RHSA-2024:1037HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.36 bug fix and security update

Published
March 6, 2024
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products77

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:2a58c1a609e4a77da66c8b5e8833d9d9df16320d44c75f9b7662ba66a4f725e6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:4fa48b5e67503877b9b33e242385cd764eb9983eecb99870eb89dfad9d5dbd0b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:6112bbf82c63d90f3637218aaeaa5c605e48bf339a1b044509d09ac9b22a6e94_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:e93c2512369179b7c5aa877a4cf33712b7c4ff58a6ac0563dbb7b7a617962dcb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:262eb9c68728104e51df63e020fed5a805e4918270d819f65a206d9c7af701e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:61a16819fdd69072e2b6cebfd56511a454a62afe02c438a2dc97d29c7636149b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:d65104b34cd5203d85483d6b81e57d0498c45eb5fd240a192afd19c18a35ddd9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:e00ce76b371b816a8c80cfd4ed7bbc9f38dfff1238bbab5208356e7c52e71217_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-config-operator@sha256:8f2b749559fccda16a01b421a9a6f85380878ef6de261b1de0c8d49e2c008081_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-config-operator@sha256:949c12a11284adeb7631beebfa6063e7b4370f4759697e248be26ba123d1a1c6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-config-operator@sha256:ea4f428f32e0b3d563684489337b5d9d85d9bded8ba953379c59bf92f4d575cd_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-config-operator@sha256:eed3827b3d2c0991701a7dc1b11fd9c470300fc280e0774029d37a106ec3daa8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-image-registry-operator@sha256:413de2cae3174106d4da50789dbff8246d4b8fd159609339131f66c504fb89b6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-image-registry-operator@sha256:4704e5fcc739c86c2556770892d2bf522126d56755be5d92af805b4fd88c7606_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-image-registry-operator@sha256:4cc7390b0c15abb9ebe7956c0469927a3c9c07227f14eb0701b976a40a8ad0d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-image-registry-operator@sha256:93f41feb4fc4e3c8a237e51e8c978de4e5d3a91acfc08ee87a5f3b92de17791c_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-network-operator@sha256:308f07643a1ef79d86e4499705e2d6d453619bb8d62b195ddac6007cd5b7a144_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-network-operator@sha256:8b30123521ecae392692ff3f437e294f47cca488f0e3021f2532b28a1ca7fe06_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-network-operator@sha256:ac2e6f3ae6fda3e9c45bfdb3d030a7371bf9e13f681779410c0791a2c98e0662_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-network-operator@sha256:de88ab976e0381b1455c0f393b4fae2e1886e4067ffb1838a74f12231e2d2df1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:52b10c3124951279acb8f82b388eecf3c6d723bd48ea1d9aa180a547107a27f3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:a96b8565e6d3349d91b6ab86af6d28d55fce9374d323d34482b73310499043cd_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:b36b9083e87bfc2a22b647576b8ea533f6d50533549b0061ad09facdf9e0fe48_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c90fe0325605ada37437986c6d5ce4df0a1a98db9832f31a21046476bf83f8f8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console-operator@sha256:5993fc55b216df28edb402f675251ee33a7aef0e3153a8fc5b4da4da9f6d1371_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console-operator@sha256:8cdbcd074d3b5cf8e7370a91a30b3dabe4ebb554285959d84a2bb5ff371ad54d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console-operator@sha256:cbb31f6d1080483ff58877d093606b866d71a4cd46d63290704779887d72fbb6_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console-operator@sha256:f5c4932a52af8377212776fe8b867061dfb56d233fb7c1decabaf4a056a211f5_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-console@sha256:3daf59dd42a704d82023dd94648f1352e4089570865d0a7e6ecd71d0f34a778c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • +47 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:9ed18a88ce6242dceab887ee7dc92eecf9e0194a569e1e8c924cbf4b1da7816e (For s390x architecture) The image digest is sha256:39c264672d907a91c8014a874a62a11da8210fa2a96dc79a892075e2f81a28d1 (For ppc64le architecture) The image digest is sha256:71acc8c734200d05ad08aeac48b82c5f7f1011a9f095b7b3bb493b93dfa1753d (For aarch64 architecture) The image digest is sha256:ddfeb044fee25f45b5c3e5e1ac542952b00e78fd2f842c985491d8e58d75ec5f All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (15)