RHSA-2023:7342HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.11 low-latency extras update

Published
November 16, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products7

  • Red Hat OpenShift Container Platform 4.11
  • openshift4/cnf-tests-rhel8@sha256:5637e6e6e40323d008541078ae6a67462574b5e6368602d86f02a42d0e1bfa0d_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/dpdk-base-rhel8@sha256:d7d6971682fb69eef049afcb96d9df2013be45bce34737d9acac52a8c401a1e8_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:8c9a3630bc8446387b1950a6bc33c4ed36ea80f76db659cc2b99dc644c92aeb9_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/numaresources-operator-bundle@sha256:05b1e4e5324742678c66e48cea3c99da88bba68da4831676dc801f2ef10b7aed_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/numaresources-rhel8-operator@sha256:2e68b9e4e95326112213b6efbd770dc20a95d080c32587c5c97575e783804087_amd64 as a component of Red Hat OpenShift Container Platform 4.11
  • openshift4/performance-addon-operator-must-gather-rhel8@sha256:e97c352088a7f3871c9aa7fbd8647d02ad363223b8b35c5998371007847769dc_amd64 as a component of Red Hat OpenShift Container Platform 4.11

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)