VDB

RHSA-2023%3A6240

RHSA-2023%3A6240 PUBLISHED CVSS 7.5 HIGH

A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64
Red Hatopenshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, *, *
Red Hatopenshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64, openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64
Red Hatopenshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, *, openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64
Red Hatopenshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64, openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64, *
Go
Red Hatopenshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64, *, openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64
Red Hatopenshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64, openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64, *
Red Hatopenshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, *, *
Red Hatopenshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64, *, openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64
Red Hatopenshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64, openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64
Red Hatopenshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64, openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64, openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64
Red Hatopenshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64, openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64, *

Timeline

  • Nov 1, 2023 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • May 21, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›