Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1037 - Security Advisory
Issued:
2024-03-06
Updated:
2024-03-06

RHSA-2024:1037 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.13.36 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.13.36 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.13.36. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2024:1039

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive

work (CVE-2023-39325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are

(For x86_64 architecture)
The image digest is sha256:9ed18a88ce6242dceab887ee7dc92eecf9e0194a569e1e8c924cbf4b1da7816e

(For s390x architecture)
The image digest is sha256:39c264672d907a91c8014a874a62a11da8210fa2a96dc79a892075e2f81a28d1

(For ppc64le architecture)
The image digest is sha256:71acc8c734200d05ad08aeac48b82c5f7f1011a9f095b7b3bb493b93dfa1753d

(For aarch64 architecture)
The image digest is sha256:ddfeb044fee25f45b5c3e5e1ac542952b00e78fd2f842c985491d8e58d75ec5f

All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • OCPBUGS-23501 - [4.13] Failed to mount gcp volume with "failed to find and re-link disk"
  • OCPBUGS-24353 - [release-4.13] cnf-tests: [test_id: 55012] RPS configuration applied on some physical devices
  • OCPBUGS-27406 - Contribute Pipeline metrics tab using the dynamic plugin
  • OCPBUGS-28630 - [release-4.13] Address manager primary node IP constantly being "updated"
  • OCPBUGS-29670 - [4.13] SELinux blocking the operation on named pipe
  • OCPBUGS-29674 - Whereabouts reconciler errors with "IPPool not found" on pod deletion although the IPPool exists
  • OCPBUGS-29725 - [4.13] Metal Day-1 When No Hostname is Provided by Either rDNS or DHCP, All Hosts are Named "localhost".
  • OCPBUGS-29728 - snapshot-controller logs report failure frequently (4.13)
  • OCPBUGS-29766 - [4.13] Lazy pod removal with recent CRI-O releases
  • OCPBUGS-6208 - Update 4.13 openshift-enterprise-console-operator image to be consistent with ART

CVEs

  • CVE-2023-39325

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

aarch64

openshift4/driver-toolkit-rhel9@sha256:e93c2512369179b7c5aa877a4cf33712b7c4ff58a6ac0563dbb7b7a617962dcb
openshift4/network-tools-rhel8@sha256:d65104b34cd5203d85483d6b81e57d0498c45eb5fd240a192afd19c18a35ddd9
openshift4/ose-cluster-config-operator@sha256:ea4f428f32e0b3d563684489337b5d9d85d9bded8ba953379c59bf92f4d575cd
openshift4/ose-cluster-image-registry-operator@sha256:413de2cae3174106d4da50789dbff8246d4b8fd159609339131f66c504fb89b6
openshift4/ose-cluster-network-operator@sha256:ac2e6f3ae6fda3e9c45bfdb3d030a7371bf9e13f681779410c0791a2c98e0662
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:a96b8565e6d3349d91b6ab86af6d28d55fce9374d323d34482b73310499043cd
openshift4/ose-console@sha256:e3206d445ea17d898dbae1afeeb15bd6d09d3ea97ed067513c33684645cf3b67
openshift4/ose-console-operator@sha256:f5c4932a52af8377212776fe8b867061dfb56d233fb7c1decabaf4a056a211f5
openshift4/ose-csi-external-snapshotter-rhel8@sha256:2574354998e889109255fdbc1e717c6e577b522dc6ce1f23f886cec451cc2552
openshift4/ose-csi-external-snapshotter@sha256:2574354998e889109255fdbc1e717c6e577b522dc6ce1f23f886cec451cc2552
openshift4/ose-csi-snapshot-controller-rhel8@sha256:08260a142e3b4e4a3248cb14c49b47729588a525cfbd72034a64a01518860013
openshift4/ose-csi-snapshot-controller@sha256:08260a142e3b4e4a3248cb14c49b47729588a525cfbd72034a64a01518860013
openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:fc78927c3b4cf6171ab533289b10606ef04e05f446650f43ecf93bc6a931dffa
openshift4/ose-insights-rhel8-operator@sha256:4221fc0ff6fe2bc52e6ee72f4936557a7e63d2cb2c200787b990974f6fb95c48
openshift4/ose-ironic-agent-rhel9@sha256:84ba5610aeca7b53e5d9a1d0c4419598946f32bf7bb2bf941e3d5dd87aad8480
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:427c5677e6aaa2d21c6d53b3005a706617f101e0053b262d49dd6a6f01c50d4b
openshift4/ose-ovn-kubernetes-rhel9@sha256:e02de4d14c6047f5e3575304bb372da64ef3e3629974682627c15b8324fdcc39
openshift4/ose-ovn-kubernetes@sha256:e02de4d14c6047f5e3575304bb372da64ef3e3629974682627c15b8324fdcc39
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:29494d23939a4d74f66cd4af9a1400f4b5dddf91b75825108eaf5976f9c71e62

ppc64le

openshift4/driver-toolkit-rhel9@sha256:4fa48b5e67503877b9b33e242385cd764eb9983eecb99870eb89dfad9d5dbd0b
openshift4/network-tools-rhel8@sha256:262eb9c68728104e51df63e020fed5a805e4918270d819f65a206d9c7af701e4
openshift4/ose-cluster-config-operator@sha256:8f2b749559fccda16a01b421a9a6f85380878ef6de261b1de0c8d49e2c008081
openshift4/ose-cluster-image-registry-operator@sha256:4cc7390b0c15abb9ebe7956c0469927a3c9c07227f14eb0701b976a40a8ad0d3
openshift4/ose-cluster-network-operator@sha256:8b30123521ecae392692ff3f437e294f47cca488f0e3021f2532b28a1ca7fe06
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:b36b9083e87bfc2a22b647576b8ea533f6d50533549b0061ad09facdf9e0fe48
openshift4/ose-console@sha256:3daf59dd42a704d82023dd94648f1352e4089570865d0a7e6ecd71d0f34a778c
openshift4/ose-console-operator@sha256:5993fc55b216df28edb402f675251ee33a7aef0e3153a8fc5b4da4da9f6d1371
openshift4/ose-csi-external-snapshotter-rhel8@sha256:7031f82f72716748c02d24c1aa19391d8341bb01311b210f218e7da06e9b5aff
openshift4/ose-csi-external-snapshotter@sha256:7031f82f72716748c02d24c1aa19391d8341bb01311b210f218e7da06e9b5aff
openshift4/ose-csi-snapshot-controller-rhel8@sha256:1e47108e8877ef713ea29f9c0982027f6dd845b2346804c204a98038b1607b40
openshift4/ose-csi-snapshot-controller@sha256:1e47108e8877ef713ea29f9c0982027f6dd845b2346804c204a98038b1607b40
openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:7deee2ef3c9de391c344c9536e98a2b6f48a1f40baea8f14e261a680cd320a7e
openshift4/ose-insights-rhel8-operator@sha256:fd96de554193dcdb2b26cd680d34b585392ec676f3bab86c1e46e7df2618b9f3
openshift4/ose-ovn-kubernetes-rhel9@sha256:8bfe2f8041c949c6c15c7ce35093839ebe5871c37ebd6bd2b88d2189b3f7ad9e
openshift4/ose-ovn-kubernetes@sha256:8bfe2f8041c949c6c15c7ce35093839ebe5871c37ebd6bd2b88d2189b3f7ad9e
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:81cb238066e3419751556df5e4294a0a5a63815b4465e14d6885ea20e4798fbd

s390x

openshift4/driver-toolkit-rhel9@sha256:6112bbf82c63d90f3637218aaeaa5c605e48bf339a1b044509d09ac9b22a6e94
openshift4/network-tools-rhel8@sha256:e00ce76b371b816a8c80cfd4ed7bbc9f38dfff1238bbab5208356e7c52e71217
openshift4/ose-cluster-config-operator@sha256:eed3827b3d2c0991701a7dc1b11fd9c470300fc280e0774029d37a106ec3daa8
openshift4/ose-cluster-image-registry-operator@sha256:93f41feb4fc4e3c8a237e51e8c978de4e5d3a91acfc08ee87a5f3b92de17791c
openshift4/ose-cluster-network-operator@sha256:308f07643a1ef79d86e4499705e2d6d453619bb8d62b195ddac6007cd5b7a144
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c90fe0325605ada37437986c6d5ce4df0a1a98db9832f31a21046476bf83f8f8
openshift4/ose-console@sha256:880731da609989f0130319f6c5b940dda34d962109df7b7b9d9be1c53eb5bf6d
openshift4/ose-console-operator@sha256:cbb31f6d1080483ff58877d093606b866d71a4cd46d63290704779887d72fbb6
openshift4/ose-csi-external-snapshotter-rhel8@sha256:05ed7192b209e4ea16d6b8c4b637098249ebcc449b3afbb5bb0f6c64613f0bd7
openshift4/ose-csi-external-snapshotter@sha256:05ed7192b209e4ea16d6b8c4b637098249ebcc449b3afbb5bb0f6c64613f0bd7
openshift4/ose-csi-snapshot-controller-rhel8@sha256:851dc6943b566fdabd35c1685e4cda695b9a758243474e27410d62892ba54297
openshift4/ose-csi-snapshot-controller@sha256:851dc6943b566fdabd35c1685e4cda695b9a758243474e27410d62892ba54297
openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:d5d241233d921ab5f55e6494d819efc32edf20f120735768c49d4dde9093b438
openshift4/ose-insights-rhel8-operator@sha256:b8abfb8a45e5fdaa55c11f94518a139e557fcce4d4c3cf8d4d1d34f3c00de329
openshift4/ose-ovn-kubernetes-rhel9@sha256:8841b780b52be646442ad2ecf4c0151b27df0419a47ab0c840db57aaa259b856
openshift4/ose-ovn-kubernetes@sha256:8841b780b52be646442ad2ecf4c0151b27df0419a47ab0c840db57aaa259b856
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:591ce173f8e85a127dcbf5f7496206f3aa805f1fbf3fed84e6b1fae72298f812

x86_64

openshift4/driver-toolkit-rhel9@sha256:2a58c1a609e4a77da66c8b5e8833d9d9df16320d44c75f9b7662ba66a4f725e6
openshift4/network-tools-rhel8@sha256:61a16819fdd69072e2b6cebfd56511a454a62afe02c438a2dc97d29c7636149b
openshift4/ose-cluster-config-operator@sha256:949c12a11284adeb7631beebfa6063e7b4370f4759697e248be26ba123d1a1c6
openshift4/ose-cluster-image-registry-operator@sha256:4704e5fcc739c86c2556770892d2bf522126d56755be5d92af805b4fd88c7606
openshift4/ose-cluster-network-operator@sha256:de88ab976e0381b1455c0f393b4fae2e1886e4067ffb1838a74f12231e2d2df1
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:52b10c3124951279acb8f82b388eecf3c6d723bd48ea1d9aa180a547107a27f3
openshift4/ose-console@sha256:8bf4f938a721d18c48b7e0debe63f041a4761220c3bda9a8b8f525a39b995673
openshift4/ose-console-operator@sha256:8cdbcd074d3b5cf8e7370a91a30b3dabe4ebb554285959d84a2bb5ff371ad54d
openshift4/ose-csi-external-snapshotter-rhel8@sha256:917bffe6ff49ca9cdcf20d8b25ff3a2cdcdde5a6595b2519f357fda9143d9425
openshift4/ose-csi-external-snapshotter@sha256:917bffe6ff49ca9cdcf20d8b25ff3a2cdcdde5a6595b2519f357fda9143d9425
openshift4/ose-csi-snapshot-controller-rhel8@sha256:6c4fb2ec1ce23e9d955b523652240ef2bb44c7adb1bf20ddf7e2869437f2dbcb
openshift4/ose-csi-snapshot-controller@sha256:6c4fb2ec1ce23e9d955b523652240ef2bb44c7adb1bf20ddf7e2869437f2dbcb
openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:c733bb72265aa53fd767fa89ff89b3777174719c393d4fc09b2f323eb2f9ac9c
openshift4/ose-insights-rhel8-operator@sha256:2e96d66132eb5f8268cb363325ccc8280adf2978ee091358a4df89003655306f
openshift4/ose-ironic-agent-rhel9@sha256:08b66f07c38fff6e7c4b08c8d7f9ff5e032aa99b4ec26042a006ba0ac57ed91f
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:808f987e40d50501fc4f8f16f2a42062c0f7419f87db78d58dfedac7759d5e79
openshift4/ose-ovn-kubernetes-rhel9@sha256:28d05d14c5fcdcedd0d354e061dc5dfcc55ffa905a7bce98c494c247477d9d1d
openshift4/ose-ovn-kubernetes@sha256:28d05d14c5fcdcedd0d354e061dc5dfcc55ffa905a7bce98c494c247477d9d1d
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:5574b411f30e4c5911bc3f32e4f5e04727497678155dce8c03798143205ddfa4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility