Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6235 - Security Advisory
Issued:
2023-11-01
Updated:
2023-11-01

RHSA-2023:6235 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Virtualization 4.13.5 Images security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Virtualization release 4.13.5 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.13.5 images.

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)
  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
  • net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • [4.13] portworx: update the storageProfile (BZ#2237872)
  • kubevirt_vmi_phase_count metrics is not working in 4.13.5 (BZ#2240675)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.13 for RHEL 9 x86_64
  • Red Hat Container Native Virtualization 4.13 for RHEL 8 x86_64
  • Red Hat Container Native Virtualization 4.13 for RHEL 7 x86_64
  • Red Hat Container Native Virtualization for ARM 64 4.13 for RHEL 9 aarch64
  • Red Hat Container Native Virtualization for ARM 64 4.13 for RHEL 8 aarch64

Fixes

  • BZ - 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
  • BZ - 2237872 - [4.13] portworx: update the storageProfile
  • BZ - 2240675 - kubevirt_vmi_phase_count metrics is not working in 4.13.5
  • BZ - 2242803 - CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

CVEs

  • CVE-2022-41723
  • CVE-2022-48303
  • CVE-2023-3341
  • CVE-2023-4527
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-4911
  • CVE-2023-34969
  • CVE-2023-38545
  • CVE-2023-38546
  • CVE-2023-39325
  • CVE-2023-40217
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

aarch64

container-native-virtualization/bridge-marker-rhel9@sha256:043c933ecc64a18f18a23862b959e60988d7223f1899d8a77c06e75352ce5a00
container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:0723b4c1c3737c07567392abde70c8d0ff41edc628859ab78b4f1db36ce9e908
container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:fae3d9f5dfd142a132fd94f80e8814207aa497459d8942037c383202852ceddd
container-native-virtualization/cnv-must-gather-rhel9@sha256:1aea0afaa1678d22f8c60ffaec52a2f126dfacd1d45a1698fb22239926dc43d9
container-native-virtualization/hco-bundle-registry-rhel9@sha256:5c7cf709c5af87312dffbd3ad438fec546002515df7fb27e5628e387c4062da5
container-native-virtualization/hostpath-csi-driver-rhel9@sha256:8a46da3aa2086587a1d0ff59b62724feac8f1923bede587c5d53ae60ca4256ad
container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:f6ba777473561391d2b0a098ae16cef0552ee7722f9a6fd527b9b06aa3677474
container-native-virtualization/hostpath-provisioner-rhel9@sha256:45a08c2561bc304bf62cee9043961c578e4e3c495bec3ad2a57f9e1ac2a62316
container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:ebcd9f0843d8d759b3e358120c4aec90a7238046d7db0c3b6014152182b14eb5
container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:a549dfc115062d3f9924c4d8527d80de1281d50179d157e6b42699a0535e8449
container-native-virtualization/kubemacpool-rhel9@sha256:155d511f94a84c412a78f8b7a90f677146996bc5b3c00a0bff12b3567c63302a
container-native-virtualization/kubesecondarydns-rhel9@sha256:eac30877a8cbe57c844e660516f0370fa4a2070c6ee805a338bde149be05a16e
container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:dbb6f6340fd4febbb2a0b9c0493af1b02681e835a8b07ddc421b1956f3cbccab
container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:d949f12237050460cbf61cf21cc6627c0124525088af419e718dcbaae5ab3b8c
container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:21176845533bfa0817ea0f29c749be2d6bb00539354bcfa3c013f70460d0a03d
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm-rhel9@sha256:909b0dad28dd12dd3645a661262044d16120b72658ade1a48658c2e86de3afaf
container-native-virtualization/kubevirt-tekton-tasks-copy-template-rhel9@sha256:6bae230bed0d35e81ebc4f98a9c68afa79a7c48617a21bef9d751412ef133806
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9@sha256:0495f03ccdc719420f530fcd530f392f0f9d59982fc0d3df9b1cc4d9dc5ac501
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template-rhel9@sha256:309e43a5a95f95ade124e9e30555d0f2df99a37c606a18aef1e39ba124a37f60
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9@sha256:811b9aaefae86a945ca7b2b9e0ca23afe36be3f9ea0728386a3e2b3df79fe376
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep-rhel9@sha256:648df73d58c946aa502bc6cde710239e9a63c54d116441887115c734af420dbc
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template-rhel9@sha256:ea952209ad5400aeb8318869978e50fb17012e0e84d61dbc19d818e2eaf1ba43
container-native-virtualization/kubevirt-tekton-tasks-operator-rhel9@sha256:e91ef2ec173663ad40867d2696d04681d917ef76b1df7ed9c451886a2adb4825
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status-rhel9@sha256:94f24421df1e69f957caafdd28327041fa198e89824d13a864c6077d946ba54c
container-native-virtualization/kubevirt-template-validator-rhel9@sha256:c7492e63269379a8bb8415645e6195f0448247dd7e513edbadf12c07601fb948
container-native-virtualization/libguestfs-tools-rhel9@sha256:3a97c4aca2b1c9fb1ca94619ba89965e6343eb6c9a92c34688f861564b8c2095
container-native-virtualization/multus-dynamic-networks-rhel9@sha256:18b22a9a9453341c3c419319bfa891437402613f01f5f10437ac81fe14a6ce6f
container-native-virtualization/ovs-cni-plugin-rhel9@sha256:73447696068a5d2f005f9148dc9424d9ca7eb96cc22597228d1ff80a593b5124
container-native-virtualization/virt-api-rhel9@sha256:4ee279958ee70fa91fce05e17e14d3f5e2f016495b9cc33268441cf5cdeaacac
container-native-virtualization/virt-artifacts-server-rhel9@sha256:7cb9c402604382e9477ca83c253cf28a88e0c3afed7c6c2b49da21bf098ad116
container-native-virtualization/virt-cdi-apiserver-rhel9@sha256:ebff907b257a40d560e6455b46f77e25a66ff5a43d20211c1f84df60afe24e71
container-native-virtualization/virt-cdi-cloner-rhel9@sha256:3ef62bc6ce5756f16a40fc66eaede1d185a6fc6a2418434649cf046cb03e49df
container-native-virtualization/virt-cdi-controller-rhel9@sha256:84f8681a07967b12ae1f60fdba3e0e60e739ff503283441cd41317f15a2dd13c
container-native-virtualization/virt-cdi-importer-rhel9@sha256:d4e38f20bf2227ddd9a916960c7f8f40df3e4f0df9adf4fedba6688bd26a2fe4
container-native-virtualization/virt-cdi-operator-rhel9@sha256:8f8262b1dfbf965f7e3be39cb4b829de84d248a9624fcbae56de3fb3ee265ce6
container-native-virtualization/virt-cdi-uploadproxy-rhel9@sha256:7e8084302d1c80303a74cecbc25bb45a97c5513f8babfb22b8ef4f0ef032048c
container-native-virtualization/virt-cdi-uploadserver-rhel9@sha256:e1f8cb4dba0f3f53b40faa9c32f5a5d98a9bf7b1d25d987ed49abe99be89b561
container-native-virtualization/virt-controller-rhel9@sha256:5ace580e85dcdbf18ef50362c0dcfe8e24b30301752cb16efd583a346699676c
container-native-virtualization/virt-exportproxy-rhel9@sha256:1e675c5c66a08fc992909e2d06913ea8ab1420fc6560c87f048020a5ab9d055f
container-native-virtualization/virt-exportserver-rhel9@sha256:ee39b31117c8f8be67863e952683cdaf3d49cad742bd722b5abbfa6613aa28de
container-native-virtualization/virt-handler-rhel9@sha256:2d65599406329f5b5b81305428873638f99a937807683338091bccbda60b9cda
container-native-virtualization/virt-launcher-rhel9@sha256:23b65c6518e23b353a8679ad4b80389c8a7c35797718a8e5ba00f976c85a8c68
container-native-virtualization/virt-operator-rhel9@sha256:e8703006f51562b0370facfca722d0064e5673db77e7a0e1edfd62418fd2847a
container-native-virtualization/virtio-win-rhel9@sha256:da9f96685d597eb80a59a99d64c4c59a5e6aa6fe042be8b6a8386bb01f6b5a4d
container-native-virtualization/vm-console-proxy-rhel9@sha256:1d8b888e5c76c6de2c178d6301d6caabbc497fa3502f30731885ade2012d01b6
container-native-virtualization/vm-network-latency-checkup-rhel9@sha256:9d456058997fc90c0d6acbeeaf349d33c4f6ce36509c3f68685a1be90d793b5b

