RHBA-2023:7586HighCVSS 7.5
Red Hat Bug Fix Advisory: LVMS 4.13.z Bug Fix and Enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products17
- LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:12885b6b6d64c105689508aea0a90902842c4bbbf21d4bc6ef26d8e35b6f1b50_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:542d07477c08ac6b698b8bd98240228e21c745c32358f652d4329ddaea5767f1_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:933f866c0e4dabdfe0497e77fe8d850707c91db9471ed2467aa455a40dc03735_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-must-gather-rhel8@sha256:f7ca5e42ceb94f5ae70309a1631be95d86fe39949465e98e85b06aaf831629b0_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:2b2dd11ad74ab33990e344fd79fabcd58f0928a33136a924893a849e1dfd8ade_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:3d8d44a805b25585e9f608742d5c53d0e916cfd6abc7a399064d30325b0bfa78_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:756f7e22c29de4cd4739f3ac3fc2ae3af691ed16bf26e7793b21d40dc585ae57_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-operator-bundle@sha256:7c33481a369c17e94fb1568ff83487a582a759b8efef0008a4b8429d2b42d9fc_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:24b36f1f27e9ef5f093949a185234847d64841e607492e86ed09403b82e1c100_arm64 as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:320ae528ed8805b724766978dc54639611f55057355a4a9e6bf1f4570076ad73_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:36ffda49af83825b6d19c88b397db19e01862e61d9cd297ee872998fd03aa372_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/lvms-rhel8-operator@sha256:a4f5c04f02980663ab608cc7909f23d71d8009a217f8ac9a4bb4ae525c9acba4_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:4dc9659b98f993354fc39cb422a06f320200030c2e65575320badecf2b8b5afe_amd64 as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:869b4218a53fa8b4466dd0a2085994091a2b7f24715937867aa8066f87ef64ee_ppc64le as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:ae57a8c475013bc7dc67ef235de52ab04f2f3d8f2c04de81e1ab77101e578331_s390x as a component of LVMS 4.13 for RHEL 8
- lvms4/topolvm-rhel8@sha256:d6b502771393b18780dcb972cce1cf386e8c1eff783a0532d5a518b17278d7df_arm64 as a component of LVMS 4.13 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.