Red Hat Security Advisory: OpenShift Container Platform 4.12.44 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products119
- Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:012d171775d8bbdde330560a511894ee714979b91a305afb363777dcd440d8b0_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:807e0b281143bcd503604648c922b4ef3c400cd0561e9f4fc083eab4f21c31af_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:8e99d3e6e90027067ba37555256d66df7348613c67b33f140d45cdc2543d4190_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:f323ec92ac15164072d27b156a80304dcf06b211ec491c0e4d85ca5a3bfa54cf_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:417739b4ffa223e4babf0f60d347db77c5a4afbe2b9da32344c73ecc3fd2e405_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:6915f348f22f8de43c6ab69c6b706fed456c48bbb4266305a7d5db910d9d2cf7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:b706ce529b18c55e857cc3c3f33fdb315b2c25dbc214974a55100ca260c8539b_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:c86a72f8463651bcb954071ddcb2539ca8268145b7ef0b01397114a35eb6d058_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:3fda72723932982bdd4efd3077dfaadbe0f251d1c07a1ae8096d97391bde6465_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:9cf8bed87798baa16a9eeff46de4b1f7add3b5259b98e54aae5c7bfaf907420e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:16e8ce7ff705544d80bb9c04d21b1985bee287552f7c6a9a8ba32f6625d0b458_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:5c1ae4091b74d2fbf60be3f8b109de70e40eeaaaec85491758bf69e8cb6f20b8_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-operator-container-rhel8@sha256:1b4208e3f11335ef35072f11605150f42091414952e085d7c868028afb29bd0e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-operator-container-rhel8@sha256:248377db20e5fb0f02cea925b32dcc14269e8a6ed9984fbe22b413130b5b7df1_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-operator-container-rhel8@sha256:40f903d3b4c76416e7e20bb5c5622851633c8fbb19344e1b259ab148ec147dbc_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-operator-container-rhel8@sha256:8beacdb2f63567e051d715a0d444976cca74d33cb2938b0cec2c26b61a91ef1f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-rhel8-operator@sha256:1b4208e3f11335ef35072f11605150f42091414952e085d7c868028afb29bd0e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-rhel8-operator@sha256:248377db20e5fb0f02cea925b32dcc14269e8a6ed9984fbe22b413130b5b7df1_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-rhel8-operator@sha256:40f903d3b4c76416e7e20bb5c5622851633c8fbb19344e1b259ab148ec147dbc_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-capi-rhel8-operator@sha256:8beacdb2f63567e051d715a0d444976cca74d33cb2938b0cec2c26b61a91ef1f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-config-operator@sha256:3c9908bd1c50d9f2b973de2813a33fdfc1ccde83bfbdb0a2885dd1350cae8d64_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-config-operator@sha256:47819a182b4b897470b633f9518d94f7a0ee75ac761062321792047bdf3d0de6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-config-operator@sha256:53aa8087ef13de0f8220687964c77d626f55acf5b766b1d61a6d58e0875f1279_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-config-operator@sha256:5bb14cf79e7ec32ff8e54eaa216504d2d9284d4e2eb274af0dd21ba40566e0a9_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-kube-cluster-api-rhel8-operator@sha256:444414c51e434850772c77c38ff015eb74666af6c7fbbdf1b57d64752229ddbc_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-kube-cluster-api-rhel8-operator@sha256:b669b256591ac9813ad540f1a32180a8e9e4348175ab67bb1e8be5f024c0b364_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-kube-cluster-api-rhel8-operator@sha256:ce9613c5c8760b6c5402b5f3faef88e51f3a148c125a645f5e6e0c1c5bca71bb_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-kube-cluster-api-rhel8-operator@sha256:e9b657ea850090ffdb620b275f7e15bfecc04e4e3dfa6556c53e5e37170bd9b3_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-cluster-network-operator@sha256:2ed05115fa3d325008295450c1ff2a49a88a20716a94755ccfa956761382290e_s390x as a component of Red Hat OpenShift Container Platform 4.12
- +89 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:304f37f9d7aa290252951751c5bf03a97085f77b4bcde0ed8a2fa455e9600e68 (For s390x architecture) The image digest is sha256:70fcc48ba45dc59687c067864189c2a93e53e5fbfb63986d4294b37db1ca02e5 (For ppc64le architecture) The image digest is sha256:c4306c368f07b6785b231693efccce269be07c9ba9bc823c77d5dda9bf648a9e (For aarch64 architecture) The image digest is sha256:604e261a661843bb39250dec3e189349f3ce3b178edc355b9c98d95a0591fa9c All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:6894
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-20277
- externalhttps://issues.redhat.com/browse/OCPBUGS-22922
- externalhttps://issues.redhat.com/browse/OCPBUGS-22972
- externalhttps://issues.redhat.com/browse/OCPBUGS-23118
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6894.json