RHSA-2025%3A0014
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the `Rapid Reset Attack` in the Go language packages.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-machine-api-provider-aws-rhel8@sha256:a6bd13d658cd7bcca6360771316e42dabd58e0604eb1ffd2308678c643c6b8c8_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-machine-api-provider-aws-rhel8@sha256:a6bd13d658cd7bcca6360771316e42dabd58e0604eb1ffd2308678c643c6b8c8_amd64, openshift4/ose-machine-api-provider-aws-rhel8@sha256:a6bd13d658cd7bcca6360771316e42dabd58e0604eb1ffd2308678c643c6b8c8_amd64, openshift4/ose-machine-api-provider-aws-rhel8@sha256:a6bd13d658cd7bcca6360771316e42dabd58e0604eb1ffd2308678c643c6b8c8_amd64 |
| Red Hat | openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:a7b06a1f2dc7cdbc412395ad856fc1c392af4e9c6ebc20e05a86685b4a03f9af_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:a7b06a1f2dc7cdbc412395ad856fc1c392af4e9c6ebc20e05a86685b4a03f9af_amd64, openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:a7b06a1f2dc7cdbc412395ad856fc1c392af4e9c6ebc20e05a86685b4a03f9af_amd64, openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:a7b06a1f2dc7cdbc412395ad856fc1c392af4e9c6ebc20e05a86685b4a03f9af_amd64 |
| Red Hat | openshift4/cloud-network-config-controller-rhel8@sha256:8f1bef7169ff498d6d0686b1c38aa6556298087275e396406649f28d95508811_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/cloud-network-config-controller-rhel8@sha256:8f1bef7169ff498d6d0686b1c38aa6556298087275e396406649f28d95508811_amd64, openshift4/cloud-network-config-controller-rhel8@sha256:8f1bef7169ff498d6d0686b1c38aa6556298087275e396406649f28d95508811_amd64, openshift4/cloud-network-config-controller-rhel8@sha256:8f1bef7169ff498d6d0686b1c38aa6556298087275e396406649f28d95508811_amd64 |
| Red Hat | openshift4/ose-prometheus-operator@sha256:7d1c77b9e5f8adc4daf42902aed4ba7c7f1b3cac54a3d6604603888c4236f14b_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-prometheus-operator@sha256:7d1c77b9e5f8adc4daf42902aed4ba7c7f1b3cac54a3d6604603888c4236f14b_amd64, openshift4/ose-prometheus-operator@sha256:7d1c77b9e5f8adc4daf42902aed4ba7c7f1b3cac54a3d6604603888c4236f14b_amd64, * |
| Red Hat | openshift4/ose-operator-registry@sha256:ffc7293787ab1a568b5fbf64c088104d331070fdd329d152c38ed689e8dd0b5b_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-operator-registry@sha256:ffc7293787ab1a568b5fbf64c088104d331070fdd329d152c38ed689e8dd0b5b_amd64, openshift4/ose-operator-registry@sha256:ffc7293787ab1a568b5fbf64c088104d331070fdd329d152c38ed689e8dd0b5b_amd64 |
| Red Hat | openshift4/ose-tests@sha256:4fa5922e060eb008fdd136a9f99bd736522e6bbd054dd82a265a05954cb7cae0_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-tests@sha256:4fa5922e060eb008fdd136a9f99bd736522e6bbd054dd82a265a05954cb7cae0_amd64, openshift4/ose-tests@sha256:4fa5922e060eb008fdd136a9f99bd736522e6bbd054dd82a265a05954cb7cae0_amd64 |
| Red Hat | openshift4/ose-ibm-cloud-controller-manager-rhel8@sha256:76065f7a855404393b124aec4c4583d4b0fb2353148531ed67d7c0c39be0873f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-ibm-cloud-controller-manager-rhel8@sha256:76065f7a855404393b124aec4c4583d4b0fb2353148531ed67d7c0c39be0873f_amd64, openshift4/ose-ibm-cloud-controller-manager-rhel8@sha256:76065f7a855404393b124aec4c4583d4b0fb2353148531ed67d7c0c39be0873f_amd64, openshift4/ose-ibm-cloud-controller-manager-rhel8@sha256:76065f7a855404393b124aec4c4583d4b0fb2353148531ed67d7c0c39be0873f_amd64 |
| Red Hat | openshift4/ose-hyperkube@sha256:e01b279ad6664120eea6a1c24bac7246df5b52ba150a9ca4e5e6fea0151e9811_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-hyperkube@sha256:e01b279ad6664120eea6a1c24bac7246df5b52ba150a9ca4e5e6fea0151e9811_amd64, *, * |
| Red Hat | openshift4/ose-cluster-platform-operators-manager-rhel8@sha256:cb8cdc5b1476f7e57c85792268ed34fc069118f4ef89df9a782c3e9900b0002f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-platform-operators-manager-rhel8@sha256:cb8cdc5b1476f7e57c85792268ed34fc069118f4ef89df9a782c3e9900b0002f_amd64, *, * |
| Red Hat | openshift4/ose-vsphere-csi-driver-rhel8@sha256:ebe8c770ea8fd2d16a631b187c5046dc5f13c760919770562a0ef15f5f6b6457_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-vsphere-csi-driver-rhel8@sha256:ebe8c770ea8fd2d16a631b187c5046dc5f13c760919770562a0ef15f5f6b6457_amd64, openshift4/ose-vsphere-csi-driver-rhel8@sha256:ebe8c770ea8fd2d16a631b187c5046dc5f13c760919770562a0ef15f5f6b6457_amd64, openshift4/ose-vsphere-csi-driver-rhel8@sha256:ebe8c770ea8fd2d16a631b187c5046dc5f13c760919770562a0ef15f5f6b6457_amd64 |
