RHSA-2023:6828HighCVSS 7.5
Red Hat Security Advisory: ACS 4.1 enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products34
- RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:225ef8caeff7d8e40d4ef1cec150a347091249c6116199a8b8cbbb2b657d40fb_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:2eb39cd2031da836b306c5f1abd54e5ef05373f36829e9cd3b24f2f2955a8135_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:7d1ba993b9e53c5826f7b41541bc057048ebab7f4f29a61a569d5c954c69d061_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:5aa8bd48817d3d52fe6d4d79cefa3c4b2a89716fcd96bac3a2c6dc11f663e470_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:64b1287daff111b974cce3df8134cb09d5a4974a37412564dc02bf93df35a4c6_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:c40c2b4aaa6e4d06e96772cf76ff1366284833e36a0872df636f549b58085f0d_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:4b28c3fd75efed62f043c52a13f766c752799bf05500260ea46ba75b5d48bf7e_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:e36c72f1a70adc1e68c822304598992f902de116b44b1b08b50df4c9a46827fe_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:f92dbf47b14e40ed15e8b1f9abae795e53682fbe7746a3f6cfd2f8c65fa8ac3c_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:165f94df366216d0684b323c872d968faa3fbb45723ddb6e35fb1e191000aa0e_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:9d3e2bb44a4f866bd04efb8223d68f21b04855239d95d81b530f61c9f5e42bd1_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:d273c4b9f0d02c2179ffbbf55e6fc260e797d1f4356dba2c536a77ed8c0b33dd_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:13565496a1f4cb80746d542fc13c9f024b811dfb7df84d2013bc79b5809622bc_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:51dc4946a777b0da34789ee31bfa64f09e2065a2b584a48539336603ae01004a_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:aafaa944201871ec15cead3aa77bbdd1da76f972f3a241b894e2254a6ec09595_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:186eaa4cf4b8896cfe4141925f26f406cc0156c676b159745d0205f4ed857951_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:5adc8bbbfe0514d877f1c4ec9bb30dbf039634c9adba729623e7a4f6843a31fb_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:b291129b5dfd95d707e4cf1007928c406de1f39020eef4e54d63b0ada33c6107_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4eb0d285b528002f312db407dabec4dca4757d3759ac3a01ba422e607ddbc4d7_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:862ad7f71a230c22e97f618c930ce3f8cd080c75a9ebf00f8b7644f1564861a7_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:cebe3e3c935995b9352b7e1b17f469f57917db4576d44d11d0ff4c37fe21948d_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:53e85c3769970a2bba52913b2c1ed8e784daf84b42de6317dd66cfe76d1591d1_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:e08adbe1d71a9907658598547514c5b9c649f766faf14f6d912bfb0d97e6d434_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:ed4a04c43fd03091f78f24df01631b5fb1e8ca79a51d075081d6c49038f14f82_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:36dbe96cd603b2da2f3a7fec55ea5132d704395d9ec01806306307f756bd1a13_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:edea8cd403c2fa9cd28706e806a5f6d9b78e8cdfa1c131eda6c2c4254d40c13e_amd64 as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:ffde60ef6348be1e34a9eee0f2b56583fb80ee54c3d19c20de6748daa8d701b1_ppc64le as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:5ca23d8f43543d454e24ec10aeb2f00847b4a4e9eb3fe3495a77e11222c21969_s390x as a component of RHACS 4.1 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:5d6f36aaca6e9f98500fcadda71eb617c852bf0d4f0b6a71b66a343b3ec41985_amd64 as a component of RHACS 4.1 for RHEL 8
- +4 more not shown
✅ Remediation
If you are using an earlier version of RHACS 4.1, you are advised to upgrade to patch release 4.1.5. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:6828
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://docs.openshift.com/acs/4.1/release_notes/41-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6828.json