RHSA-2023%3A6118
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:d234e14c2c5789d9d00dc64d8b67d699517c647b05f7190aeb624cd21a5cca8c_ppc64le as a component of 8Base-OADP-1.2 | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:d234e14c2c5789d9d00dc64d8b67d699517c647b05f7190aeb624cd21a5cca8c_ppc64le, oadp/oadp-velero-restic-restore-helper-rhel8@sha256:d234e14c2c5789d9d00dc64d8b67d699517c647b05f7190aeb624cd21a5cca8c_ppc64le, oadp/oadp-velero-restic-restore-helper-rhel8@sha256:d234e14c2c5789d9d00dc64d8b67d699517c647b05f7190aeb624cd21a5cca8c_ppc64le |
| Red Hat | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:166cc137856090465797a03844a1ce0c7c5b315917264d1a3c570ff8630c097f_amd64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:166cc137856090465797a03844a1ce0c7c5b315917264d1a3c570ff8630c097f_amd64, oadp/oadp-velero-plugin-for-csi-rhel8@sha256:166cc137856090465797a03844a1ce0c7c5b315917264d1a3c570ff8630c097f_amd64, oadp/oadp-velero-plugin-for-csi-rhel8@sha256:166cc137856090465797a03844a1ce0c7c5b315917264d1a3c570ff8630c097f_amd64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:e2cecef9337f9aba8285a8d917e5cf75e24d93d44197578f93a497eed309d94a_s390x as a component of 8Base-OADP-1.2 | *, *, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:e2cecef9337f9aba8285a8d917e5cf75e24d93d44197578f93a497eed309d94a_s390x |
| Red Hat | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:8ad05b4f05a94234566276f923ac3ef40ecc17d9e4d05821851b20e381d57bae_s390x as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:8ad05b4f05a94234566276f923ac3ef40ecc17d9e4d05821851b20e381d57bae_s390x, oadp/oadp-velero-plugin-for-csi-rhel8@sha256:8ad05b4f05a94234566276f923ac3ef40ecc17d9e4d05821851b20e381d57bae_s390x, * |
| Red Hat | oadp/oadp-velero-plugin-rhel8@sha256:017ae58a715980dfc2b32aa9d1865a7786991ab86a8c17880d142d43fe5188dd_amd64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-rhel8@sha256:017ae58a715980dfc2b32aa9d1865a7786991ab86a8c17880d142d43fe5188dd_amd64, oadp/oadp-velero-plugin-rhel8@sha256:017ae58a715980dfc2b32aa9d1865a7786991ab86a8c17880d142d43fe5188dd_amd64, oadp/oadp-velero-plugin-rhel8@sha256:017ae58a715980dfc2b32aa9d1865a7786991ab86a8c17880d142d43fe5188dd_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:d75d79f906c5385cfd85777780eb85a1750b76b09125d5d6bbb963f8e160ebe2_amd64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:d75d79f906c5385cfd85777780eb85a1750b76b09125d5d6bbb963f8e160ebe2_amd64, *, oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:d75d79f906c5385cfd85777780eb85a1750b76b09125d5d6bbb963f8e160ebe2_amd64 |
| Red Hat | oadp/oadp-volume-snapshot-mover-rhel8@sha256:d1f8e31d8ab726c672f3c53044aa7b563735686968ef0b95686c54171c3faf22_ppc64le as a component of 8Base-OADP-1.2 | oadp/oadp-volume-snapshot-mover-rhel8@sha256:d1f8e31d8ab726c672f3c53044aa7b563735686968ef0b95686c54171c3faf22_ppc64le, *, oadp/oadp-volume-snapshot-mover-rhel8@sha256:d1f8e31d8ab726c672f3c53044aa7b563735686968ef0b95686c54171c3faf22_ppc64le |
| Red Hat | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:da7601aa767656db6edea1eac57f8a891eebbf74155c395b569e2d4ff5d81269_ppc64le as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:da7601aa767656db6edea1eac57f8a891eebbf74155c395b569e2d4ff5d81269_ppc64le, *, oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:da7601aa767656db6edea1eac57f8a891eebbf74155c395b569e2d4ff5d81269_ppc64le |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64 as a component of 8Base-OADP-1.2 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64, *, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64 |
| Red Hat | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64, oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64, oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d98265aa2ddfe8a051e6e332f450ae4007e5f719eb456b2db582fe095f7cb88a_ppc64le as a component of 8Base-OADP-1.2 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d98265aa2ddfe8a051e6e332f450ae4007e5f719eb456b2db582fe095f7cb88a_ppc64le, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d98265aa2ddfe8a051e6e332f450ae4007e5f719eb456b2db582fe095f7cb88a_ppc64le, * |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:66fde1bc2e17380cff5503c81cc0b1e4912c310d4c778d7d3b76835fd1aaf45d_amd64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:66fde1bc2e17380cff5503c81cc0b1e4912c310d4c778d7d3b76835fd1aaf45d_amd64, *, oadp/oadp-velero-restic-restore-helper-rhel8@sha256:66fde1bc2e17380cff5503c81cc0b1e4912c310d4c778d7d3b76835fd1aaf45d_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64, *, * |
| Red Hat | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:d5e564b3d10e44ae21a66f1cbe877b23f55ab397328f4bd168fb4340bbb1569d_arm64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:d5e564b3d10e44ae21a66f1cbe877b23f55ab397328f4bd168fb4340bbb1569d_arm64, oadp/oadp-velero-plugin-for-csi-rhel8@sha256:d5e564b3d10e44ae21a66f1cbe877b23f55ab397328f4bd168fb4340bbb1569d_arm64, oadp/oadp-velero-plugin-for-csi-rhel8@sha256:d5e564b3d10e44ae21a66f1cbe877b23f55ab397328f4bd168fb4340bbb1569d_arm64 |
| Red Hat | oadp/oadp-rhel8-operator@sha256:d610d59b4d11ca019611a80ff929cea304a333c78ae8339a8c24628daa97ccdb_amd64 as a component of 8Base-OADP-1.2 | *, *, oadp/oadp-rhel8-operator@sha256:d610d59b4d11ca019611a80ff929cea304a333c78ae8339a8c24628daa97ccdb_amd64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64 as a component of 8Base-OADP-1.2 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:e2cecef9337f9aba8285a8d917e5cf75e24d93d44197578f93a497eed309d94a_s390x as a component of 8Base-OADP-1.2 | *, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:e2cecef9337f9aba8285a8d917e5cf75e24d93d44197578f93a497eed309d94a_s390x, oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:e2cecef9337f9aba8285a8d917e5cf75e24d93d44197578f93a497eed309d94a_s390x |
| Red Hat | oadp/oadp-velero-rhel8@sha256:e2e8e59932a0b8db365458347161fdd0589c2a533d3eb9b68330b7d3c64af363_arm64 as a component of 8Base-OADP-1.2 | oadp/oadp-velero-rhel8@sha256:e2e8e59932a0b8db365458347161fdd0589c2a533d3eb9b68330b7d3c64af363_arm64, oadp/oadp-velero-rhel8@sha256:e2e8e59932a0b8db365458347161fdd0589c2a533d3eb9b68330b7d3c64af363_arm64, * |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:c34c2a171210bc35bef35c783e9d3989e9426ec00e87c3040c5e5de808e1e90e_arm64 as a component of 8Base-OADP-1.2 | *, *, oadp/oadp-velero-restic-restore-helper-rhel8@sha256:c34c2a171210bc35bef35c783e9d3989e9426ec00e87c3040c5e5de808e1e90e_arm64 |
| Red Hat | oadp/oadp-operator-bundle@sha256:22d1ac29ae9c3b35e4f850cf26cdcbdf61d5630a1a9aeed079c2dc8f46bb7434_amd64 as a component of 8Base-OADP-1.2 | *, oadp/oadp-operator-bundle@sha256:22d1ac29ae9c3b35e4f850cf26cdcbdf61d5630a1a9aeed079c2dc8f46bb7434_amd64, oadp/oadp-operator-bundle@sha256:22d1ac29ae9c3b35e4f850cf26cdcbdf61d5630a1a9aeed079c2dc8f46bb7434_amd64 |
…and 85 more
Timeline
- Oct 25, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 21, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:6118 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6118.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-44487 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-44487 advisory
- https://github.com/dotnet/announcements/issues/277 advisory
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit