VDB
RHSA-2023%3A0918
RHSA-2023%3A0918
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the net/http library of the golang package. This flaw allows an attacker to cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:e4994674ce85b9551ddff28eb3da743f49085ead7ba34cbc9619c5f22eee1380_ppc64le as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | * |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:e4994674ce85b9551ddff28eb3da743f49085ead7ba34cbc9619c5f22eee1380_ppc64le as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | * |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:d1934056d70be3cc6576002616ae617eed4574d72b1f7fcd914812c93dd31845_s390x as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-rhel8-operator@sha256:d1934056d70be3cc6576002616ae617eed4574d72b1f7fcd914812c93dd31845_s390x |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:105fca817550739397c41b726262828bf79e478934a56049cf8c809ff370b58d_amd64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-rhel8-operator@sha256:105fca817550739397c41b726262828bf79e478934a56049cf8c809ff370b58d_amd64 |
| Red Hat | ocp-tools-4/service-binding-operator-bundle@sha256:9ab3d5eb70c654270fef9e8e9d4e5b68e1ac3c86bd0e0dcd36cc6f8741be1603_amd64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-operator-bundle@sha256:9ab3d5eb70c654270fef9e8e9d4e5b68e1ac3c86bd0e0dcd36cc6f8741be1603_amd64 |
| Red Hat | ocp-tools-4/service-binding-operator-bundle@sha256:9ab3d5eb70c654270fef9e8e9d4e5b68e1ac3c86bd0e0dcd36cc6f8741be1603_amd64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | * |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:f1994579bb4b1395ea69486dec1b8c73f038ba6a5f787afff0cf42b48681c863_arm64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-rhel8-operator@sha256:f1994579bb4b1395ea69486dec1b8c73f038ba6a5f787afff0cf42b48681c863_arm64 |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:d1934056d70be3cc6576002616ae617eed4574d72b1f7fcd914812c93dd31845_s390x as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-rhel8-operator@sha256:d1934056d70be3cc6576002616ae617eed4574d72b1f7fcd914812c93dd31845_s390x |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:f1994579bb4b1395ea69486dec1b8c73f038ba6a5f787afff0cf42b48681c863_arm64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-rhel8-operator@sha256:f1994579bb4b1395ea69486dec1b8c73f038ba6a5f787afff0cf42b48681c863_arm64 |
| Red Hat | ocp-tools-4/service-binding-rhel8-operator@sha256:105fca817550739397c41b726262828bf79e478934a56049cf8c809ff370b58d_amd64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8 | ocp-tools-4/service-binding-rhel8-operator@sha256:105fca817550739397c41b726262828bf79e478934a56049cf8c809ff370b58d_amd64 |
Timeline
- Feb 27, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:0918 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2161274 issue
- https://issues.redhat.com/browse/APPSVC-1204 advisory
- https://issues.redhat.com/browse/APPSVC-1256 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0918.json advisory
- https://access.redhat.com/security/cve/CVE-2022-41717 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41717 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41717 advisory
- https://go.dev/cl/455635 advisory
- https://go.dev/cl/455717 advisory
- https://go.dev/issue/56350 advisory
- https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ advisory
- https://pkg.go.dev/vuln/GO-2022-1144 advisory