RHSA-2023:6240HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13 low-latency extras security update

Published
November 1, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products7

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64 as a component of Red Hat OpenShift Container Platform 4.13

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (4)