RHSA-2023:6116HighCVSS 7.5
Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.0.14 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products13
- 8Base-OADP-1.0
- oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:81866c1022c5753966563d3e7e8f6c52659ec4f44ff16e80abf90b1c205214c6_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-mustgather-rhel8@sha256:47f797fdaa8dd123395d2c24baec6879528b87ed3a4b38ba75529eda9489681e_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-operator-bundle@sha256:d04648c75a3943c17d58e731a1bd9c5b087844933dd541a6f3021090efbd2a8b_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-registry-rhel8@sha256:2f2a0045c09b57f829d329f2bdca336b1b36149376199f0317372c02e008106e_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-rhel8-operator@sha256:2d0182cb70a26416314e18b9df96b2a1153e0321f9918f04b45706ec81f3186b_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-plugin-for-aws-rhel8@sha256:c9bbbcfd7aa37f989db4d82007e1e4934ec0d44a507e527a6a36df2cc4959a5a_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-plugin-for-csi-rhel8@sha256:36a97115bf48ea9fc1a3e9f7a5624d743f1b2e94ad52a6f05da27ebf26e1673b_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:43c40dee88e38834b1291ef66ad23c63c11fdc192bf288a4691ae15eddddb85a_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:6d28dd5fbe010143914176e121fc1c6ed935005bc54ef7d8d5fb65e26f72538c_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-plugin-rhel8@sha256:945e16d6a8ab0031dd9fd823524fc5036f05a534008027806a0627adcdc6ba28_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-restic-restore-helper-rhel8@sha256:29db02fcb1fa8339e3fb999d60009e5b78d969fe35609d9702bc20b9dca8c5ea_amd64 as a component of 8Base-OADP-1.0
- oadp/oadp-velero-rhel8@sha256:8a7040f970b9d4f69658af2ca419d8d329792e5ae61ad8950706a1a41a98aee0_amd64 as a component of 8Base-OADP-1.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6116
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6116.json