RHSA-2023%3A6217
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/numaresources-must-gather-rhel9@sha256:7a1fd13b308320588ed336490e7136ac6f581d43e09acf9628d4a747f1d6257f_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:dc0a4ce29d0797974b9e2b82761e522c10b1d318db423c08a7d5f7c7a44d09f4_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/cnf-tests-rhel8@sha256:dc0a4ce29d0797974b9e2b82761e522c10b1d318db423c08a7d5f7c7a44d09f4_amd64, openshift4/cnf-tests-rhel8@sha256:dc0a4ce29d0797974b9e2b82761e522c10b1d318db423c08a7d5f7c7a44d09f4_amd64 |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:7934f2caf7af7f09ecf808dc86d435e746df74d2de065fdebcd6825f64ccb748_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, openshift4/dpdk-base-rhel8@sha256:7934f2caf7af7f09ecf808dc86d435e746df74d2de065fdebcd6825f64ccb748_amd64 |
| Red Hat | openshift4/noderesourcetopology-scheduler-rhel9@sha256:7824fe71328515ea97d7c539b9f622180e8a51ef63862897819a4a2c4cf16cc7_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:7934f2caf7af7f09ecf808dc86d435e746df74d2de065fdebcd6825f64ccb748_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/dpdk-base-rhel8@sha256:7934f2caf7af7f09ecf808dc86d435e746df74d2de065fdebcd6825f64ccb748_amd64, openshift4/dpdk-base-rhel8@sha256:7934f2caf7af7f09ecf808dc86d435e746df74d2de065fdebcd6825f64ccb748_amd64, openshift4/dpdk-base-rhel8@sha256:7934f2caf7af7f09ecf808dc86d435e746df74d2de065fdebcd6825f64ccb748_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64, openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64, * |
| golang | ||
| Red Hat | openshift4/noderesourcetopology-scheduler-rhel9@sha256:7824fe71328515ea97d7c539b9f622180e8a51ef63862897819a4a2c4cf16cc7_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/noderesourcetopology-scheduler-rhel9@sha256:7824fe71328515ea97d7c539b9f622180e8a51ef63862897819a4a2c4cf16cc7_amd64, openshift4/noderesourcetopology-scheduler-rhel9@sha256:7824fe71328515ea97d7c539b9f622180e8a51ef63862897819a4a2c4cf16cc7_amd64, openshift4/noderesourcetopology-scheduler-rhel9@sha256:7824fe71328515ea97d7c539b9f622180e8a51ef63862897819a4a2c4cf16cc7_amd64 |
| Red Hat | openshift4/numaresources-rhel9-operator@sha256:e827220ff2b07b7acbb716f90d3834da84e66523e2ffa4a282e9f28270b73d19_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-rhel9-operator@sha256:e827220ff2b07b7acbb716f90d3834da84e66523e2ffa4a282e9f28270b73d19_amd64, *, * |
| Red Hat | openshift4/numaresources-must-gather-rhel9@sha256:7a1fd13b308320588ed336490e7136ac6f581d43e09acf9628d4a747f1d6257f_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-must-gather-rhel9@sha256:7a1fd13b308320588ed336490e7136ac6f581d43e09acf9628d4a747f1d6257f_amd64, openshift4/numaresources-must-gather-rhel9@sha256:7a1fd13b308320588ed336490e7136ac6f581d43e09acf9628d4a747f1d6257f_amd64, * |
| Red Hat | openshift4/numaresources-rhel9-operator@sha256:e827220ff2b07b7acbb716f90d3834da84e66523e2ffa4a282e9f28270b73d19_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-rhel9-operator@sha256:e827220ff2b07b7acbb716f90d3834da84e66523e2ffa4a282e9f28270b73d19_amd64, openshift4/numaresources-rhel9-operator@sha256:e827220ff2b07b7acbb716f90d3834da84e66523e2ffa4a282e9f28270b73d19_amd64, openshift4/numaresources-rhel9-operator@sha256:e827220ff2b07b7acbb716f90d3834da84e66523e2ffa4a282e9f28270b73d19_amd64 |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:dc0a4ce29d0797974b9e2b82761e522c10b1d318db423c08a7d5f7c7a44d09f4_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/cnf-tests-rhel8@sha256:dc0a4ce29d0797974b9e2b82761e522c10b1d318db423c08a7d5f7c7a44d09f4_amd64, *, * |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64, openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64, openshift4/numaresources-operator-bundle@sha256:44b1b733592ad126d8e48cfe0230a01552d722505c2a421e3bfe1314dac8d610_amd64 |
Timeline
- Oct 31, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 21, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:6217 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6217.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-44487 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-44487 advisory
- https://github.com/dotnet/announcements/issues/277 advisory
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit