VDB
RHSA-2023%3A4090
RHSA-2023%3A4090
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the net/http library of the golang package. This flaw allows an attacker to cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-local-storage-operator@sha256:8b75a6a1e1d28aa934313b8a1d927a27bd7c463719ca3f500daee3bae9c11d06_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-local-storage-operator@sha256:8b75a6a1e1d28aa934313b8a1d927a27bd7c463719ca3f500daee3bae9c11d06_amd64, *, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:ce8aba3ea49011ef0fe3891491c2a3ed4e4a9e0b67e3cf2013ce67110fdff59b_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:ce8aba3ea49011ef0fe3891491c2a3ed4e4a9e0b67e3cf2013ce67110fdff59b_arm64, openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:ce8aba3ea49011ef0fe3891491c2a3ed4e4a9e0b67e3cf2013ce67110fdff59b_arm64, openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:ce8aba3ea49011ef0fe3891491c2a3ed4e4a9e0b67e3cf2013ce67110fdff59b_arm64 |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:ff95b68372db7295c4ffda89570d10707fbd164bce0c917c5e0e6fbf0d60fa98_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/kubernetes-nmstate-rhel8-operator@sha256:ff95b68372db7295c4ffda89570d10707fbd164bce0c917c5e0e6fbf0d60fa98_ppc64le, openshift4/kubernetes-nmstate-rhel8-operator@sha256:ff95b68372db7295c4ffda89570d10707fbd164bce0c917c5e0e6fbf0d60fa98_ppc64le |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:a2fa18ed2a05baf2fa19b7b19cfa82e7e199e41b1b1e741d6211bab2d4970c1e_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-sriov-network-device-plugin@sha256:a2fa18ed2a05baf2fa19b7b19cfa82e7e199e41b1b1e741d6211bab2d4970c1e_arm64, openshift4/ose-sriov-network-device-plugin@sha256:a2fa18ed2a05baf2fa19b7b19cfa82e7e199e41b1b1e741d6211bab2d4970c1e_arm64, openshift4/ose-sriov-network-device-plugin@sha256:a2fa18ed2a05baf2fa19b7b19cfa82e7e199e41b1b1e741d6211bab2d4970c1e_arm64 |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x, openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x |
| Red Hat | openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64, openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64, openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64 |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:2f9ce34c3eb56d20e4e60a74d1d866c22c4466da32096ca9350d01a20cddaf82_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:2f9ce34c3eb56d20e4e60a74d1d866c22c4466da32096ca9350d01a20cddaf82_amd64, openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:2f9ce34c3eb56d20e4e60a74d1d866c22c4466da32096ca9350d01a20cddaf82_amd64, openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:2f9ce34c3eb56d20e4e60a74d1d866c22c4466da32096ca9350d01a20cddaf82_amd64 |
| Red Hat | openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64, *, openshift4/ingress-node-firewall-rhel8-operator@sha256:aad0b1d519abef572d4ce42c3a9a11369738a6eb27a330a28b674f976a28bcd7_amd64 |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:9d02b55f1a8ca1009f2db7d7134db116959da2f60e61b2aa8ff7d4845682b591_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:c77accaf43cf624d4b151ad0eadfc37724d098755cdab6e7b78e92618bba92da_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:c77accaf43cf624d4b151ad0eadfc37724d098755cdab6e7b78e92618bba92da_ppc64le, *, * |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:9d02b55f1a8ca1009f2db7d7134db116959da2f60e61b2aa8ff7d4845682b591_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-sriov-network-operator@sha256:9d02b55f1a8ca1009f2db7d7134db116959da2f60e61b2aa8ff7d4845682b591_ppc64le, openshift4/ose-sriov-network-operator@sha256:9d02b55f1a8ca1009f2db7d7134db116959da2f60e61b2aa8ff7d4845682b591_ppc64le, openshift4/ose-sriov-network-operator@sha256:9d02b55f1a8ca1009f2db7d7134db116959da2f60e61b2aa8ff7d4845682b591_ppc64le |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x, openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x, openshift4/ose-cluster-nfd-operator@sha256:53ff6f9dd71fdce92924860a2fc327b90efae09df11b975aec79bd8df3b7d5a7_s390x |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:3ba3e4be3b4bd6623322dc72ca4872052b489f1bf17b6918b4dce5a83c4e0415_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:3ba3e4be3b4bd6623322dc72ca4872052b489f1bf17b6918b4dce5a83c4e0415_amd64, openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:3ba3e4be3b4bd6623322dc72ca4872052b489f1bf17b6918b4dce5a83c4e0415_amd64, openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:3ba3e4be3b4bd6623322dc72ca4872052b489f1bf17b6918b4dce5a83c4e0415_amd64 |
| Red Hat | openshift4/ose-helm-operator@sha256:4ee134ce7226c8cb99997e94044e4bf93c825d75d3d18e4e06abd10245e94a7a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-helm-operator@sha256:4ee134ce7226c8cb99997e94044e4bf93c825d75d3d18e4e06abd10245e94a7a_ppc64le, openshift4/ose-helm-operator@sha256:4ee134ce7226c8cb99997e94044e4bf93c825d75d3d18e4e06abd10245e94a7a_ppc64le, openshift4/ose-helm-operator@sha256:4ee134ce7226c8cb99997e94044e4bf93c825d75d3d18e4e06abd10245e94a7a_ppc64le |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:282f19603b00baf84b32977c94df8b44e6fdcd5401f3842c16850429f2009084_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/kubernetes-nmstate-rhel8-operator@sha256:282f19603b00baf84b32977c94df8b44e6fdcd5401f3842c16850429f2009084_arm64, openshift4/kubernetes-nmstate-rhel8-operator@sha256:282f19603b00baf84b32977c94df8b44e6fdcd5401f3842c16850429f2009084_arm64, * |
| Red Hat | openshift4/ose-local-storage-diskmaker@sha256:32050e72125b4f4ef682ba320d06f52ed897d151495ca99c2473e3e14588944e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:8924c5daeae9246db1171ca4c65e0c0a879c3e5bee34e319c5a7fb1226212e36_s390x as a component of Red Hat OpenShift Container Platform 4.13 | *, *, openshift4/kubernetes-nmstate-rhel8-operator@sha256:8924c5daeae9246db1171ca4c65e0c0a879c3e5bee34e319c5a7fb1226212e36_s390x |
| Red Hat | openshift4/ose-sriov-cni@sha256:12fb9dab14b0787d15531628672502058e5ce94f8eefd89eb354da4062fa037e_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-sriov-cni@sha256:12fb9dab14b0787d15531628672502058e5ce94f8eefd89eb354da4062fa037e_arm64, openshift4/ose-sriov-cni@sha256:12fb9dab14b0787d15531628672502058e5ce94f8eefd89eb354da4062fa037e_arm64, openshift4/ose-sriov-cni@sha256:12fb9dab14b0787d15531628672502058e5ce94f8eefd89eb354da4062fa037e_arm64 |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:96d959d26acffd7ebd9b8f25714820cda9d6e7999935104d2fe8aedb4f9406da_s390x as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:a2167e4d84106eb050a8cc1fa1ca9d4e55672e98718fd1b999e56e9440bdfaf3_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/ose-cluster-kube-descheduler-operator@sha256:a2167e4d84106eb050a8cc1fa1ca9d4e55672e98718fd1b999e56e9440bdfaf3_ppc64le, * |
…and 311 more
Timeline
- Jul 20, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 20, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:4090 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2161274 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2178358 issue
- https://issues.redhat.com/browse/OCPBUGS-13353 advisory
- https://issues.redhat.com/browse/OCPBUGS-14099 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4090.json advisory
- https://access.redhat.com/security/cve/CVE-2022-41717 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41717 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41717 advisory
- https://go.dev/cl/455635 advisory
- https://go.dev/cl/455717 advisory
- https://go.dev/issue/56350 advisory
- https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ advisory
- https://pkg.go.dev/vuln/GO-2022-1144 advisory
- https://access.redhat.com/security/cve/CVE-2022-41723 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41723 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41723 advisory
- https://github.com/advisories/GHSA-vvpx-j8f3-3w6h advisory
…and 6 more