RHSA-2023%3A6125
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-egress-router@sha256:11e6e3e7f0c1acfb7cfa22abcdf080895ff32f9b9e2098a460a5184488839755_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-egress-router@sha256:11e6e3e7f0c1acfb7cfa22abcdf080895ff32f9b9e2098a460a5184488839755_arm64, openshift4/ose-egress-router@sha256:11e6e3e7f0c1acfb7cfa22abcdf080895ff32f9b9e2098a460a5184488839755_arm64, openshift4/ose-egress-router@sha256:11e6e3e7f0c1acfb7cfa22abcdf080895ff32f9b9e2098a460a5184488839755_arm64 |
| Red Hat | openshift4/ose-local-storage-operator@sha256:ca5e2c36082af4a69f458f561292fa5ef9cc20a0da89692b870e6425ade87372_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-local-storage-operator@sha256:ca5e2c36082af4a69f458f561292fa5ef9cc20a0da89692b870e6425ade87372_amd64, openshift4/ose-local-storage-operator@sha256:ca5e2c36082af4a69f458f561292fa5ef9cc20a0da89692b870e6425ade87372_amd64 |
| Red Hat | openshift4/ose-local-storage-diskmaker@sha256:048d65a539e642debaf066f508ee1ebef02a5d6e9c4d84c83ba4def21933f772_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:0f8323577f8e994f55815b9bfbe6bcab65aee32c4f6f8ff5e24bb9412da0f748_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-operator-sdk-rhel8@sha256:0f8323577f8e994f55815b9bfbe6bcab65aee32c4f6f8ff5e24bb9412da0f748_amd64, openshift4/ose-operator-sdk-rhel8@sha256:0f8323577f8e994f55815b9bfbe6bcab65aee32c4f6f8ff5e24bb9412da0f748_amd64, openshift4/ose-operator-sdk-rhel8@sha256:0f8323577f8e994f55815b9bfbe6bcab65aee32c4f6f8ff5e24bb9412da0f748_amd64 |
| Red Hat | openshift4/ose-cloud-event-proxy@sha256:907898f366a60aeedbb9013f877f6ade1da6463f878ca578d0c979e5e22430f7_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cloud-event-proxy@sha256:907898f366a60aeedbb9013f877f6ade1da6463f878ca578d0c979e5e22430f7_amd64, openshift4/ose-cloud-event-proxy@sha256:907898f366a60aeedbb9013f877f6ade1da6463f878ca578d0c979e5e22430f7_amd64, openshift4/ose-cloud-event-proxy@sha256:907898f366a60aeedbb9013f877f6ade1da6463f878ca578d0c979e5e22430f7_amd64 |
| Red Hat | openshift4/dpu-network-rhel8-operator@sha256:f4839ae599f27b4920d9657ac0d4f7ff51550b00910cd129b44b4774c88bd445_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/dpu-network-rhel8-operator@sha256:f4839ae599f27b4920d9657ac0d4f7ff51550b00910cd129b44b4774c88bd445_arm64 |
| Red Hat | openshift4/ose-ansible-operator@sha256:0cc558c0f4fd929c94c9d9883adfbddb12f0eed3f73c4a5dcdcaa8309ea3d351_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-ansible-operator@sha256:0cc558c0f4fd929c94c9d9883adfbddb12f0eed3f73c4a5dcdcaa8309ea3d351_s390x, openshift4/ose-ansible-operator@sha256:0cc558c0f4fd929c94c9d9883adfbddb12f0eed3f73c4a5dcdcaa8309ea3d351_s390x, openshift4/ose-ansible-operator@sha256:0cc558c0f4fd929c94c9d9883adfbddb12f0eed3f73c4a5dcdcaa8309ea3d351_s390x |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:46c40f648d361cbbacfe263419836678e9781ea43ea4b9cdb5fc21602905342c_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:46c40f648d361cbbacfe263419836678e9781ea43ea4b9cdb5fc21602905342c_arm64, openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:46c40f648d361cbbacfe263419836678e9781ea43ea4b9cdb5fc21602905342c_arm64, openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:46c40f648d361cbbacfe263419836678e9781ea43ea4b9cdb5fc21602905342c_arm64 |
| Red Hat | openshift4/ose-egress-router@sha256:8571d058b2ddc5d8cbe52f76c724b24632fbc9dd5387b0cb7d9981e5a4adacb2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-egress-router@sha256:8571d058b2ddc5d8cbe52f76c724b24632fbc9dd5387b0cb7d9981e5a4adacb2_ppc64le, *, * |
| Red Hat | openshift4/ose-local-storage-operator@sha256:c616581f3532fe81a8c52efe4de158bd18c72366c9e0e63cf30c4b4330c8fc5f_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-local-storage-operator@sha256:c616581f3532fe81a8c52efe4de158bd18c72366c9e0e63cf30c4b4330c8fc5f_arm64, *, * |
