RHSA-2023%3A6240
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64 |
| Red Hat | openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:9e8bf8dc4ec17aa7ec4f4f668face2dcfb471ff41133cefc52fc59bef5ee9b9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64, openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64 |
| Red Hat | openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64, openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64, * |
| Go | ||
| Red Hat | openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64, *, openshift4/dpdk-base-rhel8@sha256:5ab04febc5ef41b10a293ba1fef03cf9adb1f067a60a473a022124cadbb0dd51_amd64 |
| Red Hat | openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64, openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64, * |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64, *, openshift4/numaresources-rhel8-operator@sha256:1c168573d971f3892d34047957db498545f860a92af23450903949bfa801ca4b_amd64 |
| Red Hat | openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64, openshift4/performance-addon-operator-must-gather-rhel8@sha256:a85c8ccd1a092c755cdc32154fe31c1deeade95d97670218b662486b4943c84b_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64, openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64, openshift4/numaresources-operator-bundle@sha256:b8b1f1486c4195c99fd899fa615257c30a8d29929482af73f5816deb41d2aff6_amd64 |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64, openshift4/cnf-tests-rhel8@sha256:f47a3291819281714e4416e3d5c29096d22230761b029895bab95dcb25499c31_amd64, * |
Timeline
- Nov 1, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 21, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:6240 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6240.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory