RHSA-2023%3A5005
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-cluster-capacity@sha256:e44e087aee91c1acfe7d6e8371afa0fb8b15fb6bb79d2ef9b481ad1fec9afdd6_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/ose-cluster-capacity@sha256:e44e087aee91c1acfe7d6e8371afa0fb8b15fb6bb79d2ef9b481ad1fec9afdd6_amd64, * |
| Red Hat | openshift4/ose-ansible-operator@sha256:23ff614e800a60760894210950d10e849828b0ef047141105796b3493dba0c62_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/ose-ansible-operator@sha256:23ff614e800a60760894210950d10e849828b0ef047141105796b3493dba0c62_arm64, openshift4/ose-ansible-operator@sha256:23ff614e800a60760894210950d10e849828b0ef047141105796b3493dba0c62_arm64 |
| Red Hat | openshift4/ose-node-problem-detector-rhel8@sha256:2e2c6403eb0d67f7467be9c430707ee167bb8d2194ef1e2f031df343f00b29bc_s390x as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:2a0f0527217d6342d4f2ef96748da1cd534305c24f7e62e1eb4fcea6e52eba82_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/ose-egress-http-proxy@sha256:2a0f0527217d6342d4f2ef96748da1cd534305c24f7e62e1eb4fcea6e52eba82_arm64, openshift4/ose-egress-http-proxy@sha256:2a0f0527217d6342d4f2ef96748da1cd534305c24f7e62e1eb4fcea6e52eba82_arm64 |
| Red Hat | openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:c55e814ec85806e5b1e5ea69848eed2b6f3414813cf6f993855d5a1c137b31ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:c55e814ec85806e5b1e5ea69848eed2b6f3414813cf6f993855d5a1c137b31ad_ppc64le, openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:c55e814ec85806e5b1e5ea69848eed2b6f3414813cf6f993855d5a1c137b31ad_ppc64le, openshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:c55e814ec85806e5b1e5ea69848eed2b6f3414813cf6f993855d5a1c137b31ad_ppc64le |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:43b6b6e761a2b6a2b197c35b6845a36118c4f568f97375fb91f49c7b2717fb89_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:43b6b6e761a2b6a2b197c35b6845a36118c4f568f97375fb91f49c7b2717fb89_arm64, openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:43b6b6e761a2b6a2b197c35b6845a36118c4f568f97375fb91f49c7b2717fb89_arm64, openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:43b6b6e761a2b6a2b197c35b6845a36118c4f568f97375fb91f49c7b2717fb89_arm64 |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:6bd0f75271cdbdd8bf7cbe6739729f32fe57eec6c5c1101a2575578da58de5ba_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-operator-sdk-rhel8@sha256:6bd0f75271cdbdd8bf7cbe6739729f32fe57eec6c5c1101a2575578da58de5ba_arm64, *, openshift4/ose-operator-sdk-rhel8@sha256:6bd0f75271cdbdd8bf7cbe6739729f32fe57eec6c5c1101a2575578da58de5ba_arm64 |
| Red Hat | openshift4/ose-ansible-operator@sha256:7b7e6436f6c7d1c0bd95bd747f0a56b75957b2c7a7dc6a6da5f79b826e84199e_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-ansible-operator@sha256:7b7e6436f6c7d1c0bd95bd747f0a56b75957b2c7a7dc6a6da5f79b826e84199e_amd64, *, * |
| Red Hat | openshift4/ose-egress-router@sha256:3691eeed5e178d44411d327a547685f89cb0e1a58753897fea367d339369a470_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-egress-router@sha256:3691eeed5e178d44411d327a547685f89cb0e1a58753897fea367d339369a470_ppc64le, openshift4/ose-egress-router@sha256:3691eeed5e178d44411d327a547685f89cb0e1a58753897fea367d339369a470_ppc64le, openshift4/ose-egress-router@sha256:3691eeed5e178d44411d327a547685f89cb0e1a58753897fea367d339369a470_ppc64le |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:1483d7366638eda5d7b13009021f7f42ece781e6d3ec691d16cb0ae9466468ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:1483d7366638eda5d7b13009021f7f42ece781e6d3ec691d16cb0ae9466468ea_ppc64le, openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:1483d7366638eda5d7b13009021f7f42ece781e6d3ec691d16cb0ae9466468ea_ppc64le |
| Red Hat | openshift4/ose-helm-operator@sha256:b33c3225d7ed9dd7e4b42df40a4b6627f1889c6c4c71872ffe2abd8f30f2c229_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-helm-operator@sha256:b33c3225d7ed9dd7e4b42df40a4b6627f1889c6c4c71872ffe2abd8f30f2c229_s390x, *, openshift4/ose-helm-operator@sha256:b33c3225d7ed9dd7e4b42df40a4b6627f1889c6c4c71872ffe2abd8f30f2c229_s390x |
