RHSA-2023:5895HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.12.40 security and extras update

Published
October 25, 2023
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products154

  • Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:1a93529f75771c9f387697acb6f7be99df01694d9adc255301fe9bc75221d3ef_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:b74b42b48eac7f6305233a3a3f030a41f44fc0a49f2b0e996c4ad99661cee34b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:d3bdd7df1934e0f8facacd04e636fcd76bedf98ca7db5d7d24c30d0b0887680e_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:f23ca252b6e8ffbff4b7556a99aa193b254348f8735dcc21e68e5145e0b6aa07_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:431482eb58ccfa9795a5750cf74efa63fbcfd1a7594dd66a1b81a0d3b568c217_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:a6022d35a6475e902280dcfb5874ba4be8c196927d481a8c1e27cabbb87c1dbd_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:ff2c66593c08bd48cfd312e3c69ed3af69cec1a609939e34cd178f33da062921_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:53c7c148f3a31cc4bd4b60cdc735b8842b9c50945bfc68a8f414ed838542010c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:cbd9877899f6f9a0445d28647f0619c4d186e7a0824cc30986e24c0640c5be98_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:72cf77954e8a4946961bd20c7b05398f9c99ae15ddde1aca9dfe6eb442b12022_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:a1199349c9f7321b67ec73a3bb7ec8eb02c1892fa8ff60d135c9957a48b1aa7d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:a2101864a1bdef883ff6493642870fecbe91b0e31ea57a36f918523ec552213b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:e723f8ef299deb977eabc5b96adf6f2d1dd37f5a892d338c56bef95bc6f8fd8c_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:285d86578ee1284e413bd1e991d33bc1d956db5af64e42525afa2216d95dfe74_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:7fa41d4dc5d21f6970e55374a0d3c1d1a1d1e70b802538bae0067add8d17fb2d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:81c28fa0f67121b63c30f263b287c31dfa63d781226b2c2da6151551fadc2b6f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:b98d3493fe884eade42907b7d61a34d56e4da206d5211710862ea7a9b01052db_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:108683934e0081dd2b47d45b8645da0597e801d6393e0275bba60e557df22118_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:46e5e9c1a0de429ce010c8413c436b65db487b901559a31ec12d7ad5ac285ee9_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:780bf0296dfeb56ea236682bde3a200953f52ffc4a7806e57a1b2a9907edc6a0_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:ed4b83ea6860722a34422419763d8181cc2729c2c66e113e42b004f788715789_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:8a7ff91387a533b4727278f654260f37031a9f25bd8e020e9cc6b8801d2e53ef_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:8d27e611fdef663f48d1210f3c79861207cd3022c45e6a0b9024783fd3cdfbef_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:ca5d88db03042677dfabcc969806a3e4c3a68029ba5ce0593e49edacab809fff_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:d017795ad6e97fbfbc4e63c212bb3df8fd253e7fe67e0764571be242e8a67bd6_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8@sha256:1a93529f75771c9f387697acb6f7be99df01694d9adc255301fe9bc75221d3ef_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8@sha256:b74b42b48eac7f6305233a3a3f030a41f44fc0a49f2b0e996c4ad99661cee34b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8@sha256:d3bdd7df1934e0f8facacd04e636fcd76bedf98ca7db5d7d24c30d0b0887680e_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8@sha256:f23ca252b6e8ffbff4b7556a99aa193b254348f8735dcc21e68e5145e0b6aa07_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • +124 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)