RHSA-2024:0660HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.32 bug fix and security update

Published
February 7, 2024
Last Modified
September 20, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:408c8148208e0753a88f66c5185f7950e3d0f8042030890464c0a1cde9519677_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:53187a65fbec3acf034d154d9aaa6f9eda9a6a2217e27c0689556a742c79a31a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:58136fad48da84300af9fed15e9ab48a0ad5e9259132bb5d2b9f03ce6ab4025a_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:bc1d0229f6513c6d3c2168d877b2befb4a64d14b9e6514a6348f0c119fa61ec5_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:9c6d5ff0aac8a07dbaf8822533a213c74e11c91aefc5621ae7f3e8e71b30e463_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:ac78942666196e6124f0d28948488a66bc3e8581c40dc5c4f3d99f29a19f2bb9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:ad4006726a1cf55a7a403164a02d6d928b218b9a6eb631845d1993033785df23_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:e43f35d92cd3b25e48ef587cd9b4dd15db6ac226eb4ce6e782749e18db428c1e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:2b52908956137b4fc47cc84d1cc345f59ce2f5bfb59376ee3c0d447126aebdf6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:49a8de03e58ef1abc1ed7d37537269147e655453ce2b939bedd1aca7636d88a8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:5e40d49c7d12244144176195b52af308174e16944f969b04d529f5df8e8fd3fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:bfa6261e4df7ec7816123a72aa9ef4d48f6b8fb779c4ea9e23f064b711a008ac_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:742e7608bfa12c6b72fdc31552be3909b4f61bed8e880ec27c76ba17185088aa_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:8d1985daec324abb221940527918e198dda60e15b78f7aae1e015c18cf3bb038_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:922daf7e7c750ce2b3ad9368cd95efad25ae5cc7708a7748feb6c0d126bdb49d_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:eb274f3aeee43cbdc6a6f14e2c23ca826860b46dd1069206ebd0243e3a1c8a9c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:2bb8a784ec0f784ad68d505ad4739492e484ef748e1071c480c1e6dff0ec4c0a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:519c27fd1f965d090d3cc5400399943f8b419fd3c1c07300a6cf513db50f8f9c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:7a08933ed6cc13bb0b3dd5c4102ccdcb0530f579162362e56270f10813baf5af_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:7eb19ad3d6b64fa4cbe6a13d996d65d232dd480086c62f57f275329d323440e2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/oc-mirror-plugin-rhel8@sha256:f19b174496dfefbcc6cc748e89f899afc589519fce95d1ddf186abc2064527f9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:36c46fc46294bcb31ac7d38711f193000eb5f370b548ac591593669d2ff2cbe6_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:63387280f645bfb1bf3e041e03196f6230c77b25f446477e5919325a4f60c46f_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:6ceb2928f53931bece2b87d0a5764cf7b598d17b500ae8362f46661d616126e3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:a63892532a741303427f193163b11eaf9b41797415938ebf826a8ab48489ef17_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:6d09f746277525561ed0308d5c090f621e60d441778725fc541287ab205a3a40_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:dfc94c2feaa957245494f5c5f72886481093e8352d5a792cfad84e87bdb22e8e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:e044434022f845ca11b24c3dcbad4b2b5ae3e5f351dbb9a7da1532af9651d2b6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:fdbc7f0439cc0c9eb1afada12ab35dc78f1a902bb60023665be83b99329c22d8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:c39085b26665ed9877e208c123ff147cf7939dde4eca79a4f00fda8ea5b13dc9 (For s390x architecture) The image digest is sha256:34853a34501e938d425b9a967ec71bb837f0b2a3e6bc06d085ec3bfbad7f9315 (For ppc64le architecture) The image digest is sha256:aa45256672abb282af909e245970b30fc1018554f276332ba12017b746d37b36 (For aarch64 architecture) The image digest is sha256:73b504346c37e61cee65604b2719111fb38864e22116d429750c58d128f29f36 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.

🔗 References (14)