VDB
RHSA-2023%3A1327
RHSA-2023%3A1327
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the net/http library of the golang package. This flaw allows an attacker to cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-egress-http-proxy@sha256:7f3e96b390f1d73a0f8847c8464937dfe174b3417d1559625aec218b62c38ffc_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ptp-must-gather-rhel8@sha256:546c5fe0448350d45773fc62707b4fa0e584119cb48d10f21abdfa2bad690b27_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ptp-must-gather-rhel8@sha256:546c5fe0448350d45773fc62707b4fa0e584119cb48d10f21abdfa2bad690b27_arm64 |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:b33839f05f1491340ed582ea0dfa3151515a1125dbaed27cfa108b3ffe95c4c9_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-egress-http-proxy@sha256:b33839f05f1491340ed582ea0dfa3151515a1125dbaed27cfa108b3ffe95c4c9_amd64 |
| Red Hat | openshift4/ose-cluster-capacity@sha256:e6be71f0962bc11fdfa94b3347c7fad3139bd73be157d1904d8439cb3a324066_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-cluster-capacity@sha256:085dc01d60a8577cf10c0989a15e35d9ab5d2e638c3ad7ad610878714050e567_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-capacity@sha256:085dc01d60a8577cf10c0989a15e35d9ab5d2e638c3ad7ad610878714050e567_ppc64le |
| Red Hat | openshift4/ose-egress-router@sha256:6d4f086579f5e15a28446e6b50ea21c1be984a396eacf21360f1ce0f0058bab1_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-egress-router@sha256:6d4f086579f5e15a28446e6b50ea21c1be984a396eacf21360f1ce0f0058bab1_arm64 |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:3dd39ef3c0b025dc8c9c9ef9d6df3baa5cedc6112f56368ca2cec7b33d197805_s390x as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-operator-sdk-rhel8@sha256:3dd39ef3c0b025dc8c9c9ef9d6df3baa5cedc6112f56368ca2cec7b33d197805_s390x |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:3a736c5d770150a34253a1cbd85f83289b7f57fb11de5fd5b54f60267e6b3767_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/kubernetes-nmstate-rhel8-operator@sha256:3a736c5d770150a34253a1cbd85f83289b7f57fb11de5fd5b54f60267e6b3767_ppc64le |
| Red Hat | openshift4/ose-cluster-capacity@sha256:e6be71f0962bc11fdfa94b3347c7fad3139bd73be157d1904d8439cb3a324066_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:85e0e8b3a65d28382b61e690a86434eb89b09991f6c90495372797bfda62c2ea_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:baccbaae5cc255249424e4665cbbe0abdf3d86c3e5055b7da15d948c34918482_s390x as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:cfdb76e8b7b5b4b5470d63e0fa8d3ffeb09011fc50c9f3b43de6a5383ab7c41d_s390x as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:cfdb76e8b7b5b4b5470d63e0fa8d3ffeb09011fc50c9f3b43de6a5383ab7c41d_s390x |
| Red Hat | openshift4/ptp-must-gather-rhel8@sha256:485ee62cd061f15a1ed5098c0c662d8f5b9c9a4634ccc26f9ae27fa5bd2e0606_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ptp-must-gather-rhel8@sha256:485ee62cd061f15a1ed5098c0c662d8f5b9c9a4634ccc26f9ae27fa5bd2e0606_amd64 |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3b12700d1122a6948ae809696069dff8c2c016ff6e4aac3f77edcedc272b178f_s390x as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-local-storage-mustgather-rhel8@sha256:eec4bfd3b27863d79cec89b8e8f4c3867e87d0b0dc377a5ce13f7fe6d6d44e62_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-local-storage-mustgather-rhel8@sha256:eec4bfd3b27863d79cec89b8e8f4c3867e87d0b0dc377a5ce13f7fe6d6d44e62_arm64 |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:c3238f8f38f39733ee9308155936bbd7e574d52a2c1d150f4f2e6f8dd4a79ed6_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/kubernetes-nmstate-rhel8-operator@sha256:c3238f8f38f39733ee9308155936bbd7e574d52a2c1d150f4f2e6f8dd4a79ed6_amd64 |
| Red Hat | openshift4/ose-service-idler-rhel8@sha256:96b0e5d9882d5b54ca6bf17279b8ce5f75362a76d7152d8d21aac345d951a69e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-service-idler-rhel8@sha256:96b0e5d9882d5b54ca6bf17279b8ce5f75362a76d7152d8d21aac345d951a69e_ppc64le |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:3dd39ef3c0b025dc8c9c9ef9d6df3baa5cedc6112f56368ca2cec7b33d197805_s390x as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:c1ac479083431521d52e0dba496ffd8c7ddbaf7347ada1c7fa294b5c1fa9fced_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:c1ac479083431521d52e0dba496ffd8c7ddbaf7347ada1c7fa294b5c1fa9fced_ppc64le |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:ab7c321f4ff6f5307d21e8577e58a9a9264218619729f387ab98754b1c3c49a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-operator-sdk-rhel8@sha256:ab7c321f4ff6f5307d21e8577e58a9a9264218619729f387ab98754b1c3c49a9_ppc64le |
…and 98 more
Timeline
- May 17, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:1327 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2053505 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2161274 issue
- https://issues.redhat.com/browse/OCPBUGS-10381 advisory
- https://issues.redhat.com/browse/OCPBUGS-10702 advisory
- https://issues.redhat.com/browse/OCPBUGS-10729 advisory
- https://issues.redhat.com/browse/OCPBUGS-10782 advisory
- https://issues.redhat.com/browse/OCPBUGS-10896 advisory
- https://issues.redhat.com/browse/OCPBUGS-11065 advisory
- https://issues.redhat.com/browse/OCPBUGS-3057 advisory
- https://issues.redhat.com/browse/OCPBUGS-3624 advisory
- https://issues.redhat.com/browse/OCPBUGS-3671 advisory
- https://issues.redhat.com/browse/OCPBUGS-3679 advisory
- https://issues.redhat.com/browse/OCPBUGS-3682 advisory
- https://issues.redhat.com/browse/OCPBUGS-3683 advisory
- https://issues.redhat.com/browse/OCPBUGS-3689 advisory
- https://issues.redhat.com/browse/OCPBUGS-3707 advisory
- https://issues.redhat.com/browse/OCPBUGS-3745 advisory
…and 26 more