RHSA-2023:6272HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.11.53 bug fix and security update

Published
November 8, 2023
Last Modified
September 16, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.11
  • openshift4/cloud-network-config-controller-rhel8@sha256:6c21303c0bab51cc5e19cfaba71987d1eb791dea378519d1b9eaa8b4860d8262_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/cloud-network-config-controller-rhel8@sha256:7426899efa4b4d01e043b69465633739099dceaec4abd208c76057caddef7815_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/cloud-network-config-controller-rhel8@sha256:95cf7456d548f8a2373a0fa458b493ee59c3263d8e928e885a1e0461f26b1429_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/cloud-network-config-controller-rhel8@sha256:ef4af9682f3bdbfd2adb76ee3b89c51bf9edbda5be47f00c8bc4f319637a4ef2_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/driver-toolkit-rhel8@sha256:7c8420b00c90ef520329590479845e2d85f5495fd498f2fc1961b1da616a7bbc_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/driver-toolkit-rhel8@sha256:953076cf56eaf0b6989cd37599c60ed166b61e46d776dde4ce620ebf2b1c1e68_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/driver-toolkit-rhel8@sha256:c198039813bf19c4e9e466115e4a5ba0e348f53a454c058d96acdbb6e10665e8_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/driver-toolkit-rhel8@sha256:eb158f2f9439aac6c216b8ddcba388f9bcf39f36295393dcc5afa20ac91db7d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/egress-router-cni-rhel8@sha256:bf5c2e057064fad9f11a4e4f59da182576dca5adbec274898bd0e9f1ab0b2d12_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/egress-router-cni-rhel8@sha256:c1077bbce8ba2b5285129978038e100ed7102609e8da9e28f6252a2b76d6c210_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/egress-router-cni-rhel8@sha256:d64fa7e4517b09a65c7f90cb7fae71adedf6d02e40a9812f2d8d884702890ff6_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/egress-router-cni-rhel8@sha256:f0aa07446110940ad7c43955c294627ab6c77f9b0b453027c562318604c9c1f2_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/network-tools-rhel8@sha256:1df693b76e72036c08708ec6deb9d305dc8ef78324908926bdab6af5390e4be0_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/network-tools-rhel8@sha256:2f2fdc6bd3a9b05854b86f62365b348f419e946ee4eef1741ac4ffac6a2baafb_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/network-tools-rhel8@sha256:96738031e629888b9dec64fe8c9e86cde378655769ff8c795d8ffb4c11838ced_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/network-tools-rhel8@sha256:e3a1e4189ee7d9c49ed273bf078a16d279544d4548896c8e9c0b9e0753c178fa_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/oc-mirror-plugin-rhel8@sha256:9cbb92e3fbd1ae3f710bb308db10015047861bc21d6513698a4211cdbbb037b9_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:2b257b13a862b079351f0ad6aa1efa0cacf563d33c818c9da6d7e311e4cc41ad_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:4e4125ee395df9da1bd797f86aef91d52fb5b2292c6d9fac9da496ff375cf967_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:87772908cc5f7aad001a52a85d074df650d8d650249d5e64e2d2730492991fed_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:e65b37ee8dd7ecfff976b1dfd3b9c717d2fb973816a5c22c615d2e4ee6b3f6d7_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:002c0fa1c8a271467359b1637dd75737f68e9da0d3aa6d2f317840d4d6084a9d_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:64d0b91e27e269cd2d8bfd09712882bcdee4efc3ca4ec7052777ff7b904b0ab5_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:6be395179eeb6ec093bfad88420f4394a11215fa71d0283e8469c1d1a6c4c376_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:fa35472c6f79fd6abed2b427d1957302df0d2253626654c92fa0bfb58a928b7b_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:0fca59b8bfae3e09ca1403da7df2a39be838680046263b6c2054ca13273a2949_s390x as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:187cde4bf99e8f6556fb908de54e5a46dd0f8ce71d7c49f60df103da284eabaf_arm64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:4d1b32d4e9b3a2e99a9d08291fd4d83100f20d341f19f3b31a3fed1b0410729d_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:62b9e098bf912ad4cda376c548912bb49f13813cae4d505685bc308fb316998b_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:ce532664d72d7b768ad61a83500e239f67a5d2aa2b62cb6a7caf90a8d3ed6e2e (For s390x architecture) The image digest is sha256:a29b24a3c6be5f1e8961a3513b574e55fc23fb99adecd593082b6f800003ab22 (For ppc64le architecture) The image digest is sha256:748034f95f84dae39e5e80133e6c5ead289334881cb31185d69f52d50e2d7d43 (For aarch64 architecture) The image digest is sha256:8ebaf48213777bedf8e7628027058349a8021217687ca0b6df6f990679434e68 All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (11)