RHSA-2023:7602HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.25 security and extras update

Published
December 6, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products21

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-dns-proxy@sha256:5996c624d7d6f83d68b9bba67f741ffc92278b341c59e6a4ee2070f572216f76_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-dns-proxy@sha256:5a1bbd8b982cb7845cc35ab4072fefa671294f9ba9c9beaed304e5965ef9aa5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-dns-proxy@sha256:6c19b0efdbaa0249e1c5a4cf22ecaec1733fac97c914a34a2558d870ad6d4a98_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-dns-proxy@sha256:e6c238ac6ce7c41c4ddcf1af529973e9c25146e01451980b167f151906e6feb9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:39a904fca958a3a5aaabf123d2e6d0dbec88c35936a0ac77991f165ac31ecb7d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:3cdde61014e85721fe8c657d7ce835da41917f373fa11d3bdcfc923272fd64c8_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:5fd316b3d9d7d48567cbbb856f6dabb9a3971ce87ca403146ef51b7a79695965_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:97980eeba34e1639af0abfbbcff93fa3d06cb3df3b09ae3f7e042f86e75f109b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-dp-admission-controller@sha256:1a24b512d3611d1c318b47c703cbfe3d4005bc3c6dd6139a78075979ad3dcdd4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-dp-admission-controller@sha256:cb3daa4e346e3a87e1f95978c5602df689bbbbefcdb7d38879f6b007122037d4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-dp-admission-controller@sha256:da72430cc6b36cb1a1f37c34cff0732bd3f5c867146521cf834a306c92992e47_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-config-daemon@sha256:3c250a78235ea5ceae8826047cd4b52e29b6922c1d939041b8c8e907ffd95291_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-config-daemon@sha256:bb98d675b56c7e929044db871e7243bc5da16e62ac8c3338b0b420e0dccbcdef_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-config-daemon@sha256:ddb16b814c5699dd1aaed537c4dca85fcef43a3effd95c63630b16d6f031b84b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-operator@sha256:0c998da62cdf956ab7a9dbd0aa2e3a0b7853e093c7e6885acf8f62af1c5085e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-operator@sha256:89ddf537c0f2e16810b4b10a1834c4c14207103991117e0b21740fc003f2ac06_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-operator@sha256:b4f17c82dace3b04ee6fefe772aad5c5238be1e7f19fa627e35f05e8f44a7734_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-webhook@sha256:390e4d22aa8c1fc05bfd2b4c80790896aff863f32aa98eb822852c8af01e9e25_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-webhook@sha256:4429e92de0a15010210fecca5dd57e6d3437b3c68d8598fc318facf8c519caa4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-sriov-network-webhook@sha256:d37a1d918d24d132879c7d4e2aa26438bd7a609f7f19370f24800f44a8186446_ppc64le as a component of Red Hat OpenShift Container Platform 4.13

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (5)