RHSA-2023:6121HighCVSS 7.5
Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.8.1 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products12
- 8Base-RHMTC-1.8
- rhmtc/openshift-migration-controller-rhel8@sha256:6150f27bf1aeaf433d7e86f0c05f2c46e817a9258b80bb4dfe01bde5b334c403_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-hook-runner-rhel8@sha256:2a02b8eabd742ab9a5ec4977d3c3c64a83d57e92480da30d96359ad179f28a87_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-log-reader-rhel8@sha256:806d60311942650a89bb33e231084d9c0216a4bc9dfbb25f7b6c2729b3b59325_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-must-gather-rhel8@sha256:fa97c0ec47a3035972ca404268f74e4e649c632d3ba2c76aaca25c7a0261e3df_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-openvpn-rhel8@sha256:59095f4c3d4aa375b561f3101e1893a633e88193d824a353434e211d180875c0_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-operator-bundle@sha256:fb9482b83a1f76ba1310f662466913f4a493d01ff69a4b3466a8aaa8ba2897bb_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-registry-rhel8@sha256:a8c3bbb11b3d639c22853e63424d3eb65eefea87580631c99518ebeabe30ba00_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-rhel8-operator@sha256:946e92fe2bdc50791dd8ebc6c1d00b5d65147d8e0f67e92df169edfadc999be8_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:18f5774d6eb800a3fb9df52ca273609945f535985bede38a9d9e785d6349008f_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-ui-rhel8@sha256:902bb9b2efd6b7b529b36b197d7ac9f3f6a8b3b71503d66861411b77649c5cf3_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:a24897ee613d9578f4972b9c3f686299001653d76d3dac3ef22e534a4cff4e78_amd64 as a component of 8Base-RHMTC-1.8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6121
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6121.json