RHSA-2023:5809HighCVSS 7.5

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2.2 Product Security and Bug Fix Update

Published
October 17, 2023
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products8

  • Red Hat Ansible Automation Platform 2.2 for RHEL 8
  • Red Hat Ansible Automation Platform 2.2 for RHEL 9
  • receptor-0:1.4.2-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 8
  • receptor-0:1.4.2-1.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 8
  • receptor-0:1.4.2-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 9
  • receptor-0:1.4.2-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 9
  • receptorctl-0:1.4.2-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 8
  • receptorctl-0:1.4.2-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 9

✅ Remediation

Red Hat Ansible Automation Platform Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (4)