RHSA-2023:6271HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.11.53 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products170
- Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:0146993ccb41788c49dea0db9bab552313c0a7f898a9af9494fb3653c65b72fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:5649a3b58c29d27ec34c8cefa9e4f35baf9914ebcd0e4f9f770ce8e497481052_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:615993032c0e182402fea048684bfe2b8608274b56a55b75f8b2de46dc213c0a_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:85500fe6df56bdf5ac60796b2610daae1e97da10e20acbae55a6e64745ba7357_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-event-proxy-rhel8@sha256:47f72ce252ba43ba3f54cb45fab02b41485f968e2c6a03d9ddb772bd0e113a7e_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-event-proxy-rhel8@sha256:981f89ea2ed702cca392b6a980cda7438c381be194d75ef4ab4292609a555e51_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-event-proxy-rhel8@sha256:9cb3510350f1eff7a5268dfe80ecf1fa3155002401c76a4e1d159bd4a5274db1_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/dpu-network-rhel8-operator@sha256:8702a549146deb4d7ca9a567d045d15e4caba89e2ad586df0e408e2315df073a_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/dpu-network-rhel8-operator@sha256:f07c3f9ab2e701b53fca9d49666f45296c8ecd69d5fbcad22b8b5408764f7fc4_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:23665e663f1a4b16999d72a0514766689817f326e4be7d07efef099c39292636_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:30fc720332aacff5dd4e7ed974798dcad8634e7c0b60c9984374ff9d703558d5_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:8e397b987c66b9cce3d2fd03f6dade5729a2e1a11125e8ace87b4ea898ec76ea_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:999884b84ae38f50f65257fee02ab86a8560878a7f71fee681425c634ec3c6aa_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:a7df380183677f8dab1fbd9412668e99be838d01cdc2af51e226ee0eb4a47e0a_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:b9f6c7bb0f5d04f18fbbf9a747d7bca7556a38416397d8e2f044b2daa47a358b_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:ba0b67c647c7f59a45096e1740d3971f4e9888472e8a7fa16f784f487e97a9d7_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:f21534a9286ef5f45a52ee7d45f6ab70c342a851dc2afdba608a204ebb630236_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8-operator@sha256:109569cd033f4ff5871db3b070a7cfbc9510415585bb4e5bfdcdad1c81e5bd68_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8-operator@sha256:91628cc7090541be7f5ffe46a536491f0f57126b56908b4287cbbe5549c3fb74_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8-operator@sha256:a4b3057d3efd66cfaa679722beecbb35bf600cf818849a80d856b6fba395829d_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8-operator@sha256:fd480555c2f869f569e50ac262e26193e742c9bc2e60ea86b580fc0b05465a42_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8@sha256:0146993ccb41788c49dea0db9bab552313c0a7f898a9af9494fb3653c65b72fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8@sha256:5649a3b58c29d27ec34c8cefa9e4f35baf9914ebcd0e4f9f770ce8e497481052_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8@sha256:615993032c0e182402fea048684bfe2b8608274b56a55b75f8b2de46dc213c0a_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/metallb-rhel8@sha256:85500fe6df56bdf5ac60796b2610daae1e97da10e20acbae55a6e64745ba7357_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-ansible-operator@sha256:229e0e90b02da9bd09e51e1cffc14084985a80cfd7b28b2e8fb4f19efcbe5555_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-ansible-operator@sha256:75a6870e10cfc43ed0a7b87900db1bca11c5c0e8e690091b3a9e59930041d1f8_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-ansible-operator@sha256:96d89e4694ae915e676c03d2aaaa4f54be2dcb788a5bed1fd39e5df5771a748d_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/ose-ansible-operator@sha256:bcc31c606b80e1d371ed2a7077c2458584c5b7b114841b525df33544ad228a12_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- +140 more not shown
✅ Remediation
For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:6271
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://access.redhat.com/articles/11258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6271.json