Security
Headlines
HeadlinesLatestCVEs

Headline

RHBA-2023:1507: Red Hat Bug Fix Advisory: OpenShift Container Platform 4.12.10 packages update

Red Hat OpenShift Container Platform release 4.12.10 is now available with updates to packages and images that fix several bugs.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Related CVEs:

  • CVE-2023-25577: A flaw was found in python-werkzeug. Werkzeug is multipart form data parser, that will parse an unlimited number of parts, including file parts. These parts can be a small amount of bytes, but each requires CPU time to parse, and may use more memory as Python data. If a request can be made to an endpoint that accesses request.data, request.form, request.files, or request.get_data(parse_form_data=False), it can cause unexpectedly high resource usage, allowing an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests, and if many concurrent requests are sent continuously, this can exhaust or kill all available workers.
Red Hat Security Data
#web#linux#red_hat#dos#redis#nodejs#js#git#java#kubernetes#aws#ibm#rpm

Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager

All Products

发布:

2023-04-03

已更新:

2023-04-03

RHBA-2023:1507 - Bug Fix Advisory

  • 概述
  • 更新的软件包

概述

OpenShift Container Platform 4.12.10 packages update

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

标题

Red Hat OpenShift Container Platform release 4.12.10 is now available with updates to packages and images that fix several bugs.

描述

Red Hat OpenShift Container Platform is Red Hat’s cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.12.10. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHBA-2023:1508

All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html

受影响的产品

  • Red Hat OpenShift Container Platform 4.12 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 8 aarch64

修复

  • OCPBUGS-11029 - Placeholder bug for OCP 4.12.0 rpm release

Red Hat OpenShift Container Platform 4.12 for RHEL 9

SRPM

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.src.rpm

SHA-256: 6696e69cc1b5c4f118d093126c99624367705b21a9c48a28d4b2df845e762912

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.src.rpm

SHA-256: 10f23a46a46b51fca35567c3cf358c6d9993bc9e2410b77e20964a5de1617a0c

python-werkzeug-2.0.3-4.el9.src.rpm

SHA-256: 39d2e8299c971474ce810c3dda91ba07adbb5005d35fc91f2b3d637d12a74d95

x86_64

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.x86_64.rpm

SHA-256: d9316fad4e2ebf2c4bddf1f44a1c9b4c076cdc8c655b2b5ec97754bfc7306cb9

cri-o-debuginfo-1.25.2-13.rhaos4.12.git3e4b64e.el9.x86_64.rpm

SHA-256: 1754b3e8fdee1e21ccc654c2295f37290be97b7531c5ea12756b3414e3bc8d70

cri-o-debugsource-1.25.2-13.rhaos4.12.git3e4b64e.el9.x86_64.rpm

SHA-256: e4dc07771dfde6ac99ceb6b14bbd41f1c117ecc15d5cbe69e2bc430693e9ad04

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.x86_64.rpm

SHA-256: 84fd188d385f0023f84cc89e2842099aafb272bdf1d25feb6a22d3e664a09902

openshift-clients-redistributable-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.x86_64.rpm

SHA-256: d1dbd4ab95574ba7ddb1fe52271f61bc6b683cbca07c188afdcbbb92ba781599

python3-werkzeug-2.0.3-4.el9.noarch.rpm

SHA-256: 14fbddebaac3466948201473752d0d3086c74b9afbd935a6104aef11009bc4b6

Red Hat OpenShift Container Platform 4.12 for RHEL 8

SRPM

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.src.rpm

SHA-256: 91fcc5fb3397d226394ddc70cdf4aca7f465ea6679cc4681359cb59bae92411a

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.src.rpm

SHA-256: 8f5f155ae6e8455e1879a68e9d23ad98e33876fef93391718774a5309af6e8da

x86_64

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.x86_64.rpm

SHA-256: 3038441a05c07326f1939627ef3d92211b56486ee059afb95f171e1014e5764d

openshift-clients-redistributable-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.x86_64.rpm

