RHSA-2023:6845HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.13.22 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products166
- Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:32b285b14ab4b81e25b5223f6bb7eaa4c6d8c5feb55d4fdb6a1b13981a767014_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:4ce56e0317666c2ac1b8adc11bc251f8749a4b2e055d75b44cda203257a897ef_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:93f2a51639b42b871585a717af75e804d102a4279d285609e6110f538370388d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:b021b5d20373b8c9cc502b3bfce84515a8d191f6ca62bca2700b74edcbb06f42_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:2dfb38a84f4474db35d27a11f04e7459f1666cbd3a62e5086b1d073929accf9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:5ab1c1d15a1c6e0228e85ea73ffc13d571f26a10209d2c51a5eddbb9a47402f7_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:142554a1ee411c6e272dac1a8c88d29bc94d173343d851ed451775fa0d6bf300_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:40a1406f5ecad8f680de19fe91b09e4f1a488db6c629a506c64310a84595dd3c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:8b29fb05fb6829e2d9dc50c8f4ac17e51982c7f30f9e82f822a0e3d7b3820c7c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:ecd5e5cb62f910e01f8ac8bf2b2482073e1b9501a8db8422b0fb1c658396f535_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:00ee2d74db090681c31790771e75a56338442f77911d1fa584ded9c9adb66434_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:3415d04b6d4d731bb99a6b864d157cc369a330d92f595dde6f9dc34737335225_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:46e6f25439702462a529ae1d93f2ca9477dfff6af82e92c884870e5b4e94ae18_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:d836fb6104967f7d0d331c66e467f7de665e6fd3d6b3fc5c8ed2c3ed6fc7322f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:993010fbd5d55e3101d73400ed0cdcfc4ca86353bb08e44f13a683f3e131fbe2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:9f6c1f1b5e553da0165fd9c75d8eecc2e59e5246d4d68d7966d7d865e6840925_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:a35f4632d91a962a47b2187af6c9595ed5bb11ccdf79c819a870d98ffb89cbff_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:d265847152236423397d5e79b1ba56a79b7c3cd20c039bc38af70418a1660567_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:1328a834ac8f7f2d81063dedee304736e5cce78171341f4a3a246ba78c35642e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:42e52f161e221b321dec7525f31565ef7e272113ccc7744e27b05978df9af6b5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:8900991b43001083a56eb8af3fb0dfec5b87edf75c7a9be89e016d3a48d1f0b8_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:d357ed0b3ccddb6a0786acb99f823664c7f3ea80eb21660b3f5637b1f05ec2c5_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:2430f531759c9f4ed95cd51896341a22618f34e6537b6b0a43f3b3c7978d5016_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:470d63a49bcd4567e5fd2be087f879646e074fd497bc7fb609b4f0d3f1d457d2_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:531e863778ea2319ce51d5b9ae793c482e90778279c174981ee987b13b65f537_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:c66ec854d0d0378fe3901d68d7da3eb9935de2eff644407e471c4c1718c72335_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:32b285b14ab4b81e25b5223f6bb7eaa4c6d8c5feb55d4fdb6a1b13981a767014_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:4ce56e0317666c2ac1b8adc11bc251f8749a4b2e055d75b44cda203257a897ef_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:93f2a51639b42b871585a717af75e804d102a4279d285609e6110f538370388d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- +136 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:6845
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-19908
- externalhttps://issues.redhat.com/browse/OCPBUGS-22365
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6845.json