RHSA-2025%3A23529
A flaw was found in handling multiplexed streams in the HTTP/2 protocol. A client can repeatedly make a request for a new multiplex stream and immediately send an RST_STREAM frame to cancel it. This creates extra work for the server setting up and tearing down the streams while not hitting any server-side limit for the maximum number of active streams per connection, resulting in a denial of service due to server resource consumption. Red Hat has rated the severity of this flaw as 'Important' as the US Cybersecurity and Infrastructure Security Agency (CISA) declared this vulnerability an active exploit. CVE-2023-39325 was assigned for the Rapid Reset Attack in the Go language packages. Security Bulletin https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:8e8461f4865de8d6b742f3f25d1d7926517cec1e41e5d61e98c0e0a6d6f97176_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | * |
| Red Hat | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:e4a59fa9706305e2a77d7e40fe1836f2b6e11b1f86aa573f3b9623df6a625b1f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:e4a59fa9706305e2a77d7e40fe1836f2b6e11b1f86aa573f3b9623df6a625b1f_s390x |
| Red Hat | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6b5f0997888832eba63d67bf802128eb15f7cb178b082f090b95db4224a3bc5d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6b5f0997888832eba63d67bf802128eb15f7cb178b082f090b95db4224a3bc5d_arm64 |
| Red Hat | registry.redhat.io/rhacm2/thanos-rhel9@sha256:47ed82f649ebb29dac79d7c336da8d74f07b18bbcfe132d1b82dcefb9db5b891_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/thanos-rhel9@sha256:47ed82f649ebb29dac79d7c336da8d74f07b18bbcfe132d1b82dcefb9db5b891_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:83cc5d04c8df7b43d394995d7babaa907f955dd988eaa06ed1e3f69d8aca16fb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:83cc5d04c8df7b43d394995d7babaa907f955dd988eaa06ed1e3f69d8aca16fb_s390x |
| Red Hat | registry.redhat.io/rhacm2/multicloud-integrations-rhel9@sha256:7615d0d20ab5dd4cc1f3b0c4dbdc5f54e0d43c83f3009328913e5cbaf234a726_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | * |
| Red Hat | registry.redhat.io/rhacm2/insights-metrics-rhel9@sha256:17175be42fa40e15935307d238b5d520c58037d17f493ed2afd595c42b3beed0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/insights-metrics-rhel9@sha256:17175be42fa40e15935307d238b5d520c58037d17f493ed2afd595c42b3beed0_amd64 |
| Red Hat | registry.redhat.io/rhacm2/observatorium-rhel9-operator@sha256:3ec940bd155f08eee307c21d927e31ec4b07f037048f79b2fe24943860330069_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/observatorium-rhel9-operator@sha256:3ec940bd155f08eee307c21d927e31ec4b07f037048f79b2fe24943860330069_s390x |
| Red Hat | registry.redhat.io/rhacm2/endpoint-monitoring-rhel9-operator@sha256:fb9ba4d9d87806781a376867cd2d174250e4b6cc77c9284928cbb114d67ea12b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/endpoint-monitoring-rhel9-operator@sha256:fb9ba4d9d87806781a376867cd2d174250e4b6cc77c9284928cbb114d67ea12b_amd64 |
| Red Hat | registry.redhat.io/rhacm2/rbac-query-proxy-rhel9@sha256:606aa03b6693cf6535361609bac9c9535f633641a216dfce86d4e96201fb9f48_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/rbac-query-proxy-rhel9@sha256:606aa03b6693cf6535361609bac9c9535f633641a216dfce86d4e96201fb9f48_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/rbac-query-proxy-rhel9@sha256:6c14c2fd5430650fd253313f739de87e0a81032b58f2f97df86654fd14587c99_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/rbac-query-proxy-rhel9@sha256:6c14c2fd5430650fd253313f739de87e0a81032b58f2f97df86654fd14587c99_amd64 |
| Red Hat | registry.redhat.io/rhacm2/observatorium-rhel9@sha256:7424235a185bb4b11556d6d7478a15a9793b33a30d265c28563ff654e14b4ec9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/observatorium-rhel9@sha256:7424235a185bb4b11556d6d7478a15a9793b33a30d265c28563ff654e14b4ec9_amd64 |
| Red Hat | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9b72a0f4d070bdeb75c6b037b9f05d3d025c638f896716e59d598ff1e83334ad_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9b72a0f4d070bdeb75c6b037b9f05d3d025c638f896716e59d598ff1e83334ad_amd64 |
| Red Hat | registry.redhat.io/rhacm2/prometheus-alertmanager-rhel9@sha256:553083aebfd0f1fa2384417067dedc011ab24b60f881fbdca0a40046f3f14961_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/prometheus-alertmanager-rhel9@sha256:553083aebfd0f1fa2384417067dedc011ab24b60f881fbdca0a40046f3f14961_s390x |
| Red Hat | registry.redhat.io/rhacm2/config-policy-controller-rhel9@sha256:f1295e3ecd79f7c370ac946828dbdcbe28b8d2d3760a93b050fcc6fdda0634b3_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | * |
| Red Hat | registry.redhat.io/rhacm2/observatorium-rhel9-operator@sha256:2809bc415646a1e333875516cdac02baa608b67bd1e600ed9e59a106c020c055_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/observatorium-rhel9-operator@sha256:2809bc415646a1e333875516cdac02baa608b67bd1e600ed9e59a106c020c055_amd64 |
| Red Hat | registry.redhat.io/rhacm2/grafana-dashboard-loader-rhel9@sha256:ba48845c70f465b250c48938d7606c2ea868620870c8b6443f322b5565a6b6f4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/grafana-dashboard-loader-rhel9@sha256:ba48845c70f465b250c48938d7606c2ea868620870c8b6443f322b5565a6b6f4_amd64 |
| Red Hat | registry.redhat.io/rhacm2/insights-client-rhel9@sha256:aeb6d1766178eecefc78e50691354e6a5e8193d4110911dbe33bccf04f574f8c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | * |
| Red Hat | registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ae4841cd71e614cce07c9b7dfbe548e3690257a232bb768abccafb75e5c29031_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ae4841cd71e614cce07c9b7dfbe548e3690257a232bb768abccafb75e5c29031_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/submariner-addon-rhel9@sha256:3e71aef1e4943dd7cd915fe784c064f069ec390b781ae9e0f1257f46496788c0_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11 | registry.redhat.io/rhacm2/submariner-addon-rhel9@sha256:3e71aef1e4943dd7cd915fe784c064f069ec390b781ae9e0f1257f46496788c0_ppc64le |
…and 144 more
Timeline
- Dec 17, 2025 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:23529 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://access.redhat.com/security/cve/CVE-2025-7195 advisory
- https://access.redhat.com/security/cve/CVE-2025-7783 advisory
- https://access.redhat.com/security/cve/CVE-2025-9287 advisory
- https://access.redhat.com/security/cve/CVE-2025-9288 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23529.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803 issue
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-44487 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-44487 advisory
- https://github.com/dotnet/announcements/issues/277 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=2376300 issue
- https://www.cve.org/CVERecord?id=CVE-2025-7195 advisory
…and 16 more