RHBA-2023:6124HighCVSS 7.5
Red Hat Bug Fix Advisory: Red Hat Quay v3.9.4 minor release
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products11
- Quay v3
- quay/clair-rhel8@sha256:d063fd53c313d31fb6b8ae2b5c90ca72c612754cfd28dc91b731c331d679fcb9_amd64 as a component of Quay v3
- quay/quay-bridge-operator-bundle@sha256:83ba5dd9ce4a37474e70e8d8536911314d0c258f7c50232fa202d1c01c8755f8_amd64 as a component of Quay v3
- quay/quay-bridge-operator-rhel8@sha256:4c6b3d41f9f8640ec1c341444e09af6f6d222cc1b32c35a4e4f79fb9cb00fc44_amd64 as a component of Quay v3
- quay/quay-builder-qemu-rhcos-rhel8@sha256:259d7c4aad2559a052d26e3555fb4e30b6ddbc08b949e77b351dedafff0c5a4d_amd64 as a component of Quay v3
- quay/quay-builder-rhel8@sha256:c0fa0c35c2bb1baba0cad43d259d8fb3c4bf81ae1b96711bc32e919b1ae57292_amd64 as a component of Quay v3
- quay/quay-container-security-operator-bundle@sha256:9af0519509785cf2889fe81fd490453dc8f919c5a307ba442084fc75f5388ae2_amd64 as a component of Quay v3
- quay/quay-container-security-operator-rhel8@sha256:c06fde1e0433aee697c0182ff70829642edfcce7df6addb614f60042e05bc991_amd64 as a component of Quay v3
- quay/quay-operator-bundle@sha256:39fe504ac94fce04fa8679657aa97e42b530b3b4f0699ac90194a7373f0e4129_amd64 as a component of Quay v3
- quay/quay-operator-rhel8@sha256:8fb1d9966d70ab01a66387d38831378d818d17f58057138540aac83c6b4fe0cc_amd64 as a component of Quay v3
- quay/quay-rhel8@sha256:ad7db1f398e1d5fd98d453f08a7c855de600541b626a39c0669f8d67f9c7771c_amd64 as a component of Quay v3
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.