Red Hat Security Advisory: OpenShift Container Platform 4.13.21 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products65
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:3810956951c1988979ac24659c56ba6ec17e09054b6ce85abc4b14e670fc9cf6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:3b3a2a764de073fc154cf4e857a369c91ecfb5e6c42a6f0e099c5c50b332dd27_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:ce7b75eeb28e81e488f12c8836d3e5bd3d9311ff714ee9202d051a473ec0fa9f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:d4dfbb9e94e39d2f9e5542367a04cadce0ca5f7dfd9b15c5f2a97fd30688af2b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-authentication-operator@sha256:0ccc78a5bee86470de92084ef0d667741d4a342f89907083d66f1b8fb7fed3ff_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-authentication-operator@sha256:15edf4f6aeb81ceebe39ea705222b216bded95d01fe8bfce4d91b97b369c4ce5_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-authentication-operator@sha256:75d6d6e228c8db448712c8c4ce7463cd8978de42545a1ae2a3664475375d46ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-authentication-operator@sha256:8a5b24356f618c9c5794cb2881c3805e7cf9bd79f95f9694ac0977505695cef2_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-ingress-operator@sha256:252dc8ba3414ac50ff56b14900808ada31f102afa0ccd684a0066d369bd989e7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-ingress-operator@sha256:33bc668e23d4d3ebb5f9fed08c14663a37a483ddfe5426158ca73e5900623c7d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-ingress-operator@sha256:435ca54c6bada76ec200d0420b62bdd40890fb879c8c99e60a76c5d353cddfc0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-ingress-operator@sha256:997535dfc8ab47df6c357f39b9981c4f4d4538c67af3ac7206d8407105e3b218_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:075a470799eee154d399f32fe6b87c0a574a45ca97075da0356a88bf52695cd5_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:4534b5c675e52f1b2aca7802d00717550521f3ed9b134305c85e8846a7d038ab_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:7d33159b415e073ed2b526510ac416867381a466256c0c9511c00aecf039ec76_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:81a751470151e47c1e3596aa358378fdaa1d1a6859f21bbf7aab85fd822fb889_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:0905ecceec6ddbf5943fec3dc8857833fb7e2b54abc019a8304a8ef8925f61ce_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:3dc231bf8ffeecbfea375ac3fed0eb2892b4cafe670e9b86b3af393154213b46_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:9aa3df1ff21ded9e06d3c1c71450e046ea40a32b4289b8bf33b448543606ef83_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:cd6c6c190e7a6ef119ba79c515471e3fe76dc5cceece7310dc6a16d9e11702e3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:af96509b3a7f7337c3dfd538d0e641751c9df4082b8c0cf49952d320f94611c7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:b88672bc0fbdbfc98eb2416ec096cfed3efd9e255ffa96570cf600d09a69b0d9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d303a79d60b0b9a87c7e7f2a816c1551b50a932c7b12e457e609c8b1106935dd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:df712d87dbe3c49b18a605b01336697d816168127353252568e33023ce1e66e9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-samples-operator@sha256:5a080507be49f8c9813787b678a6162281ae79961d2030b5736f472902f5bdfe_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-samples-operator@sha256:84dd81dd91328854d02a2a2f445079a05df2cb57725134586f9c8d4da97bde70_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-samples-operator@sha256:bad3770097f6a0c9654d8f9638d7d204e0ddfe860b16f7edbfc790ac8aa905a3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-samples-operator@sha256:de34b48dcb344803b70341a10bae3d42183d671b9cd5a7f5d4f50df68a7af639_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console-operator@sha256:6eaad54d3c0ce20aa9e614fb6c9cdbe85bb670fe7fbf1cb4746853d8a732108b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +35 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:562c214e9662e3684ac5b8c3d5d2759a83f544da8897a00ebe91a02fcad6d2d9 (For s390x architecture) The image digest is sha256:31eb6fe82af60cf8693bf986d6db6d26cbb26950eb63401b2e6c2c19eb54c2b6 (For ppc64le architecture) The image digest is sha256:0cc5f401894fafcf40653ff631edce27297f598546235e6107e100f9b4798f3a (For aarch64 architecture) The image digest is sha256:f0c0bad639693279314010424aba2abb76ba5f8f45ff1b40d4f8936c589e2e0e All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:6257
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-11604
- externalhttps://issues.redhat.com/browse/OCPBUGS-11926
- externalhttps://issues.redhat.com/browse/OCPBUGS-13330
- externalhttps://issues.redhat.com/browse/OCPBUGS-14344
- externalhttps://issues.redhat.com/browse/OCPBUGS-18284
- externalhttps://issues.redhat.com/browse/OCPBUGS-18468
- externalhttps://issues.redhat.com/browse/OCPBUGS-18698
- externalhttps://issues.redhat.com/browse/OCPBUGS-22299
- externalhttps://issues.redhat.com/browse/OCPBUGS-22333
- externalhttps://issues.redhat.com/browse/OCPBUGS-22390
- externalhttps://issues.redhat.com/browse/OCPBUGS-22402
- externalhttps://issues.redhat.com/browse/OCPBUGS-22412
- externalhttps://issues.redhat.com/browse/OCPBUGS-2812
- externalhttps://issues.redhat.com/browse/OCPBUGS-7652
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6257.json