Bug 2268273 (CVE-2023-45288, VU#421644.3)
| Summary: | CVE-2023-45288 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Nick Tait <ntait> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, abishop, adudiak, akostadi, alcohan, amasferr, amctagga, anjoseph, ansmith, aoconnor, asherlan, asriram, bdettelb, bniver, bodavis, brking, cbartlet, chazlett, cmah, danken, dbenoit, deads, dfreiber, dhanak, dhellmann, dholler, dkenigsb, dmayorov, doconnor, dperaza, drow, dsimansk, dymurray, eaguilar, ebaron, eglynn, emachado, epacific, fdeutsch, flucifre, ganandan, gandhi.srini, ggiguash, gkamathe, gmeno, gparvin, haoli, hhorak, hkataria, ibolton, jaharrin, jajackso, jburrell, jcammara, jcantril, jchaloup, jchui, jeder, jhardy, jjoyce, jkang, jlledo, jmatthew, jmitchel, jmontleo, jneedle, jobarker, joelsmith, jolong, jorton, jpallich, jprabhak, jschluet, jwendell, kaycoth, kegrant, kholdawa, kingland, koliveir, kshier, ktsao, kverlaen, lbainbri, lcouzens, lgamliel, lhh, lmadsen, lsvaty, mabashia, matzew, mbenjamin, mburns, mgarciac, mgeary, mhackett, mmagr, mmakovy, mnewsome, mnovotny, mrunge, mskarbek, muagarwa, mwringe, nboldt, nigoyal, njean, nobody, omaciel, oourfali, opohorel, oramraz, owatkins, pahickey, pbraun, pdiak, peholase, pgaikwad, pgrist, phoracek, pierdipi, pjindal, rcernich, rfreiman, rgatica, rguimara, rhaigner, rhos-maint, rhuss, rjohnson, rojacob, sakbas, saroy, sausingh, sdawley, security-response-team, sfroberg, shbose, shvarugh, sidakwo, simaishi, sipoyare, slucidi, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, teagle, tfister, thason, thavo, tjochec, tsweeney, twalsh, vereddy, vimartin, vkumar, whayutin, wtam, yguenane, zmiele, zsadeh |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | golang 1.22.2, golang 1.21.9, golang.org/x/net 0.23.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2269449, 2269451, 2269452, 2269453, 2269415, 2269416, 2269417, 2269419, 2269447, 2269450, 2269454, 2269455, 2269456, 2269457, 2269458, 2269459, 2269460, 2269853, 2276081, 2276082, 2306525 | ||
| Bug Blocks: | 2268258 | ||
|
Description
Nick Tait
2024-03-06 20:49:42 UTC
Is this http and http2 or http2 only? The title says HTTP, but the description is all http2. If it's http2, then it's likely the container tools don't have an issue as we're HTTP based. This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:1668 https://access.redhat.com/errata/RHSA-2024:1668 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:1679 https://access.redhat.com/errata/RHSA-2024:1679 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:1681 https://access.redhat.com/errata/RHSA-2024:1681 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:1683 https://access.redhat.com/errata/RHSA-2024:1683 We are from a product team which provides security fix every month. The above CVE is reported against RedHat UBI minimal 8.9 level. And we are expected to fix this by 5th of May. It is blocking our releases. Can you please let us now when it will be fixed. Thanks & Regards, Gandhi. IBM MQ Container Security Lead. This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1963 https://access.redhat.com/errata/RHSA-2024:1963 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1962 https://access.redhat.com/errata/RHSA-2024:1962 This issue has been addressed in the following products: RHEL-9-CNV-4.14 Via RHSA-2024:2060 https://access.redhat.com/errata/RHSA-2024:2060 This issue has been addressed in the following products: STF-1.5-RHEL-8 Via RHSA-2024:2062 https://access.redhat.com/errata/RHSA-2024:2062 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:1899 https://access.redhat.com/errata/RHSA-2024:1899 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:1892 https://access.redhat.com/errata/RHSA-2024:1892 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:1897 https://access.redhat.com/errata/RHSA-2024:1897 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2079 https://access.redhat.com/errata/RHSA-2024:2079 This issue has been addressed in the following products: Cryostat 2 on RHEL 8 Via RHSA-2024:2088 https://access.redhat.com/errata/RHSA-2024:2088 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2562 https://access.redhat.com/errata/RHSA-2024:2562 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2024:2625 https://access.redhat.com/errata/RHSA-2024:2625 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:2068 https://access.redhat.com/errata/RHSA-2024:2068 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:2049 https://access.redhat.com/errata/RHSA-2024:2049 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:2699 https://access.redhat.com/errata/RHSA-2024:2699 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2724 https://access.redhat.com/errata/RHSA-2024:2724 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:2664 https://access.redhat.com/errata/RHSA-2024:2664 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:2667 https://access.redhat.com/errata/RHSA-2024:2667 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:2668 https://access.redhat.com/errata/RHSA-2024:2668 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:2672 https://access.redhat.com/errata/RHSA-2024:2672 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:2671 https://access.redhat.com/errata/RHSA-2024:2671 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:2773 https://access.redhat.com/errata/RHSA-2024:2773 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:2782 https://access.redhat.com/errata/RHSA-2024:2782 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:2936 https://access.redhat.com/errata/RHSA-2024:2936 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:2935 https://access.redhat.com/errata/RHSA-2024:2935 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:2865 https://access.redhat.com/errata/RHSA-2024:2865 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.4 Via RHSA-2024:2941 https://access.redhat.com/errata/RHSA-2024:2941 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3259 https://access.redhat.com/errata/RHSA-2024:3259 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2024:2729 https://access.redhat.com/errata/RHSA-2024:2729 This issue has been addressed in the following products: RHOL-5.9-RHEL-9 Via RHSA-2024:2933 https://access.redhat.com/errata/RHSA-2024:2933 