RHSA-2023:6256HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.21 security and extras update

Published
November 8, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products27

  • Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:05081f1f284ceb4b26f9e4874d8a6d76cd8cca5acf28ab7e067ffa6a4a483224_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:07f3e521eb6cc30b852a4cc8b5fbb2899a9a52bb84d247ade26f6b0cc838dfe9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:5420cd1f7d913cbc5041e96ffe4b1bc221efceb1af46db36ddd5e5c1871b8ea5_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:892336754509e4cbfa9b0c59bbfb36e5d951d27151a964abc3ec48c8d9fbcd80_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:24c1848eb66e1045c93dd01a2e9782e0d4dbaf7e9043c86e0f9610c498c9bb9a_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:2967a22f31c6bf713683085d95c4993d178f7263eb135db13b370544b1f041ed_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:ce4a5d7f767411f3eab5514e76f6602a7a0041bfa51b57e55e45f835fb56aaaf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:f02a03ca21a69f74413da5c7a72a6aa35502b1fbd3666eb27594c622a031773d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:05081f1f284ceb4b26f9e4874d8a6d76cd8cca5acf28ab7e067ffa6a4a483224_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:07f3e521eb6cc30b852a4cc8b5fbb2899a9a52bb84d247ade26f6b0cc838dfe9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:5420cd1f7d913cbc5041e96ffe4b1bc221efceb1af46db36ddd5e5c1871b8ea5_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:892336754509e4cbfa9b0c59bbfb36e5d951d27151a964abc3ec48c8d9fbcd80_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:0c5c3d96fb009e37b33807ccd70424e6963c14fafcccd1ce393d01d43557c4f7_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:43bcc7a641e5bc43f0f45a53878404f27f4c5a1c5626f7659476ae11c95025c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:54ba9cb5e248aa86afb3b1cc234a9d08f4b3e0f4b8952a7fd73669b53afbac02_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:ed8bd7a2df389dcf280c603b17d84d6dd6f1317cf8c25e3ff3669931dad446d6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:107a05cd3e21954f0bd89faab4763498ddd32b1d6a64aa4210ced437a61f600b_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:280a1d664e1e0069baa255a7333334103619a7027e75a70e4d901f53613f9e71_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:acaa5f1c59cf5781a5345847e9678a3ae0adeef4bded5c5957c83c869a60afe0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:cee05a72f77765261166bfffb2d6acbd19a28c6eb3fed55bba38919544ec1f5d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-dp-admission-controller@sha256:083fe6661c61e898a677d105a2d2281ba48fcc3adf14d4586f06bb2bb8e6fd1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-dp-admission-controller@sha256:27d5453c102aeb8bc09235a2bfb1f48d46668c2d76fc939998f68803eca97913_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-dp-admission-controller@sha256:52c1ade7bfb4ddc6fd1a0f7e33b6135313b4ceaae660e895b99c6e98082114ae_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-operator@sha256:1a5e2c023729824e5e4305ec74982370a20e6b475cf9946f4e026f73e6319cb7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-operator@sha256:2a44887cb1f28a928e47ec52188ab35ac3facf1fdbb519fdfbc7c73d2e411afe_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-operator@sha256:799958317ee505b1ea8bb6ba274745054815da8ae51c6709a20e6da821336b1b_arm64 as a component of Red Hat OpenShift Container Platform 4.13

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)