RHSA-2023:6116HighCVSS 7.5

Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.0.14 security and bug fix update

Published
October 25, 2023
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products13

  • 8Base-OADP-1.0
  • oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:81866c1022c5753966563d3e7e8f6c52659ec4f44ff16e80abf90b1c205214c6_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-mustgather-rhel8@sha256:47f797fdaa8dd123395d2c24baec6879528b87ed3a4b38ba75529eda9489681e_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-operator-bundle@sha256:d04648c75a3943c17d58e731a1bd9c5b087844933dd541a6f3021090efbd2a8b_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-registry-rhel8@sha256:2f2a0045c09b57f829d329f2bdca336b1b36149376199f0317372c02e008106e_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-rhel8-operator@sha256:2d0182cb70a26416314e18b9df96b2a1153e0321f9918f04b45706ec81f3186b_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-plugin-for-aws-rhel8@sha256:c9bbbcfd7aa37f989db4d82007e1e4934ec0d44a507e527a6a36df2cc4959a5a_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-plugin-for-csi-rhel8@sha256:36a97115bf48ea9fc1a3e9f7a5624d743f1b2e94ad52a6f05da27ebf26e1673b_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:43c40dee88e38834b1291ef66ad23c63c11fdc192bf288a4691ae15eddddb85a_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:6d28dd5fbe010143914176e121fc1c6ed935005bc54ef7d8d5fb65e26f72538c_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-plugin-rhel8@sha256:945e16d6a8ab0031dd9fd823524fc5036f05a534008027806a0627adcdc6ba28_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-restic-restore-helper-rhel8@sha256:29db02fcb1fa8339e3fb999d60009e5b78d969fe35609d9702bc20b9dca8c5ea_amd64 as a component of 8Base-OADP-1.0
  • oadp/oadp-velero-rhel8@sha256:8a7040f970b9d4f69658af2ca419d8d329792e5ae61ad8950706a1a41a98aee0_amd64 as a component of 8Base-OADP-1.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)