RHSA-2023:6235HighCVSS 7.5

Red Hat Security Advisory: OpenShift Virtualization 4.13.5 Images security update

Published
November 1, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products93

  • CNV 4.13 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:043c933ecc64a18f18a23862b959e60988d7223f1899d8a77c06e75352ce5a00_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:dde9d6d3bd598203276151ca6f09a8d94bc8d68160b8eeb057d528612ee387de_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:0723b4c1c3737c07567392abde70c8d0ff41edc628859ab78b4f1db36ce9e908_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:79ffb1e1fd3eb66bd8501f73376cd86e031962151fb33b1f5c99b1768558a5bf_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:0259bad586a2641e8f805cb3b011fd13ac2877afa1086be3d5f58eec5b074de0_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:fae3d9f5dfd142a132fd94f80e8814207aa497459d8942037c383202852ceddd_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:1aea0afaa1678d22f8c60ffaec52a2f126dfacd1d45a1698fb22239926dc43d9_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:bc0ed2d18c556df388a3a650d365e68f24074219683a81c12b1897c1e8a756ef_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:5c7cf709c5af87312dffbd3ad438fec546002515df7fb27e5628e387c4062da5_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:7314d53f44b9058a2a41620ea57c8eafef5161218d412b8ad7353fb570b5ae64_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:30d2d9e998ec622648c848106328ea3a45dc17d51b058f3e222f5199232a1acc_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:8a46da3aa2086587a1d0ff59b62724feac8f1923bede587c5d53ae60ca4256ad_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:280ed417e25231cefbea15d35a456e540329542d59dee59ad1824228bd35e089_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:f6ba777473561391d2b0a098ae16cef0552ee7722f9a6fd527b9b06aa3677474_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:45a08c2561bc304bf62cee9043961c578e4e3c495bec3ad2a57f9e1ac2a62316_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:c3059286198d3a75dd0cab0a8c751f4dde5b0f5e52cc38fe5b258e9324477c62_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:80f623b7d005f2ed6ccf81af9b032a13fee86c7f4a4f564e932073bca0436bfe_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:ebcd9f0843d8d759b3e358120c4aec90a7238046d7db0c3b6014152182b14eb5_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:2832fbf13013467ea73c63e5e6ad7ffe94dbbeb052ec8727f6935d41b2c4d25c_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:a549dfc115062d3f9924c4d8527d80de1281d50179d157e6b42699a0535e8449_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:155d511f94a84c412a78f8b7a90f677146996bc5b3c00a0bff12b3567c63302a_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:4d91d2b48e984b99f03ad19a25cb9b1c4eb12670fda6848a303009de65e4932e_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:4b2ed5bc8f226433a3c6e2dd926a74085b4ed60ed4f0bd505a8613e4d3c5f3ba_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:eac30877a8cbe57c844e660516f0370fa4a2070c6ee805a338bde149be05a16e_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:dbb6f6340fd4febbb2a0b9c0493af1b02681e835a8b07ddc421b1956f3cbccab_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:f824525b97a1724c9eb4e0786a19e0dc16609b14915faf31229abc4345fd91f1_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:74975f1f030959c5ad9067c709b848029d08b74a17297da8666638fc8377f4f5_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:d949f12237050460cbf61cf21cc6627c0124525088af419e718dcbaae5ab3b8c_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:21176845533bfa0817ea0f29c749be2d6bb00539354bcfa3c013f70460d0a03d_arm64 as a component of CNV 4.13 for RHEL 9
  • +63 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (9)