RHSA-2024%3A0664
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-multus-networkpolicy-rhel8@sha256:e847b95a86482b70f99422b9fef644bbd92fa85139fca80fbec6222b43f5f439_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-multus-networkpolicy-rhel8@sha256:e847b95a86482b70f99422b9fef644bbd92fa85139fca80fbec6222b43f5f439_arm64, *, openshift4/ose-multus-networkpolicy-rhel8@sha256:e847b95a86482b70f99422b9fef644bbd92fa85139fca80fbec6222b43f5f439_arm64 |
| Red Hat | openshift4/ose-telemeter@sha256:b9754301aa56d4efa6608da7e0a47ee0bc98fdda3735bb9ca6ee5780f8d77b9e_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-telemeter@sha256:b9754301aa56d4efa6608da7e0a47ee0bc98fdda3735bb9ca6ee5780f8d77b9e_arm64, openshift4/ose-telemeter@sha256:b9754301aa56d4efa6608da7e0a47ee0bc98fdda3735bb9ca6ee5780f8d77b9e_arm64, openshift4/ose-telemeter@sha256:b9754301aa56d4efa6608da7e0a47ee0bc98fdda3735bb9ca6ee5780f8d77b9e_arm64 |
| Red Hat | openshift4/ose-prometheus-alertmanager@sha256:183f258e6371ea073f70382cf2732c78c81a88d7fa72f75494afb36cf7f535c7_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-prometheus-alertmanager@sha256:183f258e6371ea073f70382cf2732c78c81a88d7fa72f75494afb36cf7f535c7_amd64, openshift4/ose-prometheus-alertmanager@sha256:183f258e6371ea073f70382cf2732c78c81a88d7fa72f75494afb36cf7f535c7_amd64, openshift4/ose-prometheus-alertmanager@sha256:183f258e6371ea073f70382cf2732c78c81a88d7fa72f75494afb36cf7f535c7_amd64 |
| Red Hat | openshift4/ose-cluster-capi-rhel8-operator@sha256:5b6e9f85f54e180cf93ae3e0840da4c28e196bd4d1ef27ea3ddfb9b3dc46216f_s390x as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-console@sha256:81fce7f676f68de30f330ee299bb4060f5a698c4678013b0aa3ee30f65b823e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-console@sha256:81fce7f676f68de30f330ee299bb4060f5a698c4678013b0aa3ee30f65b823e0_ppc64le, openshift4/ose-console@sha256:81fce7f676f68de30f330ee299bb4060f5a698c4678013b0aa3ee30f65b823e0_ppc64le |
| Red Hat | openshift4/ose-libvirt-machine-controllers@sha256:244bb20d58a19a90e1584f81d30b920e9b9cefca7d7582161addb00d730b5ae2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-libvirt-machine-controllers@sha256:244bb20d58a19a90e1584f81d30b920e9b9cefca7d7582161addb00d730b5ae2_ppc64le, openshift4/ose-libvirt-machine-controllers@sha256:244bb20d58a19a90e1584f81d30b920e9b9cefca7d7582161addb00d730b5ae2_ppc64le, * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-webhook-rhel8@sha256:90ff2c7e718f2b5cfdea8c799d3c5f9e2c9a01ef5c2acd7db3a30d1a67f1162c_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-csi-driver-shared-resource-webhook-rhel8@sha256:90ff2c7e718f2b5cfdea8c799d3c5f9e2c9a01ef5c2acd7db3a30d1a67f1162c_amd64, openshift4/ose-csi-driver-shared-resource-webhook-rhel8@sha256:90ff2c7e718f2b5cfdea8c799d3c5f9e2c9a01ef5c2acd7db3a30d1a67f1162c_amd64 |
| Red Hat | openshift4/ose-cluster-openshift-controller-manager-operator@sha256:706bf909dcbec65db40277e06931a019b1741f117b498fff74021288d82df957_s390x as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-cluster-openshift-controller-manager-operator@sha256:706bf909dcbec65db40277e06931a019b1741f117b498fff74021288d82df957_s390x, * |
| Red Hat | openshift4/ose-cluster-platform-operators-manager-rhel8@sha256:ea8f97ed701717de26d048ce57b03f966809734e5099c50f71f99ac6378c7a55_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-platform-operators-manager-rhel8@sha256:ea8f97ed701717de26d048ce57b03f966809734e5099c50f71f99ac6378c7a55_ppc64le, *, * |
| Red Hat | openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:39b9f727badbb56b790c87e1ce61aec3b4de272d2be79d4fb0069814ae2236da_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-insights-rhel8-operator@sha256:ce7cf709a4fb7fe0786f7ca38b79ccc538017c51e2d4f2325150cc0683af87a1_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-insights-rhel8-operator@sha256:ce7cf709a4fb7fe0786f7ca38b79ccc538017c51e2d4f2325150cc0683af87a1_s390x, openshift4/ose-insights-rhel8-operator@sha256:ce7cf709a4fb7fe0786f7ca38b79ccc538017c51e2d4f2325150cc0683af87a1_s390x, openshift4/ose-insights-rhel8-operator@sha256:ce7cf709a4fb7fe0786f7ca38b79ccc538017c51e2d4f2325150cc0683af87a1_s390x |
