RHSA-2023:6233HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Enterprise security update

Published
November 1, 2023
Last Modified
September 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products7

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/cnf-tests-rhel8@sha256:29579a785974ff1130882f04495f90ba8423ea0fb17bf445b82dd919b19c515d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpdk-base-rhel8@sha256:3faf3d37e7fb8125bf5c49a93cac0e69dd2dbcafcfa27939e706f1d969caa8e7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:245a7c990bcb554ded0f4832957db51d0439311bd85b5c89943e33001e29a2fe_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/numaresources-operator-bundle@sha256:d058f59dbc21e6b015de06bad2d42e2cec078cbbc80a76fe2f914d641caaef7b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/numaresources-rhel8-operator@sha256:9ae57e31edf4e0a10768d52c7a0cce4f38ce16a0e75785e356ae0c00b73b200c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/performance-addon-operator-must-gather-rhel8@sha256:76501b6f85aac090077094f0d4a2da4475b788b1fb7698b6ec33f17e1b2eb898_amd64 as a component of Red Hat OpenShift Container Platform 4.12

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (6)