RHSA-2023:6836HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.2 security and extras update

Published
November 15, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products184

  • Red Hat OpenShift Container Platform 4.14
  • openshift-tech-preview/metallb-rhel8@sha256:1b2208cc474df254c487bcf0f6855b55d2a954fd60794107aebd625748ed978b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift-tech-preview/metallb-rhel8@sha256:5b00d78c577a9c83945c127005e7d75d8e4e0ff83a2d600f9e4ad8821bd57048_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift-tech-preview/metallb-rhel8@sha256:b5c9f55e0c150ca192cfedbfafc74d7080261c5ea872f5438646e6bef4524afb_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift-tech-preview/metallb-rhel8@sha256:e71bef803bd0f6c70bc364ab12b142d0d49ce235a03191ad90434fadfcec6492_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:06b6f28c571cc2013d62a385ea4abbb6b89467d76a2fb63f1409ba6d9b647156_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:4ef634fb723c082c0dcf6070b203b8e03808c29757ee365e121722454d1d9278_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:7ae73a264e1c8a47fdd7ad502281f3e833f876318d12855123ef2ae57a3b8c74_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:19b1e4e702a64a9ab6b33425526c408f012b81cd74ff8e7ae43ab5bdc97267a8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:4960e43a0f470dd9793b4581dc34306b7c3a8a2f298bf82364a686910733fca7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:c0cd52c58233244545c4552fd6406a95f84aee286bec95b84f4168fca2f8bb6b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:edd19532b211e0c4c2e6aa805d5b1079321f29a56b79bd072e556c55f010f548_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:38d0497c0db4aa16b0ec37d917f1eaf853f5c629345ce6bc2a511e1f651ae209_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:73d54259e874a007246395057778621d72cbc12ea4dac48272877b4eaff33581_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:966695e0ff7b9570f0d53bd8111449648273ff16c633cee62f21053151eba4d1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:a94b16d20ed072b08fe3a64e2a6ac4c29a4976b6267189ff0796bb72ca983e29_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:5ba99a42b8e17b03d13d992d85ba559ddd146974637ccb4b98a6d4dbcf5e43db_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:bedcf83ac78c13444a6d7263626d5e54ce24228f8d80706c61a7e40bd7bb8fb0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:d63e150ca348b86f6dbd20fccc69a22d975d881cfb04a9f1950cb795d4f6fd05_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:e4a5adcbd26c4a013ef48390e4bd404c5844a09d98784fcae1981097589058bb_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:3b848a5f0c2be5e8ca2c0788dd02dab39e3167dac9b6e99b4873711cdab324e7_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:c1261865e7909fb968058ae01058ccf861d42e25a5635f5e72415b6efc189c77_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:e8ed9a99054bff7b1af5556d5cf9b0d37d0b14c3ea113717fb83372303d53701_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:f54f122d66e14d6d15e7a1d50d06693d506fab6cb9869401f42a46e9e1fd510b_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel8-operator@sha256:622c547380395c182a8fda35cda37c77103cbc98a89cda84953168d6b3de7ee5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel8-operator@sha256:963b8267a707efb1fcc5c69ee6ce5d1ed1bff20d421f7fdf9a459568fd72d0f4_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel8-operator@sha256:a0ba015d7c1022ba4950ab49ee3315f8f18f703e7fc55ed5590e282a7b444c0f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel8-operator@sha256:e8cdd92565af5602b592dff3e1d0260bd4775872eee7063aa3b854ab80cfea43_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel8@sha256:1b2208cc474df254c487bcf0f6855b55d2a954fd60794107aebd625748ed978b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel8@sha256:5b00d78c577a9c83945c127005e7d75d8e4e0ff83a2d600f9e4ad8821bd57048_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • +154 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (9)