RHSA-2023:6787: Important: Network Observability security update
Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:6787?
The severity of RHSA-2023:6787 is classified as important due to the potential for denial-of-service attacks.
How do I fix RHSA-2023:6787?
To fix RHSA-2023:6787, update your Go net/http and x/net/http2 packages to the latest versions provided in the security advisory.
What vulnerabilities are addressed in RHSA-2023:6787?
RHSA-2023:6787 addresses vulnerabilities related to excessive workload caused by rapid stream resets in HTTP/2-enabled web servers.
Who is affected by RHSA-2023:6787?
RHSA-2023:6787 affects users of the Go net/http and x/net/http2 libraries that are configured to use HTTP/2.
What kind of attack can RHSA-2023:6787 help mitigate?
RHSA-2023:6787 helps mitigate denial-of-service attacks that exploit rapid stream resets in HTTP/2 protocols.