Bug 1856529
| Summary: | CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4] | |||
|---|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Yuval Kashtan <ykashtan> | |
| Component: | Node | Assignee: | Urvashi Mohnani <umohnani> | |
| Status: | CLOSED ERRATA | QA Contact: | Sunil Choudhary <schoudha> | |
| Severity: | high | Docs Contact: | ||
| Priority: | urgent | |||
| Version: | 4.6 | CC: | aos-bugs, ccoleman, choag, danw, iheim, jokerman, jshepherd, kgarriso, mbarrett, mburke, mpatel, nagrawal, pehunt, vlaad, wking | |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking | |
| Target Release: | 4.5.z | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | Doc Type: | Bug Fix | ||
| Doc Text: |
In this release, the NET_RAW and SYS_CHROOT capabilities are no longer available in the default list of CRI-O capabilities. To reduce impact to clusters created in releases before <4.5.z>, the default capabilities list is now contained in separate machine configs: 99-worker-generated-crio-capabilities and 99-master-generated-crio-capabilities. The cluster creates the new machine configs when you upgrade from a previous release.
After upgrading, you should disable the NET_RAW and SYS_CHROOT capabilities, and then test your workloads. When you are ready to remove these capabilities, delete the 99-worker-generated-crio-capabilities and 99-master-generated-crio-capabilities machine configs.
If you are upgrading from an earlier release, you must upgrade to <4.5.z> before you upgrade to this release.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 1874671 (view as bug list) | Environment: | ||
| Last Closed: | 2020-10-26 14:41:55 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | 1874671 | |||
| Bug Blocks: | 1858981 | |||
| Deadline: | 2022-01-09 | |||
|
Comment 24
W. Trevor King
2020-10-16 18:01:18 UTC
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Low: OpenShift Container Platform 4.5.16 security update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:4320 |