RHSA-2023:7200HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.15.z security update

Published
February 27, 2024
Last Modified
September 15, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-45287 — golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.

🎯 Affected products11

  • Red Hat OpenShift Container Platform 4.15
  • microshift-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.src as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-greenboot-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.noarch as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-networking-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-networking-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-olm-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-olm-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-release-info-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.noarch as a component of Red Hat OpenShift Container Platform 4.15
  • microshift-selinux-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9.noarch as a component of Red Hat OpenShift Container Platform 4.15

✅ Remediation

For Red Hat build of MicroShift 4.15, read the following documentation for important instructions on how to install the latest RPMs and fully apply this asynchronous errata update: https://access.redhat.com/documentation/en-us/red_hat_build_of_microshift/4.15/html/release_notes/index Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: No mitigation is available for this flaw. Workaround: No current mitigation is available for this vulnerability.

🔗 References (32)