This issue has been addressed in the following products: RHEL-9-CNV-4.15 Via RHSA-2024:3314 https://access.redhat.com/errata/RHSA-2024:3314 This issue has been addressed in the following products: MTA-7.0-RHEL-9 MTA-7.0-RHEL-8 Via RHSA-2024:3316 https://access.redhat.com/errata/RHSA-2024:3316 This issue has been addressed in the following products: RHEL-9-CNV-4.13 Via RHSA-2024:3315 https://access.redhat.com/errata/RHSA-2024:3315 This issue has been addressed in the following products: RHOL-5.6-RHEL-8 Via RHSA-2024:2929 https://access.redhat.com/errata/RHSA-2024:2929 This issue has been addressed in the following products: RHOL-5.8-RHEL-9 Via RHSA-2024:2932 https://access.redhat.com/errata/RHSA-2024:2932 This issue has been addressed in the following products: RHOL-5.7-RHEL-8 Via RHSA-2024:2930 https://access.redhat.com/errata/RHSA-2024:2930 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2024:3352 https://access.redhat.com/errata/RHSA-2024:3352 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3346 https://access.redhat.com/errata/RHSA-2024:3346 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:2875 https://access.redhat.com/errata/RHSA-2024:2875 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2024:3467 https://access.redhat.com/errata/RHSA-2024:3467 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:3327 https://access.redhat.com/errata/RHSA-2024:3327 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2024:2728 https://access.redhat.com/errata/RHSA-2024:2728 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2024:3479 https://access.redhat.com/errata/RHSA-2024:3479 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:3331 https://access.redhat.com/errata/RHSA-2024:3331 This issue has been addressed in the following products: Red Hat Openshift distributed tracing 3.2 Via RHSA-2024:3621 https://access.redhat.com/errata/RHSA-2024:3621 This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.4 for RHEL 8 Via RHSA-2024:3680 https://access.redhat.com/errata/RHSA-2024:3680 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:3523 https://access.redhat.com/errata/RHSA-2024:3523 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2024:3781 https://access.redhat.com/errata/RHSA-2024:3781 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:3889 https://access.redhat.com/errata/RHSA-2024:3889 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:3885 https://access.redhat.com/errata/RHSA-2024:3885 This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2024:4023 https://access.redhat.com/errata/RHSA-2024:4023 This issue has been addressed in the following products: Service Interconnect 1 for RHEL 9 Via RHSA-2024:4034 https://access.redhat.com/errata/RHSA-2024:4034 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:4010 https://access.redhat.com/errata/RHSA-2024:4010 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:4041 https://access.redhat.com/errata/RHSA-2024:4041 This issue has been addressed in the following products: Service Interconnect 1.4 for RHEL 8 Service Interconnect 1.4 for RHEL 9 Via RHSA-2024:4125 https://access.redhat.com/errata/RHSA-2024:4125 This issue has been addressed in the following products: Service Interconnect 1.4 for RHEL 9 Via RHSA-2024:4126 https://access.redhat.com/errata/RHSA-2024:4126 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:4146 https://access.redhat.com/errata/RHSA-2024:4146 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:4006 https://access.redhat.com/errata/RHSA-2024:4006 This issue has been addressed in the following products: RODOO-1.1-RHEL-9 Via RHSA-2024:1616 https://access.redhat.com/errata/RHSA-2024:1616 This issue has been addressed in the following products: OSSO-1.3-RHEL-9 Via RHSA-2024:3637 https://access.redhat.com/errata/RHSA-2024:3637 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2024:4543 https://access.redhat.com/errata/RHSA-2024:4543 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:4546 https://access.redhat.com/errata/RHSA-2024:4546 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:4545 https://access.redhat.com/errata/RHSA-2024:4545 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:4484 https://access.redhat.com/errata/RHSA-2024:4484 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:4677 https://access.redhat.com/errata/RHSA-2024:4677 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:4699 https://access.redhat.com/errata/RHSA-2024:4699 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.8 for RHEL 8 Via RHSA-2024:4922 https://access.redhat.com/errata/RHSA-2024:4922 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2024:4933 https://access.redhat.com/errata/RHSA-2024:4933 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:4934 https://access.redhat.com/errata/RHSA-2024:4934 This issue has been addressed in the following products: OADP-1.3-RHEL-9 Via RHSA-2024:4982 https://access.redhat.com/errata/RHSA-2024:4982 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:4960 https://access.redhat.com/errata/RHSA-2024:4960 This issue has been addressed in the following products: OPENSHIFT-BUILDS-1.1-RHEL-8 Via RHSA-2024:6221 https://access.redhat.com/errata/RHSA-2024:6221 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2024:6004 https://access.redhat.com/errata/RHSA-2024:6004 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:6406 https://access.redhat.com/errata/RHSA-2024:6406 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:6642 https://access.redhat.com/errata/RHSA-2024:6642 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:6811 https://access.redhat.com/errata/RHSA-2024:6811 This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2024:7164 https://access.redhat.com/errata/RHSA-2024:7164 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:8235 https://access.redhat.com/errata/RHSA-2024:8235 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:8425 https://access.redhat.com/errata/RHSA-2024:8425 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:8688 https://access.redhat.com/errata/RHSA-2024:8688 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:8692 https://access.redhat.com/errata/RHSA-2024:8692 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:0832 https://access.redhat.com/errata/RHSA-2025:0832 |