| Red Hat | openshift4/ose-cluster-capacity@sha256:21924ac6078166fe76f0289569ec3492a12887e422b07d697ec10749ba661021_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-capacity@sha256:21924ac6078166fe76f0289569ec3492a12887e422b07d697ec10749ba661021_ppc64le, openshift4/ose-cluster-capacity@sha256:21924ac6078166fe76f0289569ec3492a12887e422b07d697ec10749ba661021_ppc64le, openshift4/ose-cluster-capacity@sha256:21924ac6078166fe76f0289569ec3492a12887e422b07d697ec10749ba661021_ppc64le |
| Red Hat | openshift4/ose-ptp@sha256:778c804ebffd5499fb4a889f15c23abaf33e48b1d3bf6b58af91e88f41d47917_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-ptp@sha256:778c804ebffd5499fb4a889f15c23abaf33e48b1d3bf6b58af91e88f41d47917_amd64, openshift4/ose-ptp@sha256:778c804ebffd5499fb4a889f15c23abaf33e48b1d3bf6b58af91e88f41d47917_amd64, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:2c5e09740416d672580aafe209a6813b43f4b82c824d31224d5bd3843600c50b_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:2c5e09740416d672580aafe209a6813b43f4b82c824d31224d5bd3843600c50b_arm64, *, * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:279569b6be136d06f93a5ed0e6a4105f2166b4bc93ebf558e3a77954f22ba8e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:279569b6be136d06f93a5ed0e6a4105f2166b4bc93ebf558e3a77954f22ba8e8_ppc64le |
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:74289a3e22c121d6a0712586bc12cc437bf4c86b1b34ffc0ffd27463b8ad3bfc_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:74289a3e22c121d6a0712586bc12cc437bf4c86b1b34ffc0ffd27463b8ad3bfc_arm64, *, openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:74289a3e22c121d6a0712586bc12cc437bf4c86b1b34ffc0ffd27463b8ad3bfc_arm64 |
| Red Hat | openshift4/ose-egress-router@sha256:11e6e3e7f0c1acfb7cfa22abcdf080895ff32f9b9e2098a460a5184488839755_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-egress-router@sha256:11e6e3e7f0c1acfb7cfa22abcdf080895ff32f9b9e2098a460a5184488839755_arm64, * |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:ca2b78e1dc3d807d0655a45dca6d5fc6630937ce3758b156acb1b3a2395b39fc_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-operator-sdk-rhel8@sha256:ca2b78e1dc3d807d0655a45dca6d5fc6630937ce3758b156acb1b3a2395b39fc_s390x, openshift4/ose-operator-sdk-rhel8@sha256:ca2b78e1dc3d807d0655a45dca6d5fc6630937ce3758b156acb1b3a2395b39fc_s390x, openshift4/ose-operator-sdk-rhel8@sha256:ca2b78e1dc3d807d0655a45dca6d5fc6630937ce3758b156acb1b3a2395b39fc_s390x |
| Red Hat | openshift4/frr-rhel8@sha256:6374cd34eaf01275f2eaf613dfef7528ec8590e3477b022aa588cb63f1db67aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/frr-rhel8@sha256:6374cd34eaf01275f2eaf613dfef7528ec8590e3477b022aa588cb63f1db67aa_ppc64le, openshift4/frr-rhel8@sha256:6374cd34eaf01275f2eaf613dfef7528ec8590e3477b022aa588cb63f1db67aa_ppc64le, openshift4/frr-rhel8@sha256:6374cd34eaf01275f2eaf613dfef7528ec8590e3477b022aa588cb63f1db67aa_ppc64le |
| Red Hat | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:c26534ba1547ee25524e4a166243ef02f1487b1952d5f23182ce79fd34e427f1_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:c26534ba1547ee25524e4a166243ef02f1487b1952d5f23182ce79fd34e427f1_amd64, openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:c26534ba1547ee25524e4a166243ef02f1487b1952d5f23182ce79fd34e427f1_amd64, * |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel8@sha256:c29ea460add0eb57d8a060f5a1c5b69ba08bada849e5aab554d7d308a9958d85_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cloud-event-proxy-rhel8@sha256:c29ea460add0eb57d8a060f5a1c5b69ba08bada849e5aab554d7d308a9958d85_arm64, openshift4/ose-cloud-event-proxy-rhel8@sha256:c29ea460add0eb57d8a060f5a1c5b69ba08bada849e5aab554d7d308a9958d85_arm64, openshift4/ose-cloud-event-proxy-rhel8@sha256:c29ea460add0eb57d8a060f5a1c5b69ba08bada849e5aab554d7d308a9958d85_arm64 |
…and 327 more
Timeline
- Nov 1, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 21, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:6125 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6125.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory