Red Hat Security Advisory: OpenShift Container Platform 4.13.25 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products66
- Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:318125b4e191fd453fe554ab8dd57694993cd0cd1a8ba7c5b2177f60160cd9b3_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:882a499930f037a6f18232d11c97a54eea34b0d8969b72174a575a66b5633045_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:a2019e05f066ba7bec0fc28b16ee2f1d8eb145d7cd2b0bf7e5c3a7bfc1498bc6_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:dc5a129fc1e423036155a4042e0cb03d13762872c9effc008a31d7439dc3de3e_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:57fcb7cc0a806691d78a334f023fa553744a0166b390623cec67115d0d2f0423_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:9cbecf5ac88738d32d7a52cd158d748b5aa6bda6c0f2ba6f29d164ea0a842afe_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:0b7490fedda0f9f2e9522141e4bc767734d69ed19f03b1bde6d09f0cc25e501b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-azure-cloud-node-manager-rhel8@sha256:8b4bde3c70c9cdc6be968ae8a646f20e426ccb9f72c101e960b2dcc204c17e9e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler-operator@sha256:0b756199229db4a264868851d83895912c2ebcf0f865e78e03e063c6cf7eee0c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler-operator@sha256:39c87b9238588a8f51f3643ae32133df4e86dc7f9ecab642416065ab1b3573af_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler-operator@sha256:8700ffb55b94cb6482444ffc73dc043e022af9fb0f48fd70ec801c8d555c8312_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-autoscaler-operator@sha256:8f501632ebdff66c83cf2b1250fe3d5a506d6476015bf0967cb68ca67b0bf67f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:079b25030fbae470a46c767a55cb8ccf7335a14191681989daabb2e3fbb7845f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:8fe83c8241cc00c5688a0d5275e37a6969bbdee61b17ab1bf5d362aaa2bf7375_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:a5b2807164e72064aa73889738861217f8136a466b985e018f0b3f7b9ede1fa6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-baremetal-operator-rhel8@sha256:b2fe6182d17dcf77450e5a350151dea53b8ea4e010e78300fdadd3c36929b634_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:0fcd486af7b01cd2790201e5c813b0b8f5995360adc9d37f7df411e53260a771_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:1587f42f2b79da81dd66dde0fd969b22c27a8a35418c2f723389ebfbca647d6c_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:b3f95d80c2c3a9c6291896e7bfe5f6ebb5e7d5a1af993d3d5893044b1bfc367e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-etcd-rhel8-operator@sha256:f55f64c2129e5ae0531e4717b9317b04f9cf5cd8f42b62522fa80dc514ae9748_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-image-registry-operator@sha256:10c3f6db57c419286a77a604955a54c5c17cedac957f8ccd09e18e89a6bb08a4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-image-registry-operator@sha256:291e4922d279c81849d3488d464a4829a8e0d00e8701458b9047effec9c6dea9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-image-registry-operator@sha256:75bdd2c8da249820a182634a84714865ce87725abc2bdefe3c1b0c075c986333_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-image-registry-operator@sha256:938747ab4a0bf6e11845293f9ab2756a394167bf4230fc0bfb59af56b76980fe_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:524d4401161337cc4688296a4160afd9b4199571c107accdd1ce16a8a424c328_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:7f2e6bb650ba3d8d7226abd2d006c99cc849bfdb236ea3f0c58ef98a4dae5b36_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:c0ed27055047687b64074a2409e7a4943248739fee28b5434cf5afa34ed6223c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-monitoring-operator@sha256:d410ea120de4c117aa3917f8fc644c47c97453d2aaaad6cb51252f9b4fb19b2e_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console@sha256:7eeff2f00b7ccedecf3654f191733597128754b2b837487e05533ec724f40f2f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +36 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:480f2026c07b0f2e19c3fc60a44e4a7147ab821474641952f077573d05747855 (For s390x architecture) The image digest is sha256:3c367f9cdbc5b258aa251cc51b01b54ed0799e83e5c8e69f68f6c9e433efa9c0 (For ppc64le architecture) The image digest is sha256:54334ec317677a4ea900d2bbf6a9a9b59109652c81c81c465639429a04c899be (For aarch64 architecture) The image digest is sha256:0ba4e32c7ce25273aa2b9afd7466203a88cfac96e8151c47676637cdebf93328 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:7604
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-11316
- externalhttps://issues.redhat.com/browse/OCPBUGS-18106
- externalhttps://issues.redhat.com/browse/OCPBUGS-22126
- externalhttps://issues.redhat.com/browse/OCPBUGS-23504
- externalhttps://issues.redhat.com/browse/OCPBUGS-23536
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7604.json