SHA-256: cacca01562833ce662343460cdd7665ed49132216a491c7857b48a4c1e89266d

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.noarch.rpm

SHA-256: 7b873cb44227298bc88dc5adfa0c873ae5a03aba1737cd0ca7394b63f8b3eff0

Red Hat OpenShift Container Platform for Power 4.12 for RHEL 9

SRPM

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.src.rpm

SHA-256: 6696e69cc1b5c4f118d093126c99624367705b21a9c48a28d4b2df845e762912

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.src.rpm

SHA-256: 10f23a46a46b51fca35567c3cf358c6d9993bc9e2410b77e20964a5de1617a0c

python-werkzeug-2.0.3-4.el9.src.rpm

SHA-256: 39d2e8299c971474ce810c3dda91ba07adbb5005d35fc91f2b3d637d12a74d95

ppc64le

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.ppc64le.rpm

SHA-256: 05b79ec5ed015b4cb121c362c9ff8bd946f9377e4e746014e8c30ff1c8102277

cri-o-debuginfo-1.25.2-13.rhaos4.12.git3e4b64e.el9.ppc64le.rpm

SHA-256: 2491c7d58ce98736647f1f1ba0f114e66567ef626f5958357dfc4c372b0b3727

cri-o-debugsource-1.25.2-13.rhaos4.12.git3e4b64e.el9.ppc64le.rpm

SHA-256: 9177da4c00c919f68420f3ffcc81ddb81ec3ed72c90ade0b717063faa775d690

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.ppc64le.rpm

SHA-256: 0948aab5e6a95d83d8f63214b66fff2d087d0c650154cef9358760a9ed7dcb54

python3-werkzeug-2.0.3-4.el9.noarch.rpm

SHA-256: 14fbddebaac3466948201473752d0d3086c74b9afbd935a6104aef11009bc4b6

Red Hat OpenShift Container Platform for Power 4.12 for RHEL 8

SRPM

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.src.rpm

SHA-256: 91fcc5fb3397d226394ddc70cdf4aca7f465ea6679cc4681359cb59bae92411a

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.src.rpm

SHA-256: 8f5f155ae6e8455e1879a68e9d23ad98e33876fef93391718774a5309af6e8da

ppc64le

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.ppc64le.rpm

SHA-256: ce4e6ffe718b2ae10a4b52241b99bcd71dab7b6e4450f9fd1405b4d15de72e1b

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.noarch.rpm

SHA-256: 7b873cb44227298bc88dc5adfa0c873ae5a03aba1737cd0ca7394b63f8b3eff0

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 9

SRPM

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.src.rpm

SHA-256: 6696e69cc1b5c4f118d093126c99624367705b21a9c48a28d4b2df845e762912

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.src.rpm

SHA-256: 10f23a46a46b51fca35567c3cf358c6d9993bc9e2410b77e20964a5de1617a0c

python-werkzeug-2.0.3-4.el9.src.rpm

SHA-256: 39d2e8299c971474ce810c3dda91ba07adbb5005d35fc91f2b3d637d12a74d95

s390x

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.s390x.rpm

SHA-256: d7bde13b949f75f898c20e5ee0df1d3d3290a43bd0d26644552b306870ca7648

cri-o-debuginfo-1.25.2-13.rhaos4.12.git3e4b64e.el9.s390x.rpm

SHA-256: 4d0c482863a2a89cfbe85a601739a1f3c8ddf796ec185a95d4682cf65dab1e3b

cri-o-debugsource-1.25.2-13.rhaos4.12.git3e4b64e.el9.s390x.rpm

SHA-256: f684263a73f62da0f2468eee71dec1b4f342065036a912ca14d73feccf037ad6

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.s390x.rpm

SHA-256: 793649dff9e7259ac5a827eee59f91dfa611aaa2448c3f266d4bbe0e83791a0c

python3-werkzeug-2.0.3-4.el9.noarch.rpm

SHA-256: 14fbddebaac3466948201473752d0d3086c74b9afbd935a6104aef11009bc4b6

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 8

SRPM

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.src.rpm

SHA-256: 91fcc5fb3397d226394ddc70cdf4aca7f465ea6679cc4681359cb59bae92411a

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.src.rpm

SHA-256: 8f5f155ae6e8455e1879a68e9d23ad98e33876fef93391718774a5309af6e8da

s390x

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.s390x.rpm

SHA-256: 0243878a7b6f0d51648e25cf9f50c280dfe9ce8faee11467200f918fc1567e8e

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.noarch.rpm

SHA-256: 7b873cb44227298bc88dc5adfa0c873ae5a03aba1737cd0ca7394b63f8b3eff0

Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 9

SRPM

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.src.rpm

SHA-256: 6696e69cc1b5c4f118d093126c99624367705b21a9c48a28d4b2df845e762912

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.src.rpm

SHA-256: 10f23a46a46b51fca35567c3cf358c6d9993bc9e2410b77e20964a5de1617a0c

python-werkzeug-2.0.3-4.el9.src.rpm

SHA-256: 39d2e8299c971474ce810c3dda91ba07adbb5005d35fc91f2b3d637d12a74d95

aarch64

cri-o-1.25.2-13.rhaos4.12.git3e4b64e.el9.aarch64.rpm

SHA-256: cb9d5d5daae32d67df8283e081ae0718d6e11ebe06e65f6a9d4c31c2c435c173

cri-o-debuginfo-1.25.2-13.rhaos4.12.git3e4b64e.el9.aarch64.rpm

SHA-256: bcd2579112fbcd8b183fcb28e85e59eb342541a397ec8afef1423577e4426353

cri-o-debugsource-1.25.2-13.rhaos4.12.git3e4b64e.el9.aarch64.rpm

SHA-256: f6b2c4dcdf88223532f6a73951927e2250bc124de98757224036b7d46a85f51f

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el9.aarch64.rpm

SHA-256: f48d3d4c3440242ec94294589be5a4b2834b72d01243113bcd42fcc5045852ac

python3-werkzeug-2.0.3-4.el9.noarch.rpm

SHA-256: 14fbddebaac3466948201473752d0d3086c74b9afbd935a6104aef11009bc4b6

Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 8

SRPM

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.src.rpm

SHA-256: 91fcc5fb3397d226394ddc70cdf4aca7f465ea6679cc4681359cb59bae92411a

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.src.rpm

SHA-256: 8f5f155ae6e8455e1879a68e9d23ad98e33876fef93391718774a5309af6e8da

aarch64

openshift-clients-4.12.0-202303240916.p0.g31aa3e8.assembly.stream.el8.aarch64.rpm

SHA-256: 78573c9a427235cf27efbcbff546fa3b684a214374342f9edb6ac20dca65c909

openshift4-aws-iso-4.12.0-202303221729.p0.g6b545b8.assembly.stream.el8.noarch.rpm

SHA-256: 7b873cb44227298bc88dc5adfa0c873ae5a03aba1737cd0ca7394b63f8b3eff0

Red Hat 安全团队联络方式为 [email protected]。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat Security Data: Latest News

RHSA-2023:5627: Red Hat Security Advisory: kernel security, bug fix, and enhancement update