenShift namespace
  • OCPBUGS-13792 - Failed to create STS resources on AWS GovCloud regions using ccoctl
  • OCPBUGS-13822 - Yum Config Manager Not Found
  • OCPBUGS-13864 - Pipeline is not removed when Deployment/DC/Knative Service or Application is deleted

CVEs

  • CVE-2018-17419
  • CVE-2022-25147
  • CVE-2023-25652
  • CVE-2023-25815
  • CVE-2023-28617
  • CVE-2023-29007

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html

aarch64

openshift4/driver-toolkit-rhel8@sha256:afa4538e91f4c9fb5b8ac62ef8ff9e2523f4ef16256220e265b75315006543ab
openshift4/network-tools-rhel8@sha256:be4b821ba60f99a0023adf4b9d1ecba7ffb571c65fd078b907a8c5bf71c52ca1
openshift4/ose-agent-installer-api-server-rhel8@sha256:ed3727e34119ae167f869dd0cb906af160a5dd31a70a3ec56269305b5f82e334
openshift4/ose-cloud-credential-operator@sha256:171637f735e42aecaff116cf5809ad9a95aefc000f990a4226cbcd3f53e57577
openshift4/ose-cluster-node-tuning-operator@sha256:9346703015e564a579d4f0b5df68e1032bd94eca43fdc439efe8c55fa9c89055
openshift4/ose-console@sha256:33238b13c0ecfddbe31f6d451a2ec8260114cb65c5543e3784bb93ee4990f9ef
openshift4/ose-docker-builder@sha256:d2e4f258f1fe4cbbdaff197972229d8840c871665c5941d57ee2eb1400b20aa4
openshift4/ose-haproxy-router@sha256:1e25de287b9806e0391699c050746a0baf1674a0fc7e069d021eb5746a55e936
openshift4/ose-image-customization-controller-rhel8@sha256:68b6f05e7a21b127b18c17abde3cddda5a240eb925467a2e1cdd5f72fa95b766
openshift4/ose-ironic-machine-os-downloader-rhel8@sha256:ee0bb8b9bc0fe048c24137b1917a443db411fed0817e6b21cc549bcd08ac3df6
openshift4/ose-ironic-rhel8@sha256:f7c0841a8ad19c539ee7adec078beecc76871b59424925e134f18cc749df2995
openshift4/ose-kube-proxy@sha256:1f4ddafd78510c82ff4c7b1e1bb14b4aad37d63b24c4680da8c7ff441ac34736
openshift4/ose-sdn-rhel8@sha256:dbdf2dace7fee149e0e1d4865bd3884684f053b410a5b6ca7ded0f71f8164936
openshift4/ose-tests@sha256:65d009bb18ce99a2e528b5c7d7a0f6cef0bb8429c062e31f40f918ca4832f6a2
openshift4/ose-tools-rhel8@sha256:943ceea03f8f2d9ec326ae358019db7060ffeb78006ed196fabe78035485e281

ppc64le

openshift4/driver-toolkit-rhel8@sha256:63ac5d6b0c7f95086719d31f6ea8b595bbecd84647a8c75a76ee104915f38546
openshift4/network-tools-rhel8@sha256:91c9d5a36ac6f03a0668384dcfa1c9a479498fe9688f9035167aaa07651e5815
openshift4/ose-agent-installer-api-server-rhel8@sha256:d1a022fe93aa112cc506beb6f3a797d73b1bfe70b65bbd8c230923fe201c30be
openshift4/ose-cloud-credential-operator@sha256:189e6f364a747b7dbfb3595109404793cee64cfe08c0c18256b262fe5a31cfbb
openshift4/ose-cluster-node-tuning-operator@sha256:0d58a737dfb486318e1d149da484eac01e25bbba4fdd9f9b663fb0520772207e
openshift4/ose-console@sha256:a56f3224c528c2f5e8154361da24936b6fc6d76ec7fd917635d2d4b3c2dfa7d9
openshift4/ose-docker-builder@sha256:19768bb9cedef19e38d6bf9fbab7f2b20974bdb984e0dd45daba424feb9ddb59
openshift4/ose-haproxy-router@sha256:6363a86769566555ceefb74b4ae3a43062cb02cdfe486bc785fd977856340cb6
openshift4/ose-kube-proxy@sha256:182b611f3b8f5a30e5856d502de4dc6598773fc6e484be6ee96c61eb5dc7c87d
openshift4/ose-kuryr-cni-rhel8@sha256:ea9df4be3994c4a99b4ca1c9f60124340c54a1d5ab01f68a1e53114843e61b7b
openshift4/ose-kuryr-controller-rhel8@sha256:b3317cba4bcad83acdd245d2a388c9d569d41ace7f3f0c2d34d1237eea58bfbd
openshift4/ose-sdn-rhel8@sha256:8da18bb46e5465d7096514b582af52de455233d35e61bb2652fe45fc01ca05f9
openshift4/ose-tests@sha256:06279d580b659a77da80d2862f2eae4e826202c25f5d617bab2478ef7f69f24f
openshift4/ose-tools-rhel8@sha256:1a7f61993bac350f8880ff99f2143afcce38e2cf6b3a2bcde42d541c4c502a39