| Red Hat | openshift4/ose-csi-driver-manila-rhel8@sha256:96abe04b2439736523288f09625d479b26e40e2c435fccb1ec5583c6283766b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-csi-driver-manila-rhel8@sha256:96abe04b2439736523288f09625d479b26e40e2c435fccb1ec5583c6283766b7_ppc64le, openshift4/ose-csi-driver-manila-rhel8@sha256:96abe04b2439736523288f09625d479b26e40e2c435fccb1ec5583c6283766b7_ppc64le, openshift4/ose-csi-driver-manila-rhel8@sha256:96abe04b2439736523288f09625d479b26e40e2c435fccb1ec5583c6283766b7_ppc64le |
| Red Hat | openshift4/ose-agent-installer-api-server-rhel8@sha256:a2810bb02833165d9fd14e2b54ae7c105f308d4aa5f3f6539938cb77fafa90b5_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-agent-installer-api-server-rhel8@sha256:a2810bb02833165d9fd14e2b54ae7c105f308d4aa5f3f6539938cb77fafa90b5_amd64, openshift4/ose-agent-installer-api-server-rhel8@sha256:a2810bb02833165d9fd14e2b54ae7c105f308d4aa5f3f6539938cb77fafa90b5_amd64, openshift4/ose-agent-installer-api-server-rhel8@sha256:a2810bb02833165d9fd14e2b54ae7c105f308d4aa5f3f6539938cb77fafa90b5_amd64 |
| Red Hat | openshift4/ose-multus-route-override-cni-rhel8@sha256:3c202fd923be0d5fa2fda6f6ac5c20034076fb8efeb9660ce18ce0142bd974a6_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-multus-route-override-cni-rhel8@sha256:3c202fd923be0d5fa2fda6f6ac5c20034076fb8efeb9660ce18ce0142bd974a6_amd64, * |
| Red Hat | openshift4/ose-kube-proxy@sha256:7d7d427efe5a95d5ccf0163ef81537007169058b7806f556f9d296e4a674d3f1_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-kube-proxy@sha256:7d7d427efe5a95d5ccf0163ef81537007169058b7806f556f9d296e4a674d3f1_amd64, *, openshift4/ose-kube-proxy@sha256:7d7d427efe5a95d5ccf0163ef81537007169058b7806f556f9d296e4a674d3f1_amd64 |
| Red Hat | openshift4/ose-console-operator@sha256:bbc99ebb4ad77797c881b365322164bce13c6fccb44736d921a95b5531cf2a5d_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-console-operator@sha256:bbc99ebb4ad77797c881b365322164bce13c6fccb44736d921a95b5531cf2a5d_arm64, *, openshift4/ose-console-operator@sha256:bbc99ebb4ad77797c881b365322164bce13c6fccb44736d921a95b5531cf2a5d_arm64 |
| Red Hat | openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:7f35e34b07fe70aaebae6b98413a33fc595ee4fd43134a6082246e18ad69ed4e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:7f35e34b07fe70aaebae6b98413a33fc595ee4fd43134a6082246e18ad69ed4e_ppc64le, openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:7f35e34b07fe70aaebae6b98413a33fc595ee4fd43134a6082246e18ad69ed4e_ppc64le, openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:7f35e34b07fe70aaebae6b98413a33fc595ee4fd43134a6082246e18ad69ed4e_ppc64le |
| Red Hat | openshift4/ose-cli-artifacts@sha256:9bb8cbfc31b291a3bc102794f47d3bfdb680fbc17b1e975a0694ef74cdaf7d43_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:387cf3c7bbac80f7a34f32180c36b1433fdba33cf20768c6eeb61486cbbe07ef_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:387cf3c7bbac80f7a34f32180c36b1433fdba33cf20768c6eeb61486cbbe07ef_amd64, *, * |
| Red Hat | openshift4/ose-machine-api-operator@sha256:1823b111660c9d75e049b24d3407bbb4bd2d712646144134cbb1e1ecf0ceb638_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-machine-api-operator@sha256:1823b111660c9d75e049b24d3407bbb4bd2d712646144134cbb1e1ecf0ceb638_amd64, *, openshift4/ose-machine-api-operator@sha256:1823b111660c9d75e049b24d3407bbb4bd2d712646144134cbb1e1ecf0ceb638_amd64 |
…and 1264 more
Timeline
- Feb 8, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:0664 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://issues.redhat.com/browse/OCPBUGS-16008 advisory
- https://issues.redhat.com/browse/OCPBUGS-27144 advisory
- https://issues.redhat.com/browse/OCPBUGS-27443 advisory
- https://issues.redhat.com/browse/OCPBUGS-27840 advisory
- https://issues.redhat.com/browse/OCPBUGS-28598 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0664.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory