VDB

RHBA-2023%3A7492

RHBA-2023%3A7492 PUBLISHED CVSS 7.5 HIGH

A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the Rapid Reset Attack in the Go language packages. Security Bulletin https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhods/odh-modelmesh-serving-controller-rhel8@sha256:0f60f7523db4bf6c18bf69984e56ce632ceb1f0b4e868e73ef653b43e5034f75_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-modelmesh-runtime-adapter-rhel8@sha256:f99fb510544a7e72137e48f0dca08949159786658ed8a3b3b74cc1d132fd1d35_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-operator-base-rhel8@sha256:e33814ce6b42423bb9a8237c6a4b5f58bbbd9239b8335f3fca85ad86fdc39a37_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-ml-pipelines-scheduledworkflow-rhel8@sha256:75a02edd646967593afd87f874bb207b22529af22b9e98be27781007186fe886_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-ml-pipelines-scheduledworkflow-rhel8@sha256:75a02edd646967593afd87f874bb207b22529af22b9e98be27781007186fe886_amd64
Red Hatrhods/odh-notebook-controller-rhel8@sha256:19daaa5932e1297efc469eae97f0b7f1fb4b652d44aa828e3d3bcf5e9dfdc9b4_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-ml-pipelines-scheduledworkflow-rhel8@sha256:75a02edd646967593afd87f874bb207b22529af22b9e98be27781007186fe886_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-modelmesh-rhel8@sha256:d7605432021879d043f95602b77bc99804211e0e240628fd4fb285550df61fbc_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-modelmesh-runtime-adapter-rhel8@sha256:f99fb510544a7e72137e48f0dca08949159786658ed8a3b3b74cc1d132fd1d35_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-modelmesh-runtime-adapter-rhel8@sha256:f99fb510544a7e72137e48f0dca08949159786658ed8a3b3b74cc1d132fd1d35_amd64
Red Hatrhods/odh-notebook-controller-rhel8@sha256:19daaa5932e1297efc469eae97f0b7f1fb4b652d44aa828e3d3bcf5e9dfdc9b4_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-ml-pipelines-persistenceagent-rhel8@sha256:e543aaee276a4571c3a06505b0007ae2a435848dd417ee8e47b54481106f119f_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-ml-pipelines-persistenceagent-rhel8@sha256:e543aaee276a4571c3a06505b0007ae2a435848dd417ee8e47b54481106f119f_amd64
Red Hatrhods/odh-modelmesh-serving-controller-rhel8@sha256:0f60f7523db4bf6c18bf69984e56ce632ceb1f0b4e868e73ef653b43e5034f75_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-modelmesh-serving-controller-rhel8@sha256:0f60f7523db4bf6c18bf69984e56ce632ceb1f0b4e868e73ef653b43e5034f75_amd64
Red Hatrhods/odh-ml-pipelines-artifact-manager-rhel8@sha256:3ad91b1853e45873885fdd8dcde094e5c0712a4ea93f2bf30c415c4153710e22_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-ml-pipelines-artifact-manager-rhel8@sha256:3ad91b1853e45873885fdd8dcde094e5c0712a4ea93f2bf30c415c4153710e22_amd64
Red Hatrhods/odh-operator-bundle@sha256:b637a02d23bd8364cc8914421049eb60169c163ac70bff2f33591df1a1193002_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-operator-bundle@sha256:b637a02d23bd8364cc8914421049eb60169c163ac70bff2f33591df1a1193002_amd64
Red Hatrhods/odh-trustyai-service-operator-rhel8@sha256:c6a5d496f39aa30dbc90dee4cb81f6e54d1db3c8d388315b78782d631c5746ca_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-kuberay-operator-controller-rhel8@sha256:6031c4b0cd16ad69e8ddffa27850797f2fcbed37453dc5eadcfc51fddd4fe16e_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-kuberay-operator-controller-rhel8@sha256:6031c4b0cd16ad69e8ddffa27850797f2fcbed37453dc5eadcfc51fddd4fe16e_amd64
Red Hatrhods/odh-kf-notebook-controller-rhel8@sha256:18bdde1e5d61663b56fad3135d046ab29d45ddde030059d2332dbe08f33baa22_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-codeflare-operator-rhel8@sha256:dd14914e92bde9e834b5b806e296ed210e9e45c1e71d3ca8d07492a967e41646_amd64 as a component of RHODS-2.4-RHEL-8rhods/odh-codeflare-operator-rhel8@sha256:dd14914e92bde9e834b5b806e296ed210e9e45c1e71d3ca8d07492a967e41646_amd64
Red Hatrhods/odh-rhel8-operator@sha256:00d56a2984ee01fa81cbe838567e448ce8acced37f7ff919e6e50cf951082ef2_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-ml-pipelines-persistenceagent-rhel8@sha256:e543aaee276a4571c3a06505b0007ae2a435848dd417ee8e47b54481106f119f_amd64 as a component of RHODS-2.4-RHEL-8*
Red Hatrhods/odh-ml-pipelines-cache-rhel8@sha256:d8d6dade3fff4d7312d86226534279638fc981865394a75986bf1a7ff72752f4_amd64 as a component of RHODS-2.4-RHEL-8*

…and 22 more

Timeline

  • Nov 27, 2023 CVE Published
  • Aug 7, 2026 CVE Updated
  • Aug 7, 2026 Security Advisory
  • Aug 7, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›