RHSA-2023:6125HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.12.41 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products174
- Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:30e659a24b8800ead24e646e0d179681db3bf0d3545c28cf391eac3dc74e2a7a_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:61a30124629338f6b5a73f6050c52d3e45d3f6e7c09457f65cd61c792f091d57_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:afbe06b979482282901bbb971c068bbb2edb39a9a2d2ec65e69178ed15740395_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:d527865183458b07126402186693d4bf950712a71a587baa09e8669cb075e774_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:07a2c3bc42fd4d28445d755edf0489277c25b7b1f5475423012db2fc3087cb49_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:907898f366a60aeedbb9013f877f6ade1da6463f878ca578d0c979e5e22430f7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-event-proxy-rhel8@sha256:c29ea460add0eb57d8a060f5a1c5b69ba08bada849e5aab554d7d308a9958d85_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpu-network-rhel8-operator@sha256:174bdd37e95c9c63d74d3f98b87a3e4dd393ca7a3aff55305b91e31fb54ef9cd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpu-network-rhel8-operator@sha256:f4839ae599f27b4920d9657ac0d4f7ff51550b00910cd129b44b4774c88bd445_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:11aeec86595abdb7878b29db37a5318b956101000f250cf1ad1c92e4cc0e879c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:6374cd34eaf01275f2eaf613dfef7528ec8590e3477b022aa588cb63f1db67aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:823f4d20e9f7ca37c51f4cd3fffde94dd9c351fa99ec1a67d6631918ae4dc2ce_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/frr-rhel8@sha256:dfe645c533b603005e963a27a1d0a40b666933007d8a941c251dbc30f58c55a4_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:30964e3468932b8f00816bd6cc4857665c6eb085baec707b963200ae70481fa3_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:41b79591ca965846419b58fa51dc97a999e6ee0d8086381433a7210bd03c6aba_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:bc51ba238a92fe5db451a8fd659d95a10fe3c79124098bcc7d48778e498a32d0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall-rhel8-operator@sha256:feca1ab5b38b914ac06a8fbed7ed7bcc6e741ad52d326e446071f11f3c400d9d_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:4196612f6e1db610b077b23a8e4f3d9eec44844c03ca56be57bc86950027e617_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:a1513e65fa59fe70550d2438ca42c2e806d6b3c926d0964c02db3691589f723f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:b9293fe3a30bd4356c45221a09fb6c0d88a5750307ac48cc5c0df8299c30518d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ingress-node-firewall@sha256:ec1ecd3e48b8c4bcdd675cbed76fe660f13a84dac48dff2cc61e161e9173b3ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:17eff1eb18470c31b6a6dab2834b3ff4e46d4a706543977c2e48246f43615da9_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:4f79fb3b47589b492f7ade0bdea11e8a8431c27f0bf0c308466e504868d26219_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:a8cc514d8e39ce91a4a36e16c6aa391700d5e5daf519fe1823982b6a34c5bb1d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:d6e19c680e382cf2eb4a5d0815ee41111f89953f095adef2021f57765a4f7136_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:02137073850b288c0b74342956cbac945a4afc543ee5934d042dbea811aec047_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:032a6b888e2ab7d9c1d19e689f9b8684ffe8b4978a61d00396e6875351d16dbe_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:540a05506a365dd3e7abfbad3e1040411dd20eef6503ca669caa9b43af6cc516_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:e5e48c48c77e13aa3cc202f3eb991cca16a0ffb24efdf1c060092774eed1f731_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- +144 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6125
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6125.json