| Red Hat | openshift4/ose-must-gather@sha256:6d6eae7ab126c40390d2c8e91a7a870fe82fbad725eaa22b847b1c4bdfd7473f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-must-gather@sha256:6d6eae7ab126c40390d2c8e91a7a870fe82fbad725eaa22b847b1c4bdfd7473f_amd64, *, openshift4/ose-must-gather@sha256:6d6eae7ab126c40390d2c8e91a7a870fe82fbad725eaa22b847b1c4bdfd7473f_amd64 |
| Red Hat | openshift4/ose-cluster-ingress-operator@sha256:4ca1aa2c417a987835f63c0a966c10536af9b3de32689f8b5943e7210262137c_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-ingress-operator@sha256:4ca1aa2c417a987835f63c0a966c10536af9b3de32689f8b5943e7210262137c_amd64, *, openshift4/ose-cluster-ingress-operator@sha256:4ca1aa2c417a987835f63c0a966c10536af9b3de32689f8b5943e7210262137c_amd64 |
| Red Hat | openshift4/ose-network-metrics-daemon-rhel8@sha256:b39828b0080dc7cc6dcb51796bd1ccb21ba2f60367d5337e7ca7b2cf95f1cd58_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-network-metrics-daemon-rhel8@sha256:b39828b0080dc7cc6dcb51796bd1ccb21ba2f60367d5337e7ca7b2cf95f1cd58_amd64, *, openshift4/ose-network-metrics-daemon-rhel8@sha256:b39828b0080dc7cc6dcb51796bd1ccb21ba2f60367d5337e7ca7b2cf95f1cd58_amd64 |
| Red Hat | openshift4/ose-coredns@sha256:bcc902e718358f2dce33fd7e39d6e92b329b8b907c4b659a516c8c928390e6f6_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/ose-coredns@sha256:bcc902e718358f2dce33fd7e39d6e92b329b8b907c4b659a516c8c928390e6f6_amd64 |
| Red Hat | openshift4/ovirt-csi-driver-rhel8-operator@sha256:703db85316021d023c1c7489a59e847fd36620f2190ca7e7c608876a09d8171d_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ovirt-csi-driver-rhel8-operator@sha256:703db85316021d023c1c7489a59e847fd36620f2190ca7e7c608876a09d8171d_amd64, openshift4/ovirt-csi-driver-rhel8-operator@sha256:703db85316021d023c1c7489a59e847fd36620f2190ca7e7c608876a09d8171d_amd64, * |
| Red Hat | openshift4/ose-keepalived-ipfailover@sha256:db22d4ee21aa3119bb708ebf505626d319c01de50534a904fc0ce2c92dd197c6_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-keepalived-ipfailover@sha256:db22d4ee21aa3119bb708ebf505626d319c01de50534a904fc0ce2c92dd197c6_amd64, openshift4/ose-keepalived-ipfailover@sha256:db22d4ee21aa3119bb708ebf505626d319c01de50534a904fc0ce2c92dd197c6_amd64, openshift4/ose-keepalived-ipfailover@sha256:db22d4ee21aa3119bb708ebf505626d319c01de50534a904fc0ce2c92dd197c6_amd64 |
| Red Hat | openshift4/ose-ironic-rhel9@sha256:d1ba1921a923c4e140f6822228f5a28411e482dd92af0f9b60a187b864143152_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-ironic-rhel9@sha256:d1ba1921a923c4e140f6822228f5a28411e482dd92af0f9b60a187b864143152_amd64, *, openshift4/ose-ironic-rhel9@sha256:d1ba1921a923c4e140f6822228f5a28411e482dd92af0f9b60a187b864143152_amd64 |
| Red Hat | openshift4/ose-console-operator@sha256:46386075ad910e13d2db849a7dd7bb9f1f88d67a5f9b89fb0641220c99563efd_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/ose-console-operator@sha256:46386075ad910e13d2db849a7dd7bb9f1f88d67a5f9b89fb0641220c99563efd_amd64 |
| Red Hat | openshift4/ose-prometheus@sha256:d4a05ccd12b98841dde08a29c673f35331243560b6bdd96deaff862e55362f63_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-container-networking-plugins-rhel8@sha256:f0c55957dbbe9fa64159e647b22736b21f0c6da3b924fbdd96e9666dd0c976d1_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-container-networking-plugins-rhel8@sha256:f0c55957dbbe9fa64159e647b22736b21f0c6da3b924fbdd96e9666dd0c976d1_amd64, *, openshift4/ose-container-networking-plugins-rhel8@sha256:f0c55957dbbe9fa64159e647b22736b21f0c6da3b924fbdd96e9666dd0c976d1_amd64 |
…and 362 more
Timeline
- Jan 9, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:0014 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2295777 issue
- https://issues.redhat.com/browse/OCPBUGS-45291 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0014.json advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://go.dev/issue/63417 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory
- https://access.redhat.com/security/cve/CVE-2024-6508 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6508 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6508 advisory