RHSA-2023:6280HighCVSS 7.5

Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update

Published
November 2, 2023
Last Modified
September 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products7

  • MTA 6.2 for RHEL 8
  • mta/mta-hub-rhel9@sha256:ab08ff12c34082722cb6ea3bdf3c62f99d30efb469570938400ebdd9b6e4b4b5_amd64 as a component of MTA 6.2 for RHEL 8
  • mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64 as a component of MTA 6.2 for RHEL 8
  • mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64 as a component of MTA 6.2 for RHEL 8
  • mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64 as a component of MTA 6.2 for RHEL 8
  • mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64 as a component of MTA 6.2 for RHEL 8
  • mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64 as a component of MTA 6.2 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (7)