- Issued:
- 2020-12-17
- Updated:
- 2020-12-17
RHBA-2020:5601 - OpenShift Container Storage 3.11.z Container Images Bug Fix Update
Synopsis
OpenShift Container Storage 3.11.z Container Images Bug Fix Update
Type/Severity
Bug Fix Advisory None
Topic
Updated container images that fix various bugs are now available for Red Hat OpenShift Container Storage 3.11 Update 6 in the Red Hat Container Registry.
Description
The OpenShift Container Storage solution provides persistent storage service for OpenShift Containers and OpenShift Infrastructure services.
This advisory fixes the following bugs:
-
Previously, Heketi could not collect debug information on bricks that could not be unmounted, because of the missing lsof command in the container. With this update, the lsof package is included in the rhgs-server container image. Heketi can now collect the list of applications that prevent a brick from unmounting. (BZ#1814287)
-
Previously, the ssh server in the rhgs-server container image supported SHA1 kex algorithms. These are considered weak algorithms and must be disabled. The default configuration in the sshd config no longer includes SHA1 based kex algorithms. For more information, refer to https://access.redhat.com/solutions/4278651. (BZ#1821615)
All users of OpenShift Container Storage 3.11 container images are advised to pull these updated images from the Red Hat Container Registry.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Gluster Storage Server for On-premise | 3 | x86_64 |
Fixes
- This content is not included.BZ - 1787998
- This content is not included.BZ - 1814287
- This content is not included.BZ - 1821615
- This content is not included.BZ - 1829396
- This content is not included.BZ - 1892684
CVEs
- CVE-2019-11719
- CVE-2019-11727
- CVE-2019-11756
- CVE-2019-17006
- CVE-2019-17023
- CVE-2019-20907
- CVE-2020-6829
- CVE-2020-8177
- CVE-2020-12400
- CVE-2020-12401
- CVE-2020-12402
- CVE-2020-12403
References
(none)
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.