RHSA-2024:0946HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.35 security update

Published
February 28, 2024
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products64

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:368c0aa692c128f812c78cca2bde03555ce6dd3ee4fecff625346e027770f714_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:5809b051eb86cf15e51b57176572868ba346d94f3abd2fb488633e59a36ece16_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:60269a5aa29426b83a521dfef0e998a35ed2b08db51d4dbae7a2500a9d1f9df0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:df5449cc95045714f30676f6f494faea949695d62d1dcd905717d4b3d3f4ae89_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-baremetal-installer-rhel8@sha256:1e547960cd8774707494f30a00fdb00527ab1fcda7c74e41ab59711ad4504b0d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-baremetal-installer-rhel8@sha256:66b3d25cf513839cedaca539bccb9aaacb3994af7ee747d5e3717811fa010779_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-baremetal-installer-rhel8@sha256:d6e5ea81bf740daa31704e7aebf9d63916e073b68b326595f4e478166cd1cb3e_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-baremetal-installer-rhel8@sha256:ea30ddcd9f6324f3e216bb0afe496a4ba4d77c966915757cb9896aa00dda9d19_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:1603978dfdf90cef116e401684d81b85d4810e9fb2f0ceeb2b2eeb07380a90eb_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:197ce5bee3cb4e020fd507d052fb3d137571054e91590ba5aef92c6f503b0b83_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:dddd1380680c2770e51840beb2b5063a140670d43634775f3d98fb63eea61b07_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:eb7941c1fb4b375610f60a685285e772cb494d8815811a6d121029cb3bd54544_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-insights-rhel8-operator@sha256:02610634e48548b4eaaa36d130fc8c79820bf7cffb29c1f150e20a07ac037afa_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-insights-rhel8-operator@sha256:3e14d220ab255c0a1e66d687b4eed282ae7a692e61d612270cb5246da2ccf528_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-insights-rhel8-operator@sha256:6cb35f4f02eaaf492c32a91ee5f9abaa846b6558267e87c0500d0df30652c53b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-insights-rhel8-operator@sha256:f4e9f5f638ceb2b8c6b338c2a29ac4051f31aeca2c0e1ad9c50b37da99e8ff3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer-artifacts@sha256:0aa63b4771d00a471d05d6cd3b34f90b6126db5060db6df2b2e02173591a9526_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer-artifacts@sha256:0acf8988b7f4d03937774452536580b93a08918622344f5009e8adfda231d19f_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer-artifacts@sha256:ac84cefd85343c92f98b28257c2ebee68b6d42be83ba689d7a6edfbb688143b2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer-artifacts@sha256:d96e18cefcc99e3b58eda81bcda46321dd5746d57a97bf3c7a5f7eeebe42428b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer@sha256:69f483f940db39b61d77b52ad0a31cb046cc55cc010868eb013a62e4b5e53732_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer@sha256:72919253e509dfb7c776a74cf82c343414c5ed1b4ed3ad0e8e17047f17ec4681_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer@sha256:9030d43a7d495618eb451fe8297ee593c02cc22dff7c8cc86808b75993345b35_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-installer@sha256:a577600ff180e3ded34d811e766ea723f9f95c4646dd06a7efe17e5856dd44bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-ironic-agent-rhel9@sha256:cd3627b822cd8074ca60337d3eefd67b2a716b67d163bd43d56e74e2088be380_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-ironic-agent-rhel9@sha256:e4af5bb12a15c88dbee46d3bc6f80efeb582136ccb803337b63d3ece65e48f10_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:89c19b45730a9bfc0ea1a81a3fbcc71010098b625942a662064b33b3bd281aba_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:a22eb11dc468482f9343e9060962577cd3ca939091954df21dc9c62d9db375a6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-ironic-rhel9@sha256:72b669b7f96fc597ecbae610dca36fc5066bc7f0cf612800c38a50a56b3161f4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • +34 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:2399ee629b41bf4c4006478260dcffd40849912398c09cba77bfada2fc481247 (For s390x architecture) The image digest is sha256:76973643be097f7556ec05e715121d5bd19f691acbebf0b62657e7c007e7190b (For ppc64le architecture) The image digest is sha256:aa82f2d57af3f1e0024ee5bbb4a1257d8e38c21805ff0e37079a2c1835984da7 (For aarch64 architecture) The image digest is sha256:1cdcff922de36e291741f05c0efe46a9bc88f8c212859f1a24626b149308f7ec All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (7)