Red Hat Security Advisory: OpenShift Virtualization 4.14.1 security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products89
- CNV 4.14 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:94da7e146a8e62fff71f4fd6acf939cf0d3a8c7b35f9fb14f139237729e9b0c6_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:a02de1350d6dcd4f4521029ec6d0e8f1da547b54d01d9cc2b890c840e2d8624e_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:87d8692e6b086bed77ab4b5562c4c4170caa91e235e35eede7108cd9414af28c_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:f3666171ccd500b7049a6a5fd00fd48ede1ab1a35a1bc982da2fa1af5af165c9_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:7432ab9fbb197c9b68e7d703e12625d09e49def80c53492ba00520d51a64c7b6_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:ad43c3c38d4c9f4206930dee8bf019a965cf675dfadfff28f1570e32db367055_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:97e54f6948e760e83d1a2cb36fdee7167674d1f23a3ba6fc0a133ca800946552_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:999c449f4ac126e6ab393df6b353b2227f7032050e5d359b3220c2cc1b7a3187_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:cf459590e404430fe69ab849d9abd680debbc215aff21eafade3fd3dfa104ed1_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:f0e34b9f33a291af87fb2df4561c64cd95a9a1848a74df55c7e1056e85e2ff04_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:51f272ae54582e42555d7155d61ee653edb9e7a631ec0265b7611f6c8fe2e89e_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:d9e23bafc7a2eadab5dfd1fa6030c92194134fed79613e27b314efae7a2fbc0b_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:1261e41397a3f9f445ad0353423d2eac5201846dab33214346b540423e5e3131_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:80e21c741098d690589a0091a521efe84c6813ec17d1a41ecbd4d6b0186e00b8_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:64728b8b09426d9ae8382ba27fa8239e66d926cc876b2a39c4af974e8402fbee_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:f8b26e6cebf1cd4620507a9e139cf6049818cafd016d4cbccd82d70eee4caf0d_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:5ca050c6a8291eda22bd627c688c062ce2c9ad1438919f5bfb7f2f563aa85a05_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:cd79f35fa08910c69a781a7093d8ebecabbf562f088165a2db9ebaa7f7e6c33a_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:1bac75a613f6268b8a3074f59d2c6fd3f414e0a7b3007c1eca44ed0a089da95b_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:28595fa16395c26d64787a6468d5952e430c7e86fd49ad966179e364cd496112_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:36dc46a039352f347554bd214516c8b12f31393f47069e74dee87a8f4f912c83_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:6a09e826c765dcaae515ab4dda1f2aff3a34c3fe5df66b32fdef7807027657d5_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:c265f142261694e567f39005d7f4b32d716421aad9a7c4f0784bca52c6918156_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:d016316e680f939716a31f83ffc43e5a1e930a9a71a30a78f4c87691c8d958ce_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:851c229b564efbf7ad1314598d71885a01c2732e68d64101715a17e170246bca_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:ab0521c0d88d606ac0fa4b8ee4f7b8e62f9c0c8653bc4f641450d22ab74d6c1c_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:2ee0b81f8e469fa9f376c81ab055b03e3fc0c864ed69d79f17907011865dd849_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:98caf47c1db8696080b8f66a82c70d9619d41f209cfbf921fea4bab76bcaf85a_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:81ab202e5738f4b6c8402ff085d88d7221fb1e525d650092c29c5dd8b0df43d2_arm64 as a component of CNV 4.14 for RHEL 9
- +59 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (38)
- selfhttps://access.redhat.com/errata/RHSA-2023:7704
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156753
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223411
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237470
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241658
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244869
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247657
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2249846
- externalhttps://issues.redhat.com/browse/CNV-31077
- externalhttps://issues.redhat.com/browse/CNV-31675
- externalhttps://issues.redhat.com/browse/CNV-31991
- externalhttps://issues.redhat.com/browse/CNV-32287
- externalhttps://issues.redhat.com/browse/CNV-32672
- externalhttps://issues.redhat.com/browse/CNV-32770
- externalhttps://issues.redhat.com/browse/CNV-32937
- externalhttps://issues.redhat.com/browse/CNV-32940
- externalhttps://issues.redhat.com/browse/CNV-32970
- externalhttps://issues.redhat.com/browse/CNV-33621
- externalhttps://issues.redhat.com/browse/CNV-33665
- externalhttps://issues.redhat.com/browse/CNV-34138
- externalhttps://issues.redhat.com/browse/CNV-34724
- externalhttps://issues.redhat.com/browse/CNV-34761
- externalhttps://issues.redhat.com/browse/CNV-34786
- externalhttps://issues.redhat.com/browse/CNV-34892
- externalhttps://issues.redhat.com/browse/CNV-35205
- externalhttps://issues.redhat.com/browse/CNV-35242
- externalhttps://issues.redhat.com/browse/CNV-35723
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7704.json