RHSA-2023:6251HighCVSS 7.5

Red Hat Security Advisory: OpenShift Virtualization 4.11.7 Images security and bug fix update

Published
November 1, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products15

  • CNV 4.11 for RHEL 8
  • container-native-virtualization/checkup-framework@sha256:7a9443d47b8f954670ff3a8f0196f26a3a7bb4b16d2c3469a22d01172f31fc26_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/hostpath-csi-driver-rhel8@sha256:20488cf9f269a34be9a3d82e04a28b598b26be0a495f51a47a8dba02f7e9d974_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/hostpath-csi-driver@sha256:20488cf9f269a34be9a3d82e04a28b598b26be0a495f51a47a8dba02f7e9d974_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-console-plugin@sha256:3ff40d3759ea6c50aeb143a5aff6f798611267452eb8111361ef9e0a89260bf5_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:8c7d9751d790df2471a9e8606afcb2880b800ec713a089b2a801df247a0f3fec_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:f4b0b6daf093a75fcd8d4cc61496a316f86899e8ce4217e9f761def5f9d0e794_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:33a16329639f805c0d75a0ed6fe699755938f602230104715c0ad3b545aaf7fa_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:caed594ab506d7cf550130d927b68bdcfb3707b8464f2d18da468d9b884c3017_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:4980e6eeadf62bedffff98982f0f5b5e426b0ab01867057dba027e87f9557ce4_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:254f671bc0443d32ba60cfafa4ed4592c2030270b160c1e7b1d302d797bd9a82_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:69ceb3d47f3c8c32abcca8ec5ad7ebce42ce64e8200f77c1b829c2cb5495c478_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:ec2ac2bedd9f14ff0fbdfe3844d67f1361d59eb379ef6dfcd0fa5727635bdea4_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:a1fac42b6bf868c20ad974a0409cd62e68be20ea9e4ca5ff4ebc211bb9dc85ab_amd64 as a component of CNV 4.11 for RHEL 8
  • container-native-virtualization/vm-network-latency-checkup@sha256:9d28ad64ab3d2858ce9b1144a77816cc1ae07f53b37599fc24609a9429c0a0b8_amd64 as a component of CNV 4.11 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (8)