RHSA-2023:6121HighCVSS 7.5

Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.8.1 security and bug fix update

Published
October 25, 2023
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products12

  • 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-controller-rhel8@sha256:6150f27bf1aeaf433d7e86f0c05f2c46e817a9258b80bb4dfe01bde5b334c403_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-hook-runner-rhel8@sha256:2a02b8eabd742ab9a5ec4977d3c3c64a83d57e92480da30d96359ad179f28a87_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-log-reader-rhel8@sha256:806d60311942650a89bb33e231084d9c0216a4bc9dfbb25f7b6c2729b3b59325_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-must-gather-rhel8@sha256:fa97c0ec47a3035972ca404268f74e4e649c632d3ba2c76aaca25c7a0261e3df_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-openvpn-rhel8@sha256:59095f4c3d4aa375b561f3101e1893a633e88193d824a353434e211d180875c0_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-operator-bundle@sha256:fb9482b83a1f76ba1310f662466913f4a493d01ff69a4b3466a8aaa8ba2897bb_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-registry-rhel8@sha256:a8c3bbb11b3d639c22853e63424d3eb65eefea87580631c99518ebeabe30ba00_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-rhel8-operator@sha256:946e92fe2bdc50791dd8ebc6c1d00b5d65147d8e0f67e92df169edfadc999be8_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:18f5774d6eb800a3fb9df52ca273609945f535985bede38a9d9e785d6349008f_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-ui-rhel8@sha256:902bb9b2efd6b7b529b36b197d7ac9f3f6a8b3b71503d66861411b77649c5cf3_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:a24897ee613d9578f4972b9c3f686299001653d76d3dac3ef22e534a4cff4e78_amd64 as a component of 8Base-RHMTC-1.8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)