RHSA-2023:6275HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.12.42 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products43
- Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:4c7d12333585a5805a7ed93e458c6df43e4858b0502fa7b5351395506dd36a26_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:928b08ba3ae94f271988f0d5eee36d8ebd3d3a3b04b7780e9b0cb3a79c874fcd_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:bd7db0c6b642d2ca0489bc662fb8c90aa49bfad3a4177728a832886a98ff8c24_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift-tech-preview/metallb-rhel8@sha256:e78c66a3d469c99268862c5e5d56dd978c3ec57fe459037be847e2dae5183082_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:419aae6dd41590a224c877509c90215b2ab2bcc1f7e304aaf33a03d55668b1b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:64a15ee61ee026f8d7ed4b202f4eb586b7218acb6b1ed40cd37ed3e40551c145_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:73275a96c62fa1453c8759d9283c3553ea6c0f3b27e63d715eaa29159a7c7a93_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:b9a5d656fcefa3b0079ddefba7aaa9592082a7e7874aca124a659fde62827fe0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:4748df5b5d73aa9ca3f1e9ea760ae695c1c203124588ab08609c080a56042436_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:6f1166fe2ded0a7b51284518b0beeb256df21d814ae490b491904a474e337c75_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:a90b02ce74e0ca4ab76a0ef2ede2528c86d8e0700cb04db7ae4619b5b5fc42cb_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8-operator@sha256:f05d2b346d26f4c8e948f9f0878dd6ace84dfbc38557d154e010f9f37dfd48cf_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8@sha256:4c7d12333585a5805a7ed93e458c6df43e4858b0502fa7b5351395506dd36a26_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8@sha256:928b08ba3ae94f271988f0d5eee36d8ebd3d3a3b04b7780e9b0cb3a79c874fcd_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8@sha256:bd7db0c6b642d2ca0489bc662fb8c90aa49bfad3a4177728a832886a98ff8c24_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/metallb-rhel8@sha256:e78c66a3d469c99268862c5e5d56dd978c3ec57fe459037be847e2dae5183082_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:1906f26262330e6ad23312081522b8b602b23ebe26aad497e49477734e2ae278_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:9e788201d32ca4b5362868ea336c2b744d4050fdb7f0dd6cd8bb00ccb4c018a3_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:9f3f64c41333d09b3ed7afae195bb32b8e62611432ffa069a09de7f22c861058_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:c86f6786ea993a9096cd2f7e1ba1c8adc4833b6cf1d746729abdc99cfb512331_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:4ab97f89ac6136f355034b4c820e54a0452ab07b567f60449f12b152e9bf92a5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:cb9c913c8b6175fbf61bafab38b7ad9291efa33f61c105b4d4185c502adfa146_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:110fe344a463c1e7c0587186c15ae2646c8f782fb530cfbde2149fc7ab323055_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6d90803767d6ff007c9767f9f9135bf5316ec754bd8ce5dc4cc259a6133561d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:abb8de1869be8f874aab3b855d6b71a793ad2b2e7fe80ab1501d6cd184c7142d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:ea0385db9ddada56305621fcf134d05fd92ae5b299c23b0f74076140a64aac12_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-local-storage-diskmaker@sha256:0999637fa57edd55b5af686cbd46d742e46392df43bdd0f9dd4bab4266d2f729_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-local-storage-diskmaker@sha256:488bea7413b719f4b1f07009e3f066327616173a6a8e29657d87cd8e3c42792a_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-local-storage-diskmaker@sha256:d8aa538c60d2bd7ae9cfacf26b3d66bbc5a1ed2beb4d762357a616f3b97e5185_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- +13 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6275
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6275.json