RHSA-2023:6071HighCVSS 7.5
Red Hat Security Advisory: RHACS 4.0 enhancement and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products34
- RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:203f669dfecbe15bf2c026191fac9f03cc2f0a24d4e8ebaa612e03f855cd412c_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:a26eaebf47bcf49be38da18badf53884fe8a39b2110de2288e5f83a1ee761202_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:ff2e32cba218f944d628ab1b12e13f47ba2f5c59198fbadfa91a48203ec65edc_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:681c44488bef3551c8a48b955cb4f80377336474b5eff91d751df9616b403c90_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:7b40266e9bcf63f9d17057d41a8d74a6996666a17bae8f5480d18bf68b3d36be_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:a59f4e48c51878df91baf624c89a5157f7b6298a14260c0b5d6f902a2aeb574a_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:8d01a5d038f9f778df054ab9533ff700dfafc72a8b6e086910f2e5db0634b21b_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:b3f8f5122676f1a9a46f38f7cf8e265536f275ecb7c2ad08874f5e792cc12af0_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:b60c0000ee6f5c5bfcee7ecac40feac1029f8520236cec8eb76a7353f7fab2b5_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:02afc60209fa02f98325677202887cf58a04dd334ead4bea9d601b2ebca60f25_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:39bc3203d9b1bb5031c8abdcf18b578cdb06d87939b92a1adbfe7f58f7263e5e_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:4b727955da552e9137b8beaacb58743e242ca18c722da4c83d139d01f39ced67_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:683fc6bcd5de85b025df05e59c4ca7d895fb4a3764d65a53f5f0301fd59629a4_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:a0d9cd31d953aaf7e84f5a39f405c5aa2ea62e68d6c728a936ca1ffc4dc1b93e_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:c2f484a894fe64522f40b9d0c16e19e933560505aec2e156f7ba543e3f0331bb_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:37d3b4a85e1214f54d485732f20a83c88a20622a66de83f5f445d9b6274cafe2_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:b52ff18b3d963f57dc7aeb5ffc8143aaa6eb76bea5e7912fe2f0fc6e7a6f3245_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:e2c292eebafb277fbb4d273e9edfe22435b2201e08c02c04011330e0c13fa335_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3062a2b35b2911df16e2c4d19bd3e231f4e4f4bd64bfb2d909e54c85eb3bb282_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4774c909ac77d2d0efd233b54380166576ffa1695cabdc418b809e7beae4f684_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:9f2e86b59baf64ec0e15b190676a8a81d8742f4cf88e8c216bafe3fd355a534f_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:2d56340729ea34c80d7cf9342812a20ad2bb371c4ad4de656d55e3004352df1c_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:8a56051d40e5c4c82c188303b7572da6e4bf21ce1f999db97ab878f59431b8f5_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:af78c6089f148a256854511669e111271d80dc0eba571d9f47628429bce66835_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:0312f6391720d2552b067a597c6d30bd47bd72f0e173488b615b3da8e144eb0e_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:a3829f94879b2512ae6d38f617a734e79ef9ab7de6f6c1ae1318346d6144e636_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:dc74190ce1f373590969a90aae941a6af820268aa41548bc06ae9c70da8afef5_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:65a60062866c15fab1eb1af75cc0fdeeec88e7c98c8d9a428a0a8272d6246b1c_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:94d2ae7b3e409451320370ac05ed6a88be8546b2e756a306d904ef22a372c7b9_s390x as a component of RHACS 4.0 for RHEL 8
- +4 more not shown
✅ Remediation
If you are using an earlier version of RHACS 4.0, you are advised to upgrade to patch release 4.0.5. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6071
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/acs/4.0/release_notes/40-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6071.json