RHSA-2023:7322HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.23 security and extras update

Published
November 21, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products60

  • Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:0afa8ab414fc3bcfc9f4df354d98433b750d04479c98555ca2d06b1b34d2c00c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:17876acb170ddfcde340b0cd723eb7d92ee671c2026c6213919372559093f338_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:6acba95a5dea48416d07d11afcdc7192b209d157d913859fadf8e186e695b013_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:ed25204222dd47179b2f539cfe32b3e4b3593a1de1cfde7cf3788cf026c37ba6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:9f17cb2dc5661ba3b7cafe2496e219bd0e9d6fa1ca9c10fec7d837ad6b934153_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:aee9fd60fc47db7b013c177ba3e7e82fe61832415ee980ce31e7e155f0448ca4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:d5ec6d63a49e285c4dac04622d240d04c54d8a8e152263f466bac1371e055309_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:e152b38a59e390b1e0193b35b233aff8e743b59d3eac2f2bf922d4b30baf0938_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:2a6f2a343654c1688a5e290e09fbfca6c32a88965f9501c87e002fa2a16647b3_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:4ecf38a4f15e0c10262197a6c76b9e73d09b8d3ff80d0ffb532390dd627e5f21_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:7226c4cc18442e7bdd46f12eda8e6a429b16c648d02b2200863b87371d468ceb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:d1d5f14e6aaac23a4c54768bba96722be7d6c1371a98a3197ee8ca14f43e0ea5_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:0afa8ab414fc3bcfc9f4df354d98433b750d04479c98555ca2d06b1b34d2c00c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:17876acb170ddfcde340b0cd723eb7d92ee671c2026c6213919372559093f338_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:6acba95a5dea48416d07d11afcdc7192b209d157d913859fadf8e186e695b013_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:ed25204222dd47179b2f539cfe32b3e4b3593a1de1cfde7cf3788cf026c37ba6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-capacity@sha256:2861bf310207096499130a15b626f53fd2d02d2f6698a8a0c2851e0cd7ccfa6a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-capacity@sha256:5806546eeada374b855e90f355e70ec05c120226f9b7cd504668fd1296d89c8c_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-capacity@sha256:abe8312b520f6046860eff1458254579f78640a61357f73d10dcfd1d05584cf4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-capacity@sha256:c6af63ea2ae176a840e3aec029fc9c594a13038e3a13de0e69658f4efaa8dc6b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:660b53c499911957783068e818fbf5515fe6b8c531e90cbf1adc9d32f530c6c9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:81978c017694e2bdb66e996ce8bf2c65a2167c382f97420f52e5e0068929f818_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:cbba9380708b1127cbf8763990052c9eec1412efb35d78e760fc7f60fe085ea8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:fe8d738ff042e523ec43d42926b13c98d819bec32a78e8c3d81158eca87def83_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:660b53c499911957783068e818fbf5515fe6b8c531e90cbf1adc9d32f530c6c9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:81978c017694e2bdb66e996ce8bf2c65a2167c382f97420f52e5e0068929f818_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:cbba9380708b1127cbf8763990052c9eec1412efb35d78e760fc7f60fe085ea8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:fe8d738ff042e523ec43d42926b13c98d819bec32a78e8c3d81158eca87def83_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3a2bc8ab9762c1399c299827a5d2e8e1f238608a9b2fb441b4633f968f1bdf3c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +30 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (6)