First published: Wed Nov 01 2023(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>This advisory contains OpenShift Virtualization 4.11.7 images.<br>Security Fix(es):<br><li> golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)</li> <li> HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)</li> <li> net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> 4.11.7 containers (BZ#2246329)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Virtualization |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:6251 is labeled as important.
To fix RHSA-2023:6251, you should update to the OpenShift Virtualization 4.11.7 images.
RHSA-2023:6251 affects Red Hat OpenShift Virtualization.
RHSA-2023:6251 addresses a vulnerability in the net/http and x/net/http2 packages related to rapid stream resets.
RHSA-2023:6251 was released on October 18, 2023.