VDB

RHSA-2023%3A1327

RHSA-2023%3A1327 PUBLISHED CVSS 5.300000190734863 MEDIUM

A flaw was found in the net/http library of the golang package. This flaw allows an attacker to cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-egress-http-proxy@sha256:7f3e96b390f1d73a0f8847c8464937dfe174b3417d1559625aec218b62c38ffc_ppc64le as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ptp-must-gather-rhel8@sha256:546c5fe0448350d45773fc62707b4fa0e584119cb48d10f21abdfa2bad690b27_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ptp-must-gather-rhel8@sha256:546c5fe0448350d45773fc62707b4fa0e584119cb48d10f21abdfa2bad690b27_arm64
Red Hatopenshift4/ose-egress-http-proxy@sha256:b33839f05f1491340ed582ea0dfa3151515a1125dbaed27cfa108b3ffe95c4c9_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-egress-http-proxy@sha256:b33839f05f1491340ed582ea0dfa3151515a1125dbaed27cfa108b3ffe95c4c9_amd64
Red Hatopenshift4/ose-cluster-capacity@sha256:e6be71f0962bc11fdfa94b3347c7fad3139bd73be157d1904d8439cb3a324066_amd64 as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-cluster-capacity@sha256:085dc01d60a8577cf10c0989a15e35d9ab5d2e638c3ad7ad610878714050e567_ppc64le as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-capacity@sha256:085dc01d60a8577cf10c0989a15e35d9ab5d2e638c3ad7ad610878714050e567_ppc64le
Red Hatopenshift4/ose-egress-router@sha256:6d4f086579f5e15a28446e6b50ea21c1be984a396eacf21360f1ce0f0058bab1_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-egress-router@sha256:6d4f086579f5e15a28446e6b50ea21c1be984a396eacf21360f1ce0f0058bab1_arm64
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:3dd39ef3c0b025dc8c9c9ef9d6df3baa5cedc6112f56368ca2cec7b33d197805_s390x as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-operator-sdk-rhel8@sha256:3dd39ef3c0b025dc8c9c9ef9d6df3baa5cedc6112f56368ca2cec7b33d197805_s390x
Red Hatopenshift4/kubernetes-nmstate-rhel8-operator@sha256:3a736c5d770150a34253a1cbd85f83289b7f57fb11de5fd5b54f60267e6b3767_ppc64le as a component of Red Hat OpenShift Container Platform 4.13openshift4/kubernetes-nmstate-rhel8-operator@sha256:3a736c5d770150a34253a1cbd85f83289b7f57fb11de5fd5b54f60267e6b3767_ppc64le
Red Hatopenshift4/ose-cluster-capacity@sha256:e6be71f0962bc11fdfa94b3347c7fad3139bd73be157d1904d8439cb3a324066_amd64 as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:85e0e8b3a65d28382b61e690a86434eb89b09991f6c90495372797bfda62c2ea_amd64 as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-egress-http-proxy@sha256:baccbaae5cc255249424e4665cbbe0abdf3d86c3e5055b7da15d948c34918482_s390x as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-openshift-proxy-pull-test-rhel8@sha256:cfdb76e8b7b5b4b5470d63e0fa8d3ffeb09011fc50c9f3b43de6a5383ab7c41d_s390x as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:cfdb76e8b7b5b4b5470d63e0fa8d3ffeb09011fc50c9f3b43de6a5383ab7c41d_s390x
Red Hatopenshift4/ptp-must-gather-rhel8@sha256:485ee62cd061f15a1ed5098c0c662d8f5b9c9a4634ccc26f9ae27fa5bd2e0606_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ptp-must-gather-rhel8@sha256:485ee62cd061f15a1ed5098c0c662d8f5b9c9a4634ccc26f9ae27fa5bd2e0606_amd64
Red Hatopenshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3b12700d1122a6948ae809696069dff8c2c016ff6e4aac3f77edcedc272b178f_s390x as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-local-storage-mustgather-rhel8@sha256:eec4bfd3b27863d79cec89b8e8f4c3867e87d0b0dc377a5ce13f7fe6d6d44e62_arm64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-local-storage-mustgather-rhel8@sha256:eec4bfd3b27863d79cec89b8e8f4c3867e87d0b0dc377a5ce13f7fe6d6d44e62_arm64
Red Hatopenshift4/kubernetes-nmstate-rhel8-operator@sha256:c3238f8f38f39733ee9308155936bbd7e574d52a2c1d150f4f2e6f8dd4a79ed6_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/kubernetes-nmstate-rhel8-operator@sha256:c3238f8f38f39733ee9308155936bbd7e574d52a2c1d150f4f2e6f8dd4a79ed6_amd64
Red Hatopenshift4/ose-service-idler-rhel8@sha256:96b0e5d9882d5b54ca6bf17279b8ce5f75362a76d7152d8d21aac345d951a69e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-service-idler-rhel8@sha256:96b0e5d9882d5b54ca6bf17279b8ce5f75362a76d7152d8d21aac345d951a69e_ppc64le
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:3dd39ef3c0b025dc8c9c9ef9d6df3baa5cedc6112f56368ca2cec7b33d197805_s390x as a component of Red Hat OpenShift Container Platform 4.13*
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:c1ac479083431521d52e0dba496ffd8c7ddbaf7347ada1c7fa294b5c1fa9fced_ppc64le as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:c1ac479083431521d52e0dba496ffd8c7ddbaf7347ada1c7fa294b5c1fa9fced_ppc64le
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:ab7c321f4ff6f5307d21e8577e58a9a9264218619729f387ab98754b1c3c49a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13openshift4/ose-operator-sdk-rhel8@sha256:ab7c321f4ff6f5307d21e8577e58a9a9264218619729f387ab98754b1c3c49a9_ppc64le

…and 98 more

Timeline

  • May 17, 2023 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 30, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›