RHSA-2023:6837HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.2 bug fix and security update

Published
November 15, 2023
Last Modified
August 24, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:08a0823815c9c0918443585f70f415c466e809bc0ecbe368a7330e038a729032_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:539285dbea7b601e1be4f5531f4e9eb140945d4fd1f70f0350580b4f414c254c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:96ef562ba7f6216d8371d1fdf83fa7ebadf4d71bf2d4ec3fd3693a7c84f1b535_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:a31fbf509239ec5568b2abed523630ceef1adbe73264aa609c65835891830703_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:304c2ae4505587f5a4bf4358625c34f1908edd7041825a3238d9b4a275b9055b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:7e4c3fd0423e8c8e97420ac0bae4a771c7f7070fcf32367d27238150e0e9e6c3_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:b6aee74e78a3f795103b2bf5db887e172e0c9621886147b31a57b3eb9c0d27f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:e5636eac6e6fd0859348f65d426bab72b98f7c4a081ed5efdae166837299e1d3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:32783188764e70d52814676eee49081f8532d1a3e4a18ce4086520f658bbc6d7_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:408e90fcf445b454be47150164a70291685bd1714b9419c47d2a9af93b5ba13c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:7c00cfc2efb69c54009b7d81e104ff7eca34e4ee29717c310dad20d6ece64bd1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:9249417e4903e5675b461ae62a8196f30de98fce309d7913f54b3361443b561f_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:3a610bb24c321d85193ef685469dd3c4775eac2706238191d423d7aa7e0482eb_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:8ac51e2da226aae465a85e1412a31784a9c37746a99c09ed2aa7ae248b455c13_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:eee515d9ab53aaf552fc1c58b01c7380842d31280e94001d30d6af5016de2dda_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:f0b1a53fc0ff4f8ce1df3de145cb99d86b45319956faaa278fd22ccb04def91b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:6d341f6db73574674fd169151c6f477b7e0c48bd3ab98d5ddac4ee4e08dc66a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:79964d3ba7032b35274eca07195b49c155730e6e590793433b3b2eb040c78006_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:debe75005d51d1c53fff23ccdb782089b93ec700b291f994f1100c4ee64b1de4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:ff966c6c5d54ed45564a36e13d3f75548c89575ece5bc9a6d8226d7c01933716_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:2c92b9af4618d77ad5fa2765d0067ea1fb8178db227d588b412908843a257fdc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:4a8d44503de543516043a6a1fd03fe583cd647dec5cac74c6db5cd979a003a71_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:bb4fd225f4ff65391b4e68ebddf1099900a0f0bbab44bc96c5eb505942aab80d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:e18288ecbc016b0945e12ff3b5b0488ca3af1af1db0c2b0c8f5c5fc15449d334_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:12fe69f184e4f6fa1df681137698459fbdb1110ae24f021f6a24f131f1f41355_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:2d16043315d333d0fb07013a725e119d89028aa4a366326ceae92b56b644b699_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:7251ed222e73f80e271b09d01acdb93695893b6319335942e50611f734e385ae_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:a66a7ff72db57bf541a891826608d560e17d4065e99e98a6edc431bc2b081ba1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:1fa39a0d145051a36ebca280fe08387145e20cda9d0433372a2f1fa64ffa8cc9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:45a396b169974dcbd8aae481c647bf55bcf9f0f8f6222483d407d7cec450928d (For s390x architecture) The image digest is sha256:e14fde23bc01efad56da144b7caf348abb379a87b68bd037b6b4e0191649b3c5 (For ppc64le architecture) The image digest is sha256:5ca043db92ab39595e4827b2450e4dd369feba122a11fc562d78793196af2eef (For aarch64 architecture) The image digest is sha256:a6fc0b3c4774a57efb059238bb3aab2638383ae3f2745220dd1e14e08e36e9f5 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (54)