Red Hat Security Advisory: OpenShift Virtualization 4.13.6 security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products93
- CNV 4.13 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:0e71d3c240537211edc18dfdfb3e5a3eca9f88a53ee3fd7d58dc18074644a69c_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:d85a4f8ec1cea7bba6575be9984f48fce5a4600b562fb072780719f1bc5ed80e_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:107d04e43edd1399d48742b8830dcba237809320a1fec8b4f68782b0efc2fd86_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:f559d2bdbd8487f726498d10f96a3951f0e44b7c063939cabfca16e74c35bd68_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:70ddbdb6e7c61024cb4249af53a943a40fcf09d7867c55e91d10a61f90dee9f9_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:92c79fa3527d94798647e08d652d3efa3de951792938514d1c975216a9deb6b1_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:01237c51aae3adceeea01460602c5bb900357444cae56ae0e22e99c818435692_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:1fe01e810e8e7b6b86d60199113bd59ca65fe92f7619c9fb7e953ac6eef5d3e3_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:1b696ba369b10f370f5e13d5cb86cacd34fae5406454e2f89a91708b34efd350_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:bd1138c5193f4141105fdf665bf60693631ee6edafa8688cd541534fb8b4da88_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:4d3b8bc4aebf94a9fd4247bca243e7a19e9bc7ddb0060f3020eaae90a4d3b554_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:67a15301595b1552963b684a2bdcbabd0b7c9f64efea05a22f1defaeb802e000_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:46935d95ae6c7861756fee7c4026d7877d6991ae7d237aeade91694c98ececd6_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:91d2e6eb9652199683914aa039cb9e1df6f17f1c9a4c8bde03cb8dbf146cf66e_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:9ebff9a91c3fb8018cafc2f47834375575921677a1dd30b5d4b8205a3fc9b08e_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:a66f5bdcf12014dc03a240fcdb800545c992b7f6b3fe8471b10431e98ab1abc9_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:01630384f181e43217d435dcc0ae92e137bf976876690b68c442e59cc4b50d80_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:18d5ce221b8b2c938b2d52d6751e4679b57a7723ff02698ab0fce89c4c160bd9_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:380f2d6a3b273717a130ff60531efbcbad5031b503d6be70e74f0dad77e61e48_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:ab8e7f2fac2870e0ac55a6b22ecac1120db26f9203687588be13ad3e644835a3_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:016464c7400ea5e04d1d4df40bec38bd4dde83d8f79db0c54a8d81e803b8fb79_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:81e70858aab8bda6cc23788eab031ec38b00b45fb87a4358a98d11f511030396_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:a82f6e4ae5e2f3f26e81b5ed030a892c48165a69584cdb636bc281c2f63ab3f0_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:c7f3ad8727cda85d27466ccba129d0835e2a40cd23a1104e5d688887144d0eac_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:44425d1d119a2f9cb64dfad35ef5699b246ac4373e13c3184db67e53c7de4c01_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:5a053e4919a82d77a3b889ea0d67e2cb8fcdb3c0490eaaee2a2c6695ff7b8bc3_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:eb09be5eb5cc9c61ac72e16d868001911cb900cee4e0d4b33e0e1bf2121b8bd1_arm64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:ebf7a7fccbcfde5a5e41789bc6674b956b24f9ea467b0b1a78c8e4edf3ef84b0_amd64 as a component of CNV 4.13 for RHEL 9
- container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:10505edee0e2e0deedb789149d5393da6a654dd509b01eaec0831fa687efdafd_amd64 as a component of CNV 4.13 for RHEL 9
- +63 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:7522
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247666
- externalhttps://issues.redhat.com/browse/CNV-34788
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7522.json