Red Hat Security Advisory: OpenShift Container Platform 4.12.45 bug fix and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:06fc73bdcb5ad74f78f518ef77d230525422f4c642756ca4ff0fac87092c9f63_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:59389f4dc93676a9c47c6a14c3777bf1391446a6ace0197e7a030ff46e59ff79_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:dd7d790e2753c3e5c98b682f1d72e0ab1d9562b6d46531678f19873a4d80267d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:e93119ab33e86b2fee5a99885fc0707ee15dfb5c08e0233c6abd6e0d78dcd6f3_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:4061a6b6a076fe403fe28510574f12fcd287789704183f88747a6d47c26c8bf9_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:61a6d6f20c21eedec340467df57aa468426ff9b818b36c845e14a8328092b892_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:af094699320ba8e459c25e38ffd1304002ec3d901bce3518a1ec2b7b501a7699_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:d2685174ee65d6491fef6bdf32190e752876c5ddeefea772113210b2d84d41da_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:1366c4fe5fae3c9313409cd9cdc5d19d40d970b5857c2ec8531452a572be275c_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:28f05f6b302f89a2dec5ebcb855e4e7b04228ba726ca21b892965667f406ddf9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:6a18f605be5bf185685c68077d331b03fbe5aa8877d22d7f5c7c75ca774b5aa6_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:eff734ed58bdd8b9eed6cbc20a8006cedb8e69186e9fc2d4b9d6ecccffb36f6d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:04dfc3d20ca2ae489489e6ff0fe8c6e40eef5bc2b03ff80d91a1fcead72129d7_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:95b4d37bd9ceb4342687c7f559d961496610fef8f6726db672d7f69658b98315_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:b55400a00113d737a5d0fb01acb44b1ba361bbdf7ec7ae2d9330dc0e0cfca2ef_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:dc986de37524724962ab73b3ade148a2ee9ac48fb55619a6b0c33376f6cc343e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:32bdd31307c46f6094cdd77760bd1d54be2819f88355be664a795a45bbedb27e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:726136f1b03f86320c06f883882aa8c1c44e965862d21b3030c499eec91788f8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:84cbcebdd4a57e6b072aa406f8654329753c2b774a77bfd33b40ca7eef437cf7_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:aaa1ee74721e31e72c32d8008fb8a1bf089c0b100117ad83f6286a6741fbd3fe_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:94c1bf6c3d538f6021dc51a0733f1f3a02501d680ec181a0e213923c19fa7bbf_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:6474893b0cb06b5d89fae2080a3c4e1bb36ded45a5c7c189837bbf3380e1e41a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:735e238774d6935ac50c70c7a35e5596a1cafad2d6193803e1e544f8b60bc528_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:913ca712732f32b9f81a35e72f5c4609485563e94e8e1f5119a0e99f9f4e4f96_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:e0c947004093d723f693ed0abcb24340556f8bd9656f4b26b9b38bdf73eae204_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:75d1a5644da737b9f594722bd0af8ebd3a9887427cbea8e615c1fae7ec4cf4e9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a908927fa1b60a7d75fba14819174de0aae5cdbe7ba86836cd7a09ee945a27ef_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:f6aac7564da214ae4ddeb376cad08371d4255c5a25f35f36533621eb3205cb93_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:fe982bbc3057c17e4c3a434c9440ab63c27213b1751ca327c5c56e0f0e0481cb_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:faf0aebc0abce8890e046eecfa392c24bc24f6c49146c45447fb0977e692db6e (For s390x architecture) The image digest is sha256:81bca585161b537e68082ffaab1e7d0572b5901e4b87cdc0db6c54f55574e545 (For ppc64le architecture) The image digest is sha256:9937014e58f57af2efa103c38faf8e8a9ccd6ade3346c9b869415e341b3dd153 (For aarch64 architecture) The image digest is sha256:d6a9e81f293cfef34562982af7054aca2f4081ef526bea60ee27fab3ba88462d All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2023:7608
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-19064
- externalhttps://issues.redhat.com/browse/OCPBUGS-20185
- externalhttps://issues.redhat.com/browse/OCPBUGS-20413
- externalhttps://issues.redhat.com/browse/OCPBUGS-20417
- externalhttps://issues.redhat.com/browse/OCPBUGS-21596
- externalhttps://issues.redhat.com/browse/OCPBUGS-22949
- externalhttps://issues.redhat.com/browse/OCPBUGS-23154
- externalhttps://issues.redhat.com/browse/OCPBUGS-23182
- externalhttps://issues.redhat.com/browse/OCPBUGS-23222
- externalhttps://issues.redhat.com/browse/OCPBUGS-23274
- externalhttps://issues.redhat.com/browse/OCPBUGS-23293
- externalhttps://issues.redhat.com/browse/OCPBUGS-23329
- externalhttps://issues.redhat.com/browse/OCPBUGS-23346
- externalhttps://issues.redhat.com/browse/OCPBUGS-23415
- externalhttps://issues.redhat.com/browse/OCPBUGS-23419
- externalhttps://issues.redhat.com/browse/OCPBUGS-23439
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7608.json