RHSA-2023:7515HighCVSS 8.8

Red Hat Security Advisory: Red Hat OpenShift for Windows Containers 9.0.0 security update

Published
November 27, 2023
Last Modified
August 31, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-3676 — kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation CVE-2023-3955 — kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products4

  • Red Hat OpenShift Container Platform 4.14
  • openshift4-wincw/windows-machine-config-operator-bundle@sha256:d45504b2b477258f723c3c91a353e1100c9679a67730911f87225da7dd76230f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4-wincw/windows-machine-config-rhel9-operator@sha256:ae6b81b631c16ae515ef4adb40159669a8051a670d88d7b762ff56ae6e09031c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/windows-machine-config-operator-bundle@sha256:d45504b2b477258f723c3c91a353e1100c9679a67730911f87225da7dd76230f_amd64 as a component of Red Hat OpenShift Container Platform 4.14

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (56)