RHBA-2023:7585HighCVSS 7.5
Red Hat Bug Fix Advisory: LVMS 4.12.z bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products17
- LVMS 4.12 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:7fe4d2f8952aec2363a41cfa52d8a5af8eeaad0b825305ad7c3ded5c66d8e880_amd64 as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:a0a5223ceba00ba2f7c1c412b9be12e6de067b15a77e1d36c68fa2c33e0b2ed3_ppc64le as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:d90a99e55479c81464958af10d373080f68f6472448cb3e64d277d58c3edb9fe_s390x as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:e9f67e0566688a35bbcb466f2fa2c387dfcadbd075d775f47eb768de1b8634c1_arm64 as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:3d45d0f9163fcafd6887dd6ab1a46f95201896febd05a1f3c9c92fc8da2cd613_arm64 as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:6069c716a5204b195d7d7ac2101872cce2719fa4eaf5fa870df8dc0e40807da3_s390x as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:9f31b8ca61b9c36a4c1543ade4a9bd3cdf7471f49262183abdcfd2e6ed963711_ppc64le as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:a8e7fc912fa5f64c16fcae7eb764ff048c1a7d04e0e7b3903a66aa07d7c1ebc6_amd64 as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:2522f3d2dfa776c3aa5cdea16df5d7d12ef5224db2d83182c62c013a4f6b51cc_ppc64le as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:8754ba369dfd3eab19c617960c4c8702766de735c55e6d94184917e58c80073f_s390x as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:cb8af860369ac67091ae5fc6cf722a056fda251c30a00f181a80d5a4a061a1ca_arm64 as a component of LVMS 4.12 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:dad91322329e2f779963cc0f99b467971d548e8da704661e7e0e4a8fecbff61d_amd64 as a component of LVMS 4.12 for RHEL 8
- lvms4/topolvm-rhel8@sha256:72cb4ec110b115061c7025d1e1e696361cd3e948f49205295d7137bde437d041_amd64 as a component of LVMS 4.12 for RHEL 8
- lvms4/topolvm-rhel8@sha256:8f9402ccaaf0c0e0e2eb05997da4603dfa2d56798537bbf63fb9132a78d298d1_ppc64le as a component of LVMS 4.12 for RHEL 8
- lvms4/topolvm-rhel8@sha256:ac9dd4ba6deb0983f8ad423743f14aa11a3b2cf5be26b79294c503e3078d3a68_s390x as a component of LVMS 4.12 for RHEL 8
- lvms4/topolvm-rhel8@sha256:eef9906cf3d713d2253962925f83058eb1b83f2d643d5f1c160a0504c0bc7eb2_arm64 as a component of LVMS 4.12 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.