Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0193 - Security Advisory
Issued:
2024-01-17
Updated:
2024-01-17

RHSA-2024:0193 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.13.29 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

An update is now available for Red Hat OpenShift Container Platform 4.13.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.13.29. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHSA-2024:0195

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)
  • mongo-go-driver: specific cstrings input may not be properly validated (CVE-2021-20329)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are

(For x86_64 architecture)
The image digest is sha256:9c4a4471bb93ab11d255925535ff719742cafa8ae06d622b870133787a72abc3

(For s390x architecture)
The image digest is sha256:80c287d6ee8baa959462ddb58f23c89cd4d37e54350813de09ef2b2704519057

(For ppc64le architecture)
The image digest is sha256:0b087b1c8f1af8c2339fd40c57e2b15d3bb5c4c761ed04b6e67dc3b9fff7be19

(For aarch64 architecture)
The image digest is sha256:e0c45710ebff1bcd72c694f3bac3de92074163aa1db4b7a03d1a81cb53b79888

All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64

Fixes

  • BZ - 1971033 - CVE-2021-20329 mongo-go-driver: specific cstrings input may not be properly validated
  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • OCPBUGS-19658 - The KUBELET_NODE_IPS does not reflect in the kubelet service after the dual-stack conversion
  • OCPBUGS-23483 - Silencing of Alert in Developer Console not working until OpenShift Container Platform 4.14
  • OCPBUGS-25988 - Bump to kubernetes 1.26.12

CVEs

  • CVE-2021-20329
  • CVE-2023-5388
  • CVE-2023-39325

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/driver-toolkit-rhel9@sha256:fbe0e1f721cbc7db4f46191f2e96cd3e439d4de6af3e4c3656e90b32d6cb2da2
openshift4/network-tools-rhel8@sha256:cf3ee30fc23923f027f97f6611abd2eeb21164aa65697445664a6f860929f7e0
openshift4/ose-agent-installer-node-agent-rhel8@sha256:16e8bd6a4bfc6cac55541cbf038c475c54c8207ac82212766368d6df363967b0
openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:f9fa6a423bc75e9864c2acef175a6cc5494d6175c70c9145c56b6eea5c953f2f
openshift4/ose-cluster-network-operator@sha256:434ad23d0d405b7e22456ed4b3f882b81ab77d5f35b6ef2db87c1374042e0a86
openshift4/ose-console@sha256:afab7d8212ee932132217b76ba99cee7c44369283634021f9c6c1956f83c4c98
openshift4/ose-hyperkube@sha256:bbdf4f84891e1774cca9e07037e17b40b09737a2bf7af8ad292ded95c3c458ff
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:5be223aa82849a0f6b14c3fd581ee34b065d439b601a0bb1bcc2659a258afb39
openshift4/ose-machine-config-operator@sha256:b1207de1db941794219f728c3920b1b432113628d2e8fd2cc8f1b65598ff3082
openshift4/ose-operator-lifecycle-manager@sha256:b380c6f0a092c12992b790b64b3118dfa3141753281b3cb65d718e27e01bca88
openshift4/ose-operator-registry@sha256:8955d2f48b0d837431f46a7d7a91f3217f3ce535c1d4b4cc81c22970cf0f05e6
openshift4/ose-ovn-kubernetes-rhel9@sha256:64b4004e9af037ff3c1be4881e4d2893edfb76a01106bc355a0a93d56b701842
openshift4/ose-ovn-kubernetes@sha256:64b4004e9af037ff3c1be4881e4d2893edfb76a01106bc355a0a93d56b701842
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:5e727715cdf8d52c95302d34bd6cd6bed6e22b48a1a77a060f264df30653b06f
openshift4/ose-pod@sha256:a8cbaef00c8a839000e49c55843474ef5020cc7ab2cf6aa2d10d05b8cf3fdd0a
openshift4/ose-tests@sha256:b478437b4f3cdf52491b0c9fd85ec171752dc45415c165ab0e7103ea5bf55906
openshift4/ose-tools-rhel8@sha256:9494f1f3a59f31415a846395375396ea51ba4c541802d83879b5b1d331ca308f

ppc64le

openshift4/driver-toolkit-rhel9@sha256:f83f933fe00b8434456d7924e07f07a82ae38991270945fe96770982bdc414e7
openshift4/network-tools-rhel8@sha256:c401686e9a0c234f590cb505372ba94302b9a0e0b73867e39a0e12426ca6e6ff
openshift4/ose-agent-installer-node-agent-rhel8@sha256:b2e2bd59321c4301a2ee202090bf40b230ce7a1ee0871f9b0a30be9b37a8882d
openshift4/ose-cluster-network-operator@sha256:637168d333dbd5970715b98f97946e85bc71485824c4dab2de82154efb8a472b
openshift4/ose-console@sha256:483a932e552796c74a6ff394233710beb516f42c9b964fc13b3276f52cf4f7fe
openshift4/ose-hyperkube@sha256:a3adda700381f8b2f22509e4ade1022d86244f2fc9d1f2d2158259ffedd3b516
openshift4/ose-machine-config-operator@sha256:6445f27aac98ae77b4ae47e92cd44cdf69f92dae51e0cbdd4b1625c7e2188f9c
openshift4/ose-operator-lifecycle-manager@sha256:00754781fdba3e206ac7187543c0c0833afdb8e765551a0316d7a66e8391e50f
openshift4/ose-operator-registry@sha256:be83a3c4b057d0a36e330c919f829de58c8bdd05f5dc11eaf85455fe9b0790b4
openshift4/ose-ovn-kubernetes-rhel9@sha256:b1e9a7c0a5bc4645fc33c404732927bf288505b675c91ec8e4d2a06798630dc3
openshift4/ose-ovn-kubernetes@sha256:b1e9a7c0a5bc4645fc33c404732927bf288505b675c91ec8e4d2a06798630dc3
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:12be23429b3173f6183c822f3426a7c1871d8fa5dacfd03d6cb2ae8cd6dbaf63
openshift4/ose-pod@sha256:75ac644f92e98c8e9616e2820aad3450b850a28112b152f79670db3379fb25b6
openshift4/ose-tests@sha256:d5cc21b6082b532234a6f7c838618a94d200e290c85cff769f2407b29b92abb2
openshift4/ose-tools-rhel8@sha256:8d14f86b472e43fbbafccf485ed173b7cda54ccb1971b3db0c0f06fac39f3146

s390x

openshift4/driver-toolkit-rhel9@sha256:05d6234e1a633a3f4031c577c915da75cece186dcd270f89447a03f1fd250a1a
openshift4/network-tools-rhel8@sha256:473cce3ee81558458beb6778df4fad6024a75ff3ce212fbc9848d30732bfe0dd
openshift4/ose-agent-installer-node-agent-rhel8@sha256:59b8105f8c827c6954f0ccb97321f851f387327ab7af6cea58d9fba71ceeac0b
openshift4/ose-cluster-network-operator@sha256:c7728b5165b2abdc9f63d3dd83c2894a9adc49a3e50a2c4c56662657c0e4562b
openshift4/ose-console@sha256:eeff56f6fe0956bbc6379bea152e65e6b98809db8e48022db5ef396094bfc25e
openshift4/ose-hyperkube@sha256:474953b990b02f9f7141ef2316e6e4dfb654fa970be893bb11b0be4a6651003a
openshift4/ose-machine-config-operator@sha256:8bdf00523bfc894c75c09fcf64201c4ab5aad4b6580a2ac554e0f446b99a4caf
openshift4/ose-operator-lifecycle-manager@sha256:cb73249f2ebd7a06bcd473022dcaadfd6efa7be741ae372fff5c8c6dc584adb6
openshift4/ose-operator-registry@sha256:d8815fd567c4b8143e1a03c5398ce59ba8c00b63785d92ae268742bd5f55b53e
openshift4/ose-ovn-kubernetes-rhel9@sha256:321234a8c7571370282568e008bab4a21795b5bf0f44f12a6d16bf3544290a76
openshift4/ose-ovn-kubernetes@sha256:321234a8c7571370282568e008bab4a21795b5bf0f44f12a6d16bf3544290a76
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:c5bf6c297ab451a47b9a40d1372313624f49578a63557035b486677bcb7df3e9
openshift4/ose-pod@sha256:0f8f11ef796d5811303dd674d129b51b9e1209b984d6364a5f144135546195e3
openshift4/ose-tests@sha256:7c4bd099e226d7bcaa446be037ba63ed0a58076c6cc428ad61160bea3d0b2304
openshift4/ose-tools-rhel8@sha256:8f13c578cc8a0631a9a5de1cd88357045f3fb4766202e365c8022195cea4fb8e

x86_64

openshift4/driver-toolkit-rhel9@sha256:1670b7ed6745cfab81e2f472e9e77834e0fb6dc792b017bccda1217403dc0247
openshift4/network-tools-rhel8@sha256:db1d60dd61f746fdc09a73c6520a2e32590bfbd22417f8d379d6a72a3b7505b7
openshift4/ose-agent-installer-node-agent-rhel8@sha256:66d8c54aa10c766124c332a0203e717f7f8b120031b5933e977f5b12644dd11a
openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:7a895374b2289119947ac54b49c34c2abd44e7f108411b65a0181e9965d5205f
openshift4/ose-cluster-network-operator@sha256:abc6213b793b35a404eeec68d5667bd6e108879ee86a182fc6efe5efae463e1f
openshift4/ose-console@sha256:7c69be58deb42c078baaa9f8b4e90f327a38b79a3b00a24ddb104c6727fc8a7e
openshift4/ose-hyperkube@sha256:c59ba2f520589740b92799483837a438208a352854391173e0a87c4e8c6906f9
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:7486da69bbcacaf43bea2cb8d681e556084aaccfd388e1ad4383cbba517d142b
openshift4/ose-machine-config-operator@sha256:1bf04c081f10010a77c3bbdf098b48f94333138c0ed614be39594ccbf2c11a7b
openshift4/ose-operator-lifecycle-manager@sha256:101373b564e354a6d420654c1338556e33acfc6a64f6d53e6c2bb6d03a9c6dbb
openshift4/ose-operator-registry@sha256:9eebd925df7317c2cecae7569d3484849e65e7eebfe4240abc82ab62644fdb47
openshift4/ose-ovn-kubernetes-rhel9@sha256:afe287daf5bbcc2762d326a84bcf712c2f3818fb88a0f72cb2dbebcbb453c209
openshift4/ose-ovn-kubernetes@sha256:afe287daf5bbcc2762d326a84bcf712c2f3818fb88a0f72cb2dbebcbb453c209
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:d87068e6d8dc13555d9d4073ece644733f1cd7e4b9b6a4fa4b4676339fc8e5de
openshift4/ose-pod@sha256:7a53f216d1969028e231cc54a6df6ae776c12f65866e6b223ced540f531e7963
openshift4/ose-tests@sha256:a4084c4597803ebe3d1a226634d5322091855f0da34676a0538dd5ae21434bd0
openshift4/ose-tools-rhel8@sha256:b21c1ec26ab2065396b220132715b383d86974941a9f7c59d079aaf16cfb24db

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility