Bug 1856529
Summary: | CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4] | |||
---|---|---|---|---|
Product: | OpenShift Container Platform | Reporter: | Yuval Kashtan <ykashtan> | |
Component: | Node | Assignee: | Urvashi Mohnani <umohnani> | |
Status: | CLOSED ERRATA | QA Contact: | Sunil Choudhary <schoudha> | |
Severity: | high | Docs Contact: | ||
Priority: | urgent | |||
Version: | 4.6 | CC: | aos-bugs, ccoleman, choag, danw, iheim, jokerman, jshepherd, kgarriso, mbarrett, mburke, mpatel, nagrawal, pehunt, vlaad, wking | |
Target Milestone: | --- | Keywords: | Security, SecurityTracking | |
Target Release: | 4.5.z | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | Doc Type: | Bug Fix | ||
Doc Text: |
In this release, the NET_RAW and SYS_CHROOT capabilities are no longer available in the default list of CRI-O capabilities. To reduce impact to clusters created in releases before <4.5.z>, the default capabilities list is now contained in separate machine configs: 99-worker-generated-crio-capabilities and 99-master-generated-crio-capabilities. The cluster creates the new machine configs when you upgrade from a previous release.
After upgrading, you should disable the NET_RAW and SYS_CHROOT capabilities, and then test your workloads. When you are ready to remove these capabilities, delete the 99-worker-generated-crio-capabilities and 99-master-generated-crio-capabilities machine configs.
If you are upgrading from an earlier release, you must upgrade to <4.5.z> before you upgrade to this release.
|
Story Points: | --- | |
Clone Of: | ||||
: | 1874671 (view as bug list) | Environment: | ||
Last Closed: | 2020-10-26 14:41:55 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 1874671 | |||
Bug Blocks: | 1858981 | |||
Deadline: | 2022-01-09 |
Comment 24
W. Trevor King
2020-10-16 18:01:18 UTC
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Low: OpenShift Container Platform 4.5.16 security update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:4320 |