Uploaded image for project: 'OpenShift Core Networking'
  1. OpenShift Core Networking
  2. CORENET-5342

Impact OpenShift 4.14.40 downgrades libreswan to an older version with CVE exposure

XMLWordPrintable

    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None

      Impact statement for the OCPBUGS-44379 series:

      Which 4.y.z to 4.y'.z' updates increase vulnerability?

      • Customers upgrading from any 4.13 or 4.14.z to 4.14.40 with IPSec enabled
      • A fresh installation of 4.14 with IPsec configured (spec.defaultNetwork.ovnKubernetesConfig.ipsecConfig: {})

      Which types of clusters?

      • IPSec OCP enabled clusters

      What is the impact? Is it serious enough to warrant removing update recommendations?

      How involved is remediation?

      Is this a regression?

      • Yes, this regression was introduced by pinning the libreswan package in ovnk container on 4.14.40 

       

              zshi@redhat.com Zenghui Shi
              trking W. Trevor King
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: