RHSA-2023:5896HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.12.40 bug fix and security update

Published
October 25, 2023
Last Modified
August 18, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:2b1111df93ac6bbd3e41f062b93f5447a5b1211b0520cf0efcd1459bbc07313e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:649ca238e1bfd44616251260bda84947d1276ef571028ee9d667c737cedb0abf_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:c260314ce32117ef2b47da987465797573efa7a947bb7c3370e74c619fa708db_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-network-config-controller-rhel8@sha256:e008378300c11c1c8b5fab48d13911aadbed115ad304fff265c737e234cebf63_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:635b15478f717a49ad336ecb4ac7b2974bd31784aadfd6aaea89ee515c64c271_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:7bba84f766c22241fb45a02f7934a9a2f34766c678e2beff7bcdf30b4353a534_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:8971938b624483a0845cbda355b6e55e26bb95f87f1e6c252b3fa36c68df7ea1_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/egress-router-cni-rhel8@sha256:bc95f121c003db4cdaa0425f4fd3d91ef9e079d8c67217d811dbe33a83748470_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:0157ec50af67bb54ed0581b32550124741015eb654ac302aca8f9ca70307e8a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:3d92ea9f6af0f7c6d9e0754e66226351de3cba5fef5c05d93e7349ddf4cfc02d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:58c546b1a68f4bf8467a7bec9820ceaaf1ccaf7f1d243639c240ee10d23ea43a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubevirt-csi-driver-rhel8@sha256:7c249c78a9308ac9ab8d61d0598e9c834f4d11ae4895ab3143b76fdba5837259_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:1f64e67093165f8c485e15772909898238331c952596b698bc49d39cf01d03c1_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:9084cd8e37eaf09291d2b427645e5cd40618e50b821f371a2803abc7de6ec8f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:c97ddb479618fd7ac247b4aa5f2fde5937fcf4bfd2f61736f2334f73ff4e2cf8_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/network-tools-rhel8@sha256:f562b928112e0d7b1cfc02be3aa2d8fa75a9b14d5a336f1eedce5cddd9d8119b_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/oc-mirror-plugin-rhel8@sha256:d91a6410a01c652620de1bc0162b525379026dd88a3054a546fc4721bd890f7c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:7bdd4492ce1d348342bae28c248182ecb3548d3528250dee53903a399c2f9a6a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:b579bc8e5c3452d2c3efee591240d7ae8e783225d6169caf4227923a82896d7c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:d4480a2e94452006b35ed51c75b070783571bfefd49cc128cc794d2fa9b49e7e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/openshift-route-controller-manager-rhel8@sha256:ebc90db39a8c83316048ed114d6e50c25464fb5b8db9a9fb2cdc9db03a79aece_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:7a185558386a23e058ee84020eecb813c16b4f414af7c52f5ade555b8e5d2708_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:8fd0a72a8fa225ed311a74fde3bd02d81dacf5d9c4dbba8048c5b0b5e6adc4ad_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:c6eafdf4d4ec4e558fef4d561de92a8fdd7eb800047580c3edd5f4a497407b95_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:db3d5b39c0eb45a29b3fbbccd50e43b1b6cb5ea6c6262f6d43c3d7f5d8f2362c_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:01ef876b469d69385e30adcc512359b24a3da4205b25e7cc59b11430c59a3cbd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:6eba8ff772806f7ec148c6b0c1294c0502e72e9233143a2e713db87cb1bae84e_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:bb77a72d815a26c990d1252a722da735681fd33b342efaa6446db4cf3f9c18b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:cf816b940b2a618a437fc17a8f126cf10052abae3c4d6d2d14fc191d3cba8bf6_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:b0b1aac82f9083d20e7e4269b05dd3679299d277d122fa9d29b772f38d2cacff (For s390x architecture) The image digest is sha256:a3708a1c82e2ebad7960bbf6cce9ede744f03d5a3f188c1fdfd30ee97d119f84 (For ppc64le architecture) The image digest is sha256:5dabb62ee50a11536d163230bcf2122554eb8cda9f124715903542cd15d39852 (For aarch64 architecture) The image digest is sha256:6dc1980ef56c62ceec013aa60319ba93b0edd1fbcc8dce081bd6f9f04c3f1bdc All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (6)