RHSA-2023:6841HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Enterprise security update

Published
November 16, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products174

  • Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:03fff40e666e9d8ac2791ef6811afaa0eff0a983532c64a1fe887ccedd229814_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:673e7a39cb7fd28c870944c499fc8a832883abce205149882753a790c76bc7e5_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:b76e9da1702d85f92aa45071c7af3ed3952d188868367493d6a2226709b30e56_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:c77fab79095381ec7104cf353528a24cc4cdbf5eea379a0bcfbe79f4271dc67f_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:22b1c938c579b3a22464a705bddd9fc9a5817c07e05e3bdefcd53e33cb039e0c_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:5685959de13370c6e3ad176af2559cb7d0da53d7065bbfba56900ba30738b132_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:8a2d1c4b75096ef0ef068bfa2a9e033e9a6b768a7ae9224c8f4e83bd29948e5a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:0a4a204293bf6cf8f9486b076668e1bb2d033cc628a2691aa9a53ffabf4bdc26_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:ba936ab5b07a0af8999e9ece58b07990dfe2a5f991d5899d1ccdeaf19e63873f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:4902d30d18d124ec14154f19ec30d439b214354bef262adc317495e190ebadef_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:90af298ae4d06d973eacd70a47a4fb29081aad636aed943a519b613510b8fc7f_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:d8571c82f786ae3c398c97f865a213c587b8fe70b2f2ab8b744eb06956cd6c98_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:e074780862985ede8a7ef86bf7ea99d7cbf8f865604a68b06c1d46eecd5c98d2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:985e9f662922cf29293861069f7a7ef503c80fcc7ed266fcaf2bb85b894ae612_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:98e25fa5c16fa5f5fbc43aa8455b3d448f1c1b2df8b61197dfd9959bb7cd885f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:ba52f5954a733ebe03602bae249b776d6843491effbea1dca40f5b16103e6971_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:e0ed5e321899488ac22333089b2723871520578f33c6d8939b86402e9324c061_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:a450e0c6267be84f770a3aaa97224d9bccc60a5cc8de23572e00b3b5646587dd_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:c8d31ca074793d99ece9d99d303e90b93e23eff37317ae422efb42e275d022f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:e2649aade6ad30fd35c3b3c6e16839cf5e94dbee73a4dc776c4d71579deee5b7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:e6a53ecaad739f27fcc015de44a1debd888c2437fd1f1ead55e08bdf6ee8a7ad_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:2266bbff720ecb6bd655d6b4a19b8f9417a6462ab6d6dc0edcf3dd228fd6d164_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:48e48417e1d260f56c77c0572209b53949b871341226fb4cc1d5027d77ca35d4_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:4c23adcf3371cfe3cc71cf7a6b45f7536eea091418541d4f6922ac54411c7c01_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:b1d85d1f7c5bfe5aebe9c25d2037960933b76cb186d54a28cfcf70d42ba2f117_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:0305de9d469a2ac18d3cda881f1fdedec5fbb2a893f81b97c4bfa077fbf1b108_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:3429bb8c3ba408dd5d07e3e60a8ed6fe1833adcbf0ab16d1f390edd0002539b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:8bb9f5823ee1ae3599f7154f2eb477e3af67994c40236a93003b6d862ddaf443_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:eef97de88150282748fa84f419be2ed6cf65213f92e53d7d18d22f533bb3df70_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • +144 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)