| Red Hat | openshift4/ose-helm-operator@sha256:c6ac1879d9e5fcb2c671f14ee03f76441a21ded88213e09fa59f9907d0e22bd0_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/ose-helm-operator@sha256:c6ac1879d9e5fcb2c671f14ee03f76441a21ded88213e09fa59f9907d0e22bd0_arm64, openshift4/ose-helm-operator@sha256:c6ac1879d9e5fcb2c671f14ee03f76441a21ded88213e09fa59f9907d0e22bd0_arm64 |
| Red Hat | openshift4/ose-egress-dns-proxy@sha256:98ec26354260a7d7a09322267981f9607814b3067a8311a217beae94f275a742_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ose-egress-router@sha256:90a19339a32b9bea590699a8a5437b015141f8cc692b3b4d43e3e6748d6a7ffe_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-egress-router@sha256:90a19339a32b9bea590699a8a5437b015141f8cc692b3b4d43e3e6748d6a7ffe_s390x, openshift4/ose-egress-router@sha256:90a19339a32b9bea590699a8a5437b015141f8cc692b3b4d43e3e6748d6a7ffe_s390x, openshift4/ose-egress-router@sha256:90a19339a32b9bea590699a8a5437b015141f8cc692b3b4d43e3e6748d6a7ffe_s390x |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:a515bbaf11a14a7c497522d7019cc5196a6035346bac2bc35fb0af20e2386b44_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-egress-http-proxy@sha256:a515bbaf11a14a7c497522d7019cc5196a6035346bac2bc35fb0af20e2386b44_ppc64le, openshift4/ose-egress-http-proxy@sha256:a515bbaf11a14a7c497522d7019cc5196a6035346bac2bc35fb0af20e2386b44_ppc64le, openshift4/ose-egress-http-proxy@sha256:a515bbaf11a14a7c497522d7019cc5196a6035346bac2bc35fb0af20e2386b44_ppc64le |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:49a574305707d8c5134a2280908e21b3a1cea4a6b83a8a2d8b315dfd4504ad24_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-operator-sdk-rhel8@sha256:49a574305707d8c5134a2280908e21b3a1cea4a6b83a8a2d8b315dfd4504ad24_s390x, *, * |
| Red Hat | openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:d6e68c2a07ebf6167a2c7a3c93b73bf9d2648b48e4d5c4050cbecfffd2e7b91b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | *, *, openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:d6e68c2a07ebf6167a2c7a3c93b73bf9d2648b48e4d5c4050cbecfffd2e7b91b_ppc64le |
| Red Hat | openshift4/ose-node-problem-detector-rhel8@sha256:c1cfa9430614051d59e9052984fc997cead2169d9644d7778d11084837b9fcad_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-node-problem-detector-rhel8@sha256:c1cfa9430614051d59e9052984fc997cead2169d9644d7778d11084837b9fcad_ppc64le, *, * |
| Red Hat | openshift4/ose-egress-dns-proxy@sha256:98ec26354260a7d7a09322267981f9607814b3067a8311a217beae94f275a742_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-egress-dns-proxy@sha256:98ec26354260a7d7a09322267981f9607814b3067a8311a217beae94f275a742_ppc64le, openshift4/ose-egress-dns-proxy@sha256:98ec26354260a7d7a09322267981f9607814b3067a8311a217beae94f275a742_ppc64le, openshift4/ose-egress-dns-proxy@sha256:98ec26354260a7d7a09322267981f9607814b3067a8311a217beae94f275a742_ppc64le |
| Red Hat | openshift4/ose-ansible-operator@sha256:d7bf6d2a4a4756d0fbd9c2af65212fa72397ef54d24b2d9987780e4b4feaec1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/ose-ansible-operator@sha256:d7bf6d2a4a4756d0fbd9c2af65212fa72397ef54d24b2d9987780e4b4feaec1c_ppc64le, openshift4/ose-ansible-operator@sha256:d7bf6d2a4a4756d0fbd9c2af65212fa72397ef54d24b2d9987780e4b4feaec1c_ppc64le |
…and 83 more
Timeline
- Oct 31, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 21, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:5005 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://issues.redhat.com/browse/OCPBUGS-10323 advisory
- https://issues.redhat.com/browse/OCPBUGS-10415 advisory
- https://issues.redhat.com/browse/OCPBUGS-10700 advisory
- https://issues.redhat.com/browse/OCPBUGS-10783 advisory
- https://issues.redhat.com/browse/OCPBUGS-10865 advisory
- https://issues.redhat.com/browse/OCPBUGS-10884 advisory
- https://issues.redhat.com/browse/OCPBUGS-12312 advisory
- https://issues.redhat.com/browse/OCPBUGS-12856 advisory
- https://issues.redhat.com/browse/OCPBUGS-13048 advisory
- https://issues.redhat.com/browse/OCPBUGS-13382 advisory
- https://issues.redhat.com/browse/OCPBUGS-13724 advisory
- https://issues.redhat.com/browse/OCPBUGS-13849 advisory
- https://issues.redhat.com/browse/OCPBUGS-13898 advisory
- https://issues.redhat.com/browse/OCPBUGS-14084 advisory
- https://issues.redhat.com/browse/OCPBUGS-14154 advisory
- https://issues.redhat.com/browse/OCPBUGS-14179 advisory
- https://issues.redhat.com/browse/OCPBUGS-14591 advisory
…and 26 more