s390x

openshift4/driver-toolkit-rhel8@sha256:082150cc22007fe9c90019ca3ad7dac12b0ed8cab7d1c8c7ff5b155f59736f17
openshift4/network-tools-rhel8@sha256:34b133627c417d9d9a5bacba793010e7247039878e4986a6086c4f926d387970
openshift4/ose-agent-installer-api-server-rhel8@sha256:e2b1f55fe0c8d3a8b3a1c1171a1b65d96280bec144793c2509528352241bdc8b
openshift4/ose-cloud-credential-operator@sha256:7f91abc3b14e6f8d1366bc2d81d60a987ffb8d2c9c4295f06ad8a04858e38ed0
openshift4/ose-cluster-node-tuning-operator@sha256:bf40eb8407f1cb14c549b6c253734d78e383f67bd3d02d297c410914fee06783
openshift4/ose-console@sha256:79a3fd4fcc7b27e4b77aa591667f220d8ba9d72231770a41f6afe773534d6130
openshift4/ose-docker-builder@sha256:5cc332ee1a82d2a4da2df874d5e78d99ee54c235bd9a7d82cc813c1ba66e0cca
openshift4/ose-haproxy-router@sha256:3390642521366c0c8ab186438998c899c119a3e9ba528fcc7d5692d49eceb191
openshift4/ose-kube-proxy@sha256:7cdc6f40f4a7a395d29a91e3d9108818b06ee12d58c91659663fa3b662a63ceb
openshift4/ose-sdn-rhel8@sha256:306b85ae9fd82ec7c458137f751cf0819ece5b9610462f9b9725ad4680a9519c
openshift4/ose-tests@sha256:8b123e54923a19da2c488ee794e4ec63d533ce18e1fb7f92254a96d330dbfd63
openshift4/ose-tools-rhel8@sha256:c5079dcf0b8e1e652df0ef7d867da7b4c79f82a7208343ed55317e17f79e93a5

x86_64

openshift4/driver-toolkit-rhel8@sha256:521365b0e122d6fbfd6167bb4f3cfdca4c40399c1c82f27196670ebda4282aae
openshift4/network-tools-rhel8@sha256:e0fa33f4202acaf40992d29ee689161af743c71129fdc7f4c52effc4e3323608
openshift4/ose-agent-installer-api-server-rhel8@sha256:985981af01d868016ce9e1111c95b9f87b17fd82a2d0a983d1211b22799424f0
openshift4/ose-cloud-credential-operator@sha256:c2ce285ea79f7b01d4e03c77775fe95caae9a2f3f44548f1efc6489f2334b9d8
openshift4/ose-cluster-node-tuning-operator@sha256:e59aa8b3f756a00115d38c8480e98d83bc047dbb9483a168ed90c505c8548b13
openshift4/ose-console@sha256:c6192b52d7608845166272f36806ab44cb085613cea47d31148c73fd4c8a7fb8
openshift4/ose-docker-builder@sha256:415b376e7bc5c29c127c98c0d2a1d0fd2d6590e61d12bcf58413a72433acafcc
openshift4/ose-haproxy-router@sha256:0dfd7b5f4a111c6f4155735db42834d6649119cac3ee896c6344975720845ebb
openshift4/ose-image-customization-controller-rhel8@sha256:026ad30a90097d32a3311728e8b5c10b5d385848658a044ecc42204a82d77f66
openshift4/ose-ironic-machine-os-downloader-rhel8@sha256:3ddd8e4aee16f74b4d3ac17f47ac1db94525a00f127d542e792f086f13a0eaae
openshift4/ose-ironic-rhel8@sha256:adca5acf4b3a9551392e14bd4ab5a78a000117b81337c155e9439920fd8c99bb
openshift4/ose-kube-proxy@sha256:8a73ec789ccc3f5d54f177d4ce5aae30e46b0389723ec4b1146826c6037153d5
openshift4/ose-kuryr-cni-rhel8@sha256:32543a0409a9e1f90b112aae8e46dcc7a1a2e25ed006ad19041727c6ab58bde1
openshift4/ose-kuryr-controller-rhel8@sha256:d1abc4d4c06c597aa7fb59ea47eab04722df18e7e618f870e6ac2470682a0783
openshift4/ose-sdn-rhel8@sha256:a2cf395947d3bf01ad535a662f1ffe65ace4a3dea3a10cae442ee12a9a7aa8a4
openshift4/ose-tests@sha256:7dc4d6c7e3de9e8a36f3498fdd23aac77e14693990ba2fab2cef7a9f06362b3a
openshift4/ose-tools-rhel8@sha256:6ff7efacc3ba2817d560c8766fc58829de4be301f3fcfdb25e1b60d6a5b6130e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility