Red Hat Security Advisory: OpenShift Container Platform 4.13.19 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products169
- Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:1ea923a6908e58ba3ca77c2f08cc7a50df4dce9341055f1aa007b5f33a172f00_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:5ea1a8f197e9c3b8cc11583b49a0c57f5679a57597e689101551d511b1cbd567_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:a1cdafb7a4f5b399ba3a2bbbd97f6ec55fa58d0b0bcff73645a6939710218e79_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:dad9b83e0fb1c1ac802cb2f95932e227467e6cc3c630c569a2f46f2d4c6b8cda_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:4c57f4732767082e523289b14aff8b13565e4af01036e1c50f128064fd84adbf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:6d3659fad8fc7f49e44a5d1577789dfb373670fa2fe8ebadc04870a81a04fe53_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:00d2a90cb8ec02add70b819e4521569b80e8778780887f2063c1fdeff05cb3c7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:0170422d58598b741a42ef990412a5cda856b045176a752b5914fbe025ac17b9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:655785d4b563319c3504bc047607d8e51e18b2f40024082e75b60a5212fa7977_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:6e8cd5cbac26007bf42c86773b841257be5f533aa0eb501fb4eeef45a0f27363_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:23c2ab3fefc76154846642bc7f687e540a82aa9df7725f590cee4a667f999aee_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:2aea4ffb73a90eaecac491d20cb8b047095c8d80a4826faf4e0db8fc56cfad65_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:ef2fb3e4f30fec8c4e4c186cbcbb49ff7b56d4226d58edbdf15e5642bc434c72_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:f5cd1f4cbbaae11b48f040e2435fc01d4a66c17bc185b73eb57f5a0ebfc0dd5c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:2bb2a303e2b8543d45a5f5475826c04ce8a6819de5390bc3f8bcc600c07fc71e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:84938ed1f7e65a6602eeb6635d438c75c6cb190cd4b0d174129243e917275d44_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:aac652852848988e4f6b2a93e4e167ce03262209e30fdfbcd9e615fb60d1b597_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:f7c3afb7f1233ff7732febafac2cba8a2092da4e1cb186f9c0c4225df71a7371_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:0b9c891ea13e156fe5158b9180e2f5579fe8106d5b21cbfa0747587e76ff4d95_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:193af3dfd0ac76f70e4953173eb0d5c509e54d218abae84e9d8d2e3766da239b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:810db57ee8a3abaea97e040d1f8f6638633d80e99e521eb63cadee789b034af8_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:8f6e33f585bb8ae3ca50b0db1c3b9b7a4b37fc761894aec20d9e53f2be2ae77b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:67a802fa4be2a9d8cfd661d36c8e9f88b07a68f318f2c878b741bae30b78241a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:c8a44e11f061e541610603bf51b3930d6611ba366768c1f3d8dfecd237cfc97c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:de57b91ac601a39a99f3f67276f09fc03c19ffb2e8a4c316cd4925628261b566_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:ecfafbad777f3c53ed067e3909b6d543d235d660e228e0f9a59ea9b0e8cd3949_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:1ea923a6908e58ba3ca77c2f08cc7a50df4dce9341055f1aa007b5f33a172f00_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:5ea1a8f197e9c3b8cc11583b49a0c57f5679a57597e689101551d511b1cbd567_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:a1cdafb7a4f5b399ba3a2bbbd97f6ec55fa58d0b0bcff73645a6939710218e79_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +139 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:6129
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6129.json