RHSA-2023%3A6280
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64, mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64, * |
| Red Hat | mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64, mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64, mta/mta-operator-bundle@sha256:2660d6e04d2f6475565999b41947e1b5e615beb6a4f82e596e21f947f0963866_amd64 |
| Red Hat | mta/mta-hub-rhel9@sha256:ab08ff12c34082722cb6ea3bdf3c62f99d30efb469570938400ebdd9b6e4b4b5_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-hub-rhel9@sha256:ab08ff12c34082722cb6ea3bdf3c62f99d30efb469570938400ebdd9b6e4b4b5_amd64, *, mta/mta-hub-rhel9@sha256:ab08ff12c34082722cb6ea3bdf3c62f99d30efb469570938400ebdd9b6e4b4b5_amd64 |
| golang | Go | |
| Red Hat | mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64, mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64, mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64 |
| Red Hat | mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64, mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64, * |
| Red Hat | mta/mta-hub-rhel9@sha256:ab08ff12c34082722cb6ea3bdf3c62f99d30efb469570938400ebdd9b6e4b4b5_amd64 as a component of MTA 6.2 for RHEL 8 | *, mta/mta-hub-rhel9@sha256:ab08ff12c34082722cb6ea3bdf3c62f99d30efb469570938400ebdd9b6e4b4b5_amd64, * |
| Red Hat | mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64, *, mta/mta-windup-addon-rhel9@sha256:8235d925582c44ea38fce014c14a4b674ae99bdf90440d7d1e9b552f4dd67069_amd64 |
| Red Hat | mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64, mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64, * |
| Red Hat | mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64, mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64, mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64 |
| Red Hat | mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64, mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64, mta/mta-pathfinder-rhel9@sha256:210453bf83f0906897220af8b027215c14099dd72a88af35154165ea295e6864_amd64 |
| Red Hat | mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64 as a component of MTA 6.2 for RHEL 8 | *, mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64, mta/mta-rhel8-operator@sha256:a044ecc125e34bbdc41c5926b9bb49cf233c534618367e1bd57d24d4b54164fb_amd64 |
| Red Hat | mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64 as a component of MTA 6.2 for RHEL 8 | mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64, mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64, mta/mta-ui-rhel9@sha256:a82420cc54e8e8cdd0d8905d4f8ef1167bfd16cd474c09f0146ed756a6fac0dc_amd64 |
Timeline
- Nov 2, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 21, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:6280 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://issues.redhat.com/browse/MTA-1365 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6280.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-44487 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-44487 advisory
- https://github.com/dotnet/announcements/issues/277 advisory
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit