Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:9615 - Security Advisory
Issued:
2024-11-20
Updated:
2024-11-20

RHSA-2024:9615 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Container Platform 4.16.23 bug fix and security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Container Platform release 4.16.23 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.16.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.23. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHSA-2024:9618

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html

Security Fix(es):

  • golang-protobuf: encoding/protojson, internal/encoding/json: infinite

loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
(CVE-2024-24786)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as follows:

(For x86_64 architecture)
The image digest is sha256:be725d2e56befbcb28068207b77d731650ad2c82ae77630f46631af750894347

(For s390x architecture)
The image digest is sha256:d931e1c6ada8869765e43480235c9029fdeb32311cc59afbd495a2366ffaf210

(For ppc64le architecture)
The image digest is sha256:f69f71b59b5e797872065ea84e9e06f60b4bc64c3e8fff8d2c356e09d4d9297f

(For aarch64 architecture)
The image digest is sha256:818beb020ebab89caa0a68304ac6a58ed365ad4ff192c130b4cc0695660cddc1

All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.16 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform for Power 4.16 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.16 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.16 for RHEL 9 aarch64

Fixes

  • BZ - 2268046 - CVE-2024-24786 golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
  • OCPBUGS-36290 - [IBMCLOUD] New VPC regions not GA'd cause failures during resource lookup
  • OCPBUGS-38930 - Invalid configuration for device 0 error with openshift-installer for vsphere
  • OCPBUGS-43344 - Allow from host network networkpolicies do not work during live migration
  • OCPBUGS-43834 - Enable topology e2e tests in CI
  • OCPBUGS-43967 - Re-vendor assisted-service to make external platform work
  • OCPBUGS-44104 - Errors reported by tuned when using SecureBoot
  • OCPBUGS-44105 - network-edge DNS case failed: 'DNS should answer A and AAAA queries for a dual-stack service'
  • OCPBUGS-44182 - Update admins to add CFE members
  • OCPBUGS-44194 - [4.16]gather admin and edit clusterrole definitions
  • OCPBUGS-44234 - Backwards compatibility for ENI tagging in AWS on HCP ROSA
  • OCPBUGS-44301 - pod cannot be ready during live migration
  • OCPBUGS-44337 - Removal of additionalTrustBundle CA that was passed via install-config.yaml during agent-based installation, does not remove certificate from node
  • OCPBUGS-44361 - Fixing empty tuned submodule when using Dockerfile

CVEs

  • CVE-2024-3596
  • CVE-2024-9407
  • CVE-2024-9675
  • CVE-2024-9676
  • CVE-2024-24786
  • CVE-2024-44244
  • CVE-2024-44296

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift4/network-tools-rhel9@sha256:670f96d5b1938deadc4a32e757e5fe7f791dae9c751f54e494b10c6c8b1f5cba
openshift4/ose-agent-installer-node-agent-rhel9@sha256:d0e7fccdaad30c10adf587f03f91d16abb901a252e6592a0098bd4eaeb39ec40
openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:e34b02c45c614f133440f3c91a27476cb5f9a9ad9ef08ef2872afdc614b12739
openshift4/ose-baremetal-installer-rhel9@sha256:f81bab242ba423355e2ec87636498aba9fc17e534c3e46b9f02068e279083fe2
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:028a0c49ce83d1396f4044b3ae46424ce9a752c575ff39852fc017c1e2ba54cf
openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:daee2ce917873c16bc297b60845c5d6f98f4ba2dc88ec0396cd16454d3787bf6
openshift4/ose-cluster-update-keys-rhel9@sha256:c7f948630aa6f2b9a08cb16e02320ca870b50ce977e87bcb31616147e24d1afa
openshift4/ose-console-rhel9@sha256:fc39134749c7adb1410c6d44d1e5033bbbbbe27714c4e63f38e4216b5b0e7407
openshift4/ose-hyperkube-rhel9@sha256:2a02d4d53b130b5fe87a05f7f764c53db51a7b98cc61f0a0a1dfd5f754777fc6
openshift4/ose-hypershift-rhel9@sha256:7c82b88cfc519b8a39eaeb10f250da2242a78912651c16c77393833998e005ae
openshift4/ose-insights-rhel9-operator@sha256:f56593aafb6f16906a7818bced10941628c98208ece6f93fc71c876f1a92c592
openshift4/ose-installer-altinfra-rhel9@sha256:5fcec2b83ba9a61a6f0dabd5c5ced6df51352db9dba6020c932e7ff35978d759
openshift4/ose-installer-artifacts-rhel9@sha256:b37d191d3ae00836c235b41359f112b9e88647a89a746199bc10281d0737a384
openshift4/ose-installer-rhel9@sha256:67fc02cd9e7a1cd0356253f3e271ccc26dd18280e8ad2f9a3518376ed69c8af2
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:be8648ab1904e0da1922186294398b97389ac7af305e329705f90cbac692f508
openshift4/ose-ironic-rhel9@sha256:5a381c1fd4e2953419c43841a26ce5e4f4342d8a7af57c2dccab5feaa717cae7
openshift4/ose-kube-proxy-rhel9@sha256:6bf90e8cb0d6863f46d59d452be50a6fbc4e6c784cf8ebc8fb05aced9056ceb7
openshift4/ose-machine-config-rhel9-operator@sha256:b1ed598dc7c00d0a8456cd82495742c9930d94de1b2b3916ee0cb44b1e67c4b1
openshift4/ose-machine-os-images-rhel9@sha256:5e9f33c1c2dc3f92b34e62f78b186590c54c52d8d73061e7355ec6d2aba59872
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:26ea2876f7904af1c5873206324a31705dc9d7fe305324c721f042b26d0512b0
openshift4/ose-ovn-kubernetes-rhel9@sha256:f653ee618f8e35c7d69f164eaa244187482e2c8eaa78309748743efa70ebb905
openshift4/ose-pod-rhel9@sha256:de9d477235c7ef452e5c3e8ff0d8e68c919f6c10a72e85f17fcd395857591b40
openshift4/ose-sdn-rhel9@sha256:ff71949fc17158f5ff6c87267a8ccfac4ca998700c544d350000ed290295c868

ppc64le

openshift4/network-tools-rhel9@sha256:93367a64cbaffcc6e657e8b13a0c6f5f9d74097e9b8181469634c6ce8ebee698
openshift4/ose-agent-installer-node-agent-rhel9@sha256:ef2e372f7fe3d6b7da281972c238c83c94403b951f50d38ecf03ad79c5949964
openshift4/ose-baremetal-installer-rhel9@sha256:1aa16d90b177f94d152c49c2aef1e41afead575dc77813db4d03cc8d6255394b
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4eda4dde1a273bffdeba7cc498e90a56a1238739a9dabca40c89f67ceda919e6
openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:639d0e5a437c7eaad0fe61b8aea672aef6dbf9a9d58b2990c2da0685e2749ae9
openshift4/ose-cluster-update-keys-rhel9@sha256:1e4aa688b95e250687fa84358bdbc608056f03fda051e83c5e79616a328125d8
openshift4/ose-console-rhel9@sha256:9baa2d34c23af0ae8b77a6761779c9fc5918d592059380d06767012b378ac154
openshift4/ose-hyperkube-rhel9@sha256:e2109416eb054139d7dac8dbd1fc4f4c990865f32858b82bf173cbed31926b18
openshift4/ose-hypershift-rhel9@sha256:eae315517f214521b5e5d6feae6718621063a89114be1b1b8382c9fee4ad815e
openshift4/ose-insights-rhel9-operator@sha256:b26687cabb631bef6415f0b208a9e7b1af115f1ea9205e3c4cc4579faac5a5bf
openshift4/ose-installer-altinfra-rhel9@sha256:a30a314e458e83bdcb6f4e035576d237368a737293a0c84c644a2e843e099f86
openshift4/ose-installer-artifacts-rhel9@sha256:e6b2468aa0826acf2e13cf728dc203bfc3669a7e27b2d2beb78bef174e56c92a
openshift4/ose-installer-rhel9@sha256:28f298f362791ae39d3474a2527501e01f78fc75a2d2257b79215b00f061656e
openshift4/ose-kube-proxy-rhel9@sha256:8f35d2f498ee4f8e33bf4b3b9bcf5a4c176350b418508d1e5ab3117c2d4c150d
openshift4/ose-machine-config-rhel9-operator@sha256:99b5598c7bcbd0a5b1c42c3e0579adc318a6d099dd48e92187061873732e45cc
openshift4/ose-machine-os-images-rhel9@sha256:36bccdd4bf4ab191e2496e94be3906e8b53b802600eb17cae667b90e6a734a34
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:b365f4462976f80bf96cd8b68e7424facf1065fbd15f0566cf7bb4e502564958
openshift4/ose-ovn-kubernetes-rhel9@sha256:15400005ed8e14ea5cf87b3bc26fccf5e0dded3c450477aa7ffe88c3ca8eddc6
openshift4/ose-pod-rhel9@sha256:a618a0a00537688e95dfb15c5b36a2e5f5c00f5902f2dff2cf1910c22140881d
openshift4/ose-sdn-rhel9@sha256:7534ece64dcd57fda629cadad38587d3103d2e117b71475b2bda3133f665f164

s390x

openshift4/network-tools-rhel9@sha256:771ad63aa6a263439d14010bcc1ca61a6f69c13d8948cab5e0eb5a49b2e19b4f
openshift4/ose-agent-installer-node-agent-rhel9@sha256:1c1e3d5df84a516eed6788859bbcb39366df09fbb53273284db60bca015a1df3
openshift4/ose-baremetal-installer-rhel9@sha256:9ecd96037d8286e42da313bfbc393af117ca9d6cefc24b24bdfb5f2abe02ed88
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:df87192e9855071ba67b68957d5ae88cbc2903026b83cacb00d7d48d78375750
openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:968aea2c932a3538db834964998363b70eccab5d478018ba8e817edb376ae099
openshift4/ose-cluster-update-keys-rhel9@sha256:9fcf9a3fb276c68bb83edf76dd43694d5bc72291bf83a9940579005d1661c564
openshift4/ose-console-rhel9@sha256:353552152238103ac26f8c11abe0e40a9d9bf88d79df52eb75137e497df5f1d2
openshift4/ose-hyperkube-rhel9@sha256:4f9b5e652d432f70b5b86df6346a3f6a5a6a06eae84f05e1decd5c604e9140ef
openshift4/ose-hypershift-rhel9@sha256:a752bedcd03d080d01d0d42a88022586f9e3507552eaf3c2afcff0f811558985
openshift4/ose-insights-rhel9-operator@sha256:284f0113cd28bd7b629117ca791def2e4549a25cb76cb4c5311ed0a62bde3719
openshift4/ose-installer-altinfra-rhel9@sha256:50f757a81efa39ef97649934bd276aa1938eb35cd30b2e3dd511f8bd51853beb
openshift4/ose-installer-artifacts-rhel9@sha256:471b5acf2dd71973329190bedb4eaf3314eee5facfa8c3e8fb17a15a597bde6a
openshift4/ose-installer-rhel9@sha256:9ab7f38ed0fd2273c12423fa30a3aac757c86b7e5714b22fb987cdc51b17b890
openshift4/ose-kube-proxy-rhel9@sha256:96506a8271bb87f50e39c6bdea170a14f29d0ace259727bb046a22f25ebcac3b
openshift4/ose-machine-config-rhel9-operator@sha256:758f4ba9b4f4e824abce1851074654c392fb48a0bab38f8ed1e46fe00eb8fdd7
openshift4/ose-machine-os-images-rhel9@sha256:c0d15e07bfd908142811917c7a57f18daaf3ebbf0602b0a681180051a31b2643
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:dce56f786162b1b07edeba6a1a279866645883586655c5643156ef4cb7352243
openshift4/ose-ovn-kubernetes-rhel9@sha256:f9367cdfb0ac5bba96923a947478d48fc2b4ac956f70ce4b3aad86e69b53ceec
openshift4/ose-pod-rhel9@sha256:9beefd1f1bf1d085e99cf6b757de1609c563508e561f2536bc05561c01fd53cc
openshift4/ose-sdn-rhel9@sha256:11afeca757c2895f36272424c4d6970b159fc9a467f9ec148594ef09a9fe23e2

x86_64

openshift4/network-tools-rhel9@sha256:6577ffa4cfbbf8b15b8d29a8e2e370d8e25aa58b5b359da3a501eeef3f7c7d09
openshift4/ose-agent-installer-node-agent-rhel9@sha256:c92caffec36af37d9eade5f032ddef8ecf81d0b4d26acd7aaffd7b81a12408e6
openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:fbad492113bbe9763af4b04be533473dea08ffdd759a288a697b41c7aafa4d5e
openshift4/ose-baremetal-installer-rhel9@sha256:ce516fe46f04586f81459888e70080209b9c594f3b0b159d9d97b97dabb160fa
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:1fe69a3a000b11276fc0d8917830654e2191d3f396b8d2139c66d03b18b3b81d
openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:65c2eb98167a444ae910e3c490e0b44a467596d000a5e884d90e4bd14b9a3c27
openshift4/ose-cluster-update-keys-rhel9@sha256:047c51c8d81707c5893b5d9f17384db2d503024494f07513ef4e70e19b6d3449
openshift4/ose-console-rhel9@sha256:2ef83f80479dd9234579169e53a17f178c5c67fce9fb767c4d75eb26795eb3ae
openshift4/ose-hyperkube-rhel9@sha256:356eb36a4df44223f5507b7dcc4802c3a4a2a956266df544933b704c91311e87
openshift4/ose-hypershift-rhel9@sha256:4f074178949af6b50920bc1b75bb85ebacc9384525f912369a9e1b37a0acdd27
openshift4/ose-insights-rhel9-operator@sha256:02c9bdab6fd09d7165a5ff28b426698c8a75b7a1c980235b2d0115e0bd73889e
openshift4/ose-installer-altinfra-rhel9@sha256:a4cced445dd661dc2f2afd9ae7db7048de29d99d5139ea81b24fa17a41239cef
openshift4/ose-installer-artifacts-rhel9@sha256:d132b5c83e663b1c288ba26df0cc363dd9e5e2860d8e67d70633c76278bd0e22
openshift4/ose-installer-rhel9@sha256:63601f40d5fca333a31df8673ac43dbbfb0c9c26543fd50ada2f8f6babc9fb31
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:9352f0a3c96e80b36c1a49035434973e4fd7da35cf18dc064a6166a6ab8bd49e
openshift4/ose-ironic-rhel9@sha256:2c0729a7bb1309ea98131f183a33e8e0bc34486558afe426023f6638257f217b
openshift4/ose-kube-proxy-rhel9@sha256:02d98132e4a37307620fb5d957c13221bcc836c50e3675e77c7b329301fe054f
openshift4/ose-machine-config-rhel9-operator@sha256:8a045c2f7b607a4db99411c3c4595e09c334bed8d48dd5607c7425e4280776b8
openshift4/ose-machine-os-images-rhel9@sha256:3c3c670b81807ed2e33d2965889af90bc33c3532fa6df7c8c36c98c6ca8a3dd2
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:320cd7f1e27e5e7b857a9ba451d0cb7725e8aaf84d98e0b0f3d6b16f0e030774
openshift4/ose-ovn-kubernetes-rhel9@sha256:d91e43dddb7749a386ba7bccfb85614b6a0ab391ce0e5e8b5a9343d00815c758
openshift4/ose-pod-rhel9@sha256:7252d235f2e73e641da4f01e738f950f2c02578fdb940bb42070590aa5462367
openshift4/ose-sdn-rhel9@sha256:f4f8eca68f22ad1b43a7497173bad87a803d000c7c422af2dd0ced1062de5bba

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility