RHSA-2023:7607HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.12.45 security and extras update

Published
December 6, 2023
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products174

  • Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:198b1f72ee4f424fa113845e6a87dfa866e20fc8b84e8827be4621bd97b7e12f_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:21615408394f70770bc38def52a3ef9b0bff7b88fbf12fd22b1520234a398dcb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:c87608a3f232dfba2b2ff49594c6d11462d41e7ce05ff256e52c81f2570fb15e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:feaad9dcda41d5d3d075da86ec81a3c6b6f1b31f6425fd899477657745409a61_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:07cf1e463dcbb0c95411d65ba7e40c3e0596babf939a355161447a10efd1907b_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:48d3974c4a68ed8f4bf5cf5b05376e7659a352b6fc8ff6755809c03443c9242a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:dac327af9a56130e06709cea9b51400f8ab94931229358a72f50eb66a0fb8ed8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:036220096ae8027606a18600e476e4c442e32c2c784531a3a6a5e65d23654eed_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:e83fc469ad0bfa07460635ef524869c1d79aeb7733efeaee028974f4e3bdd1ef_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:6460776be3449b486bf7e86b6c84dda9664516e6128c86d6643e04a98f5957f5_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:85f43dce384d640299ae1e51ad341e592edf4a36c9fd7e5e2e2621101573034f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:b274835139b29cd37596b27253a4a6a4420ac6e7287c0e6ba6beef44cdb42bfc_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:d969377ed16da70565d9c86c7036e549b931565b06948015a51ee6aef1fc5907_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:255f54458ca6d6fad5c8027f3cfaae88065ccfd4ee28fd6e0c28a69d40c156e5_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:b71fb223e0cbce99e737e499ea8e83e939db8e34d9c97b627745559966e0535e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:ea381955920468efd40ce41b8982365a6bab81f933e6f663b2099428c57b560a_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:fc6fbafe680328ec9a03c1ca4f7f12774f5178f0b32f4f05bbaa068bbdd51ca9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:03a9354a8497c3eb11ecd32d2792984fdb305958c30f46752782b07bb9c52779_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:40aa6464960733c0a748b5e93d97d9fcbfa591b4381fa46da05f99d91645df0e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:aac03e5e5d59997e132db5145529582de5c53a488caead5e067ff562a5303dcd_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:ebd23792c2782e2a2072aad21a40716edf11875175892db6b32952cd70bf9b61_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:60c50c608a087be767cc467d32a5aab91e1d7b778591f65c6590f5ad83450600_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:b7da2ee2162081e41d7960819a7b753ba8876c38778adf7f033da7758f469fa9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:c9e8cdad2f2a69d9e912a3e2822fc7c44b895263b9c250e118dd7865015544aa_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:dea338f9aa984a640c1455a4254f6ea073ac61f0b874bd41574135c3fb4c203a_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:482fff9c77a48020e8b07a72c6dd543138dbc24fcd2429d5ecaf013c4c36c617_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:543b18daffb91a3bbef1f07f81f0dfac81b0de0ca4d36e82f60d602adbbde401_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:cbf45e26bf092e35d322329c4f7a10081405fda4e888dcc836b8ac0277c0f3f3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:e6cd98caedfbb4f321225af58733bc85d57d0008dda06638cdf5601141f0076b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • +144 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (6)