Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: OpenShift Container Platform 4.7.8 security
and extras update
Advisory ID: RHSA-2021:1227-01
Product: Red Hat OpenShift Enterprise
Advisory URL: https://access.redhat.com/errata/RHSA-2021:1227
Issue date: 2021-04-26
CVE Names: CVE-2021-3121
====================================================================
1. Summary:
Red Hat OpenShift Container Platform release 4.7.8 is now
available with
updates to packages and images that fix several bugs.
Red Hat Product Security has rated this update as having a
security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base
score, which
gives a detailed severity rating, is available for each
vulnerability from
the CVE link(s) in the References section.
2. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud
computing
Kubernetes application platform solution designed for on-premise or
private
cloud deployments.
Security Fix(es):
* gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain
index
validation (CVE-2021-3121)
For more details about the security issue(s), including the
impact, a CVSS
score, acknowledgments, and other related information, refer to the
CVE
page(s) listed in the References section.
This advisory contains the RPM packages for Red Hat OpenShift
Container
Platform 4.7.8. See the following advisory for the container images
for
this release:
https://access.redhat.com/errata/RHSA-2021:1225
All OpenShift Container Platform 4.7 users are advised to
upgrade to these
updated packages and images when they are available in the
appropriate
release channel. To check for available updates, use the OpenShift
Console
or the CLI oc command. Instructions for upgrading a cluster are
available
at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
-
-between-minor.html#understanding-upgrade-channels_updating-cluster-between
- -minor
3. Solution:
For OpenShift Container Platform 4.7 see the following
documentation, which
will be updated shortly for this release, for important
instructions on how
to upgrade your cluster and fully apply this asynchronous errata
update:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-rel
ease-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
- -cli.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1921650 - CVE-2021-3121 gogo/protobuf:
plugin/unmarshal/unmarshal.go lacks certain index validation
1950891 - Placeholder bug for OCP 4.7.0 extras release
5. References:
https://access.redhat.com/security/cve/CVE-2021-3121
https://access.redhat.com/security/updates/classification/#moderate
6. Contact:
The Red Hat security contact is <
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYIbqPdzjgjWX9erEAQjkTw/9Gl8fRWtywhbT6fN1rx48sTEWb8/db388
pHWNqQp2rB+t65vZRTzUMgA+2c2FiRdVEWVN/BNMQk7Jh9/WdGJaetCKmEOPZOqM
0MpWT5a8mhMT5Ckzl8Dlz44qm1g0cgxGja0rZIhYBcAnDINAoEiPadvUWzHmfw1p
SX6HGCW46BnYCjMXY9/2lNEZxBY14Gv6k4lw41dh4hEMujZX490rdk/PXpcIeJLG
z1nfrhbkHL8m8SBVqb0YI1Agd+lJ2zuBh5dBM01mhqHHK9ziwJtW9nM1Ti8nIWLY
hu9npIJnvO0DtO1MJy5UClr8rcLMBl+0Iiara6nDxAafud5JKFwZ7/k5Orxfnier
iVxGQBfm5FVOLCUY9EPra01McyIawvpx3NvB6ivCo8+zj37AecZp/KfVz5InkNtH
msuIlqKXjwuwzMlcuNWVuh3Bq9C/6mXvoZYs5YUo6MZxyoTs6zWAnvF3WLGpmzW+
JzoL3KRi+LFYBIu5xxKVXpGXNydEs+mwrMnFpWyMYNvY4fR1JM/tl8JkVMSRk38u
PHHuUvAlmgi/14ZTwdcWJhk0Lvu2qAD5vYCBlvT65fIRZrPpMvQBw+0+7DyyKmUH
AIhk0mDIiowy3B5SfTRrieH64/2FuVP66r0bWXoBKBf8oRU+sUiMK/W2w+wDrZzG
nk75I3cl3o8=F/bt
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Read more https://packetstormsecurity.com/files/162336/RHSA-2021-1227-01.txt

