Red Hat Bug Fix Advisory: OpenShift Container Platform Assisted Installer version 2.26.1 release
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products13
- Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-agent-rhel8@sha256:84e3c5280d8c0629324b3fbe9e82ac21c7f464a6f64ccb3a6155b24c37bf9040_amd64 as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-agent-rhel8@sha256:9310948fdff425c553994efbc1d5ecac61ca9a4b2236e4f2d4bcf1805a3ff983_ppc64le as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-agent-rhel8@sha256:aac4a97cf6e5d6956e31336b1e19a7006a6a88dbd3bd96e6ba331bd59085e2ce_arm64 as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-agent-rhel8@sha256:c6ee2abb6cca7244a282b8e6b3235e8df8b2864d39fe19919cb3db9047acb943_s390x as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-reporter-rhel8@sha256:323987cc958f26387ebc08a488478e05d634fadc92fc9bf01a3027126b19e251_amd64 as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-reporter-rhel8@sha256:a404b59ec107bc7c1c7d9d19251d44136daf1c3ced06d8f2847fdf0451778562_arm64 as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-reporter-rhel8@sha256:c102491e8a8b7b8a40e09a9206cc3291cecedf5ab13ec1ef9cf3fcdeb1ff00b7_s390x as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-reporter-rhel8@sha256:d87f95f5c685d893fc10b447345964a16731fe5bb2b95dc5a5494c7fc7f0d37c_ppc64le as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-rhel8@sha256:6f242c9c58eb6b963043634deb588c7650b4d9d920b552875cc38c7339dbe971_arm64 as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-rhel8@sha256:87d17df6b11851fc76fc59baeb116f9b0476e295df7ae4a19dcc4cba28884450_s390x as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-rhel8@sha256:daec8e0db2c276cd52a80115da4a52715f27584ea0d699ba9583786dfae2bf3b_amd64 as a component of Red Hat Assisted Installer 2.0
- rhai-tech-preview/assisted-installer-rhel8@sha256:e74ce2a65fefa286b1583aaad613736035c7052fe8d4bf53d315365c61696dba_ppc64le as a component of Red Hat Assisted Installer 2.0
✅ Remediation
For OpenShift Container Platform 4.14, see the following documentation for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHBA-2023:6254
- externalhttps://issues.redhat.com/browse/MGMT-13692
- externalhttps://issues.redhat.com/browse/MGMT-15984
- externalhttps://issues.redhat.com/browse/MGMT-16011
- externalhttps://issues.redhat.com/browse/MGMT-16037
- externalhttps://issues.redhat.com/browse/MGMT-16039
- externalhttps://issues.redhat.com/browse/MGMT-16045
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhba-2023_6254.json