RHSA-2023:7687HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.26 bug fix and security update

Published
December 13, 2023
Last Modified
September 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products77

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:87161107ecf98404c8a16253f70cb1161f912631e7071e9e8a5f23abc8cb1c81_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:bd0f5b09a69991141ac453788e1bf82f929755add56ff0b016f59dc5f9ee4069_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:d896d49b3ad7a06348fb4c901a43e57106d8964e6b7a6c41cbc51a591a693ce5_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:e09e7d18dbd03548965cf7e2452ab240819a04912c395c307ea7ac83b8234407_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:9111bf8e1272fd77d44db6ca15c4c7c82df530dbd651f6c0b880dc06b2259b15_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:d3a0c24bcb4ce2061d3cf47fa4ea07607610447bdf8719ba31ad96b2867909a6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:db2d757db4c605c4f91d949a01b9de771ff4b80005dd46c472d0cb2af56b12e0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:eaece5585ade7ea69944930312f4b7316a3cb9efce38336edb53e8d2404e4373_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:02770a527d1b5278a849109640666c8da368f7db0dceb7e71410f17a18d39511_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:0ae007dd4af28973b1beca810365c4d0b958e27d1e6cdd99638ac09b869ee915_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:63735dba9f371806527f425d20c748e6e46b16847cdf5ee2ea95739676c5bd6f_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:867f3d534eb4a6bcc5677ad1b2dacb9745d945019a2c441c0fdf27332770dd3f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:12c05195a2ae13dab2d32fa033233163d312b13f1a52b75525fa36311fdd36ee_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:1a569a7bb305680ec918b7155c155ffba2106de5237ca6c8f3f1d0453232633e_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:24469931fe23b851e812508f683922e3c118127d0bce5fbac28ca4c2305039f6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:408f99eeea797688f019ae48d1146d2aafdc617f03333f738d965bdf0ccf9f13_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:08c0702b76afcd36918a08363f923cb58306c989e19a220fcf912f064553768d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:52ee0a106024b1d7868e0dc618d713696cb12b6d3c450933316f2cf01c456649_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:5b2b23814f522b36dad0538790b4a67674503f6a9b9a07c285ba801da5f6fd6c_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:d8a3620411240d33e8923fa3cfa51bfc7db3c4d87d9bbb1a3460bc68f61f56be_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-gcp-cloud-controller-manager-rhel8@sha256:0a7942473533bff70f8ebda2d93910d63b4dbb4c8d4b75253be06299b0786587_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-gcp-cloud-controller-manager-rhel8@sha256:8a493115b7fc957bb2cb8f69314a1fe02e484db87abee79ed60d41e79fd82134_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-gcp-cloud-controller-manager-rhel8@sha256:9021508b88e4bb0af0f244e7448ff1f014521a9d392b2241745b04a694db2080_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-hyperkube@sha256:171472cbdf0fcbaa145691078ab1905261fba7a24881e5e6ae590ac8165e8e3a_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-hyperkube@sha256:37dd7c8c5dcd7844aba30c339460e201eaaa646fb79ad01920ef15870fbc7d2f_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-hyperkube@sha256:5906942e53bca144c074630ad88c3cc158d521e777f17c95f56ff82e512e399e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-hyperkube@sha256:625464dbba9d77d4cd210521acae68652a8c6aed28f478ad2f49b903e0d4a827_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-hypershift-rhel8@sha256:464fd072dab1e1cf7e87d41c667f31592a64dc2af9b9c7b088d7c8d41055d0b6_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-hypershift-rhel8@sha256:48c9c1b2069a0ecc4a7f5f1bdde41be7b3d8088a5cccca1d843c82e670fa1ba8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +47 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:dece136ed888653cae20c2832b9e94de7c7ab24e34cddf49d5d284f41d7b61b1 (For s390x architecture) The image digest is sha256:bfbdafa2c6a2802bf2b66c8e1b5bf9fadfe540c9739da8daa666d69a1890c31f (For ppc64le architecture) The image digest is sha256:afeb405b91d2e79d752beef15e7f63bc54519e7371d508a47f8570cff34b384c (For aarch64 architecture) The image digest is sha256:bfc4eaa2419cc0a214789137cd2ffb56403f35ec14ec11937858e2c88824587d All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (10)