RHSA-2023:7474HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.13.24 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products169
- Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:583993f21b7bee165d57d9898b8ec2b3b3e06269660f76fe77a8c57663f458bf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:7e9088c1af44491f8753769152f656f8bde9d9927acf2794a72f3436e1ac7e4f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:bfb8faa87de3ed63284dcb63113830668e7ea66537e1cb1a59958c31e99c4236_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:d9a64d8121c6a90951a528c85d69391ae853894166cb8178d22d83059e843156_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:7641db5563f6cfe1d827c48619974a48521abe612f94141bfc7ed6498f608c34_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:e6f678d058311279fd6a1a4fa983090791b35ece404c0fd9f583becdb8422d73_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:2d4572172d54572a418008c59d93b93e9bf0e7cf87d7eae5ce1db50cff7329c3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:9a3e807339d4285c12e15a2df0972110680e3c43a1bf3ce8b474db18da57d06a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:b9ec86a575cf2b6629cae77d492d81b37ec8e4cff23f4b769e11ffdd68dfc361_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:d2ef1443ba20cc8a014d1e8926d3a663f5a28e2a4ba2580c5b8d7b45dc481ebd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:3dd0367ad9b8f1b01f22fef9351808e8513f5ff507108f58e50ddf16486420cf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:7e39e68c2a87f02c1b4a705069205bd4ebac98a90e263b0243f982c091c9f9e8_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:dc072431131fee2e95578aa8d1a277b53cf1da0814202ec60f2f36622624b276_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:f4ddd2343827d746388e35bd6c8c5f20520258fe089a3e4f5bc887cdf3ab0354_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:2c24202b64bd9d540e2ccb95b2b3cd9e5591fd6e2cf5243aa3a746dd44bd5958_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:2fa01274966e1fa500d8c361046ee018f8e62d0400fe320a2bff983bd060252e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:372bc9408c0842282bc2ea96f32133f04c9fd23d46a10c8ba11f9a63d0e7288c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:47b499c32aa92f129c3648c06d1672c4e41cfedddb1f19ed30bdba8b55c3f8ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:2cea2356984e2092fe6eb1c2b1090a9aea9baac1e1ec88c9d91a618a1c7d2f3d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:3048ee83ac0736ca70434265a36a7f050937c06ad5f1c90109b2e7aa3d001d74_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:3df677b96e8dcc147058658c5c18135753ede31e29f03ce9856149e861f07a07_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:c3f438e57e0e1d416d0d4864bd12e8d49890eaab2ab46a3c0104dbc161e43348_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:1771c284613475def23c0161c528cb6d498009be8ca9764772433a93e1f6b36c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:9aef30e1c2131c1eebaf2141bc7bd165c51619738258b79164e5b440ad8a6225_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:db0533199027c100b3a0e93786a3c10a34391dbcc8498f296f84c920551aadc2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:e703e961d11fcc280682673fe89965b3d23b05f25c5b7b1273adec50b87b360e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:583993f21b7bee165d57d9898b8ec2b3b3e06269660f76fe77a8c57663f458bf_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:7e9088c1af44491f8753769152f656f8bde9d9927acf2794a72f3436e1ac7e4f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:bfb8faa87de3ed63284dcb63113830668e7ea66537e1cb1a59958c31e99c4236_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- +139 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.