x86_64

container-native-virtualization/bridge-marker-rhel9@sha256:dde9d6d3bd598203276151ca6f09a8d94bc8d68160b8eeb057d528612ee387de
container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:79ffb1e1fd3eb66bd8501f73376cd86e031962151fb33b1f5c99b1768558a5bf
container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:0259bad586a2641e8f805cb3b011fd13ac2877afa1086be3d5f58eec5b074de0
container-native-virtualization/cnv-must-gather-rhel9@sha256:bc0ed2d18c556df388a3a650d365e68f24074219683a81c12b1897c1e8a756ef
container-native-virtualization/hco-bundle-registry-rhel9@sha256:7314d53f44b9058a2a41620ea57c8eafef5161218d412b8ad7353fb570b5ae64
container-native-virtualization/hostpath-csi-driver-rhel9@sha256:30d2d9e998ec622648c848106328ea3a45dc17d51b058f3e222f5199232a1acc
container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:280ed417e25231cefbea15d35a456e540329542d59dee59ad1824228bd35e089
container-native-virtualization/hostpath-provisioner-rhel9@sha256:c3059286198d3a75dd0cab0a8c751f4dde5b0f5e52cc38fe5b258e9324477c62
container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:80f623b7d005f2ed6ccf81af9b032a13fee86c7f4a4f564e932073bca0436bfe
container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:2832fbf13013467ea73c63e5e6ad7ffe94dbbeb052ec8727f6935d41b2c4d25c
container-native-virtualization/kubemacpool-rhel9@sha256:4d91d2b48e984b99f03ad19a25cb9b1c4eb12670fda6848a303009de65e4932e
container-native-virtualization/kubesecondarydns-rhel9@sha256:4b2ed5bc8f226433a3c6e2dd926a74085b4ed60ed4f0bd505a8613e4d3c5f3ba
container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:f824525b97a1724c9eb4e0786a19e0dc16609b14915faf31229abc4345fd91f1
container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:74975f1f030959c5ad9067c709b848029d08b74a17297da8666638fc8377f4f5
container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:90ef77f56d0b7a5c7ac67425fdad169d3f865cc24723bd10635c1d974b9dd540
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm-rhel9@sha256:96cd6da0c42ce26091f0d9cc7fbc47d24ebeec51b4407d45c5e7d0a7d861e773
container-native-virtualization/kubevirt-tekton-tasks-copy-template-rhel9@sha256:1d8602530af08cf8344e6d9494a9e53aa51ff54cbf4292a9c5c9633b8d3ddf62
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9@sha256:7807aaec505ba59712ff21c0db7daa33ed13e52ab1f1aba346dc9cbc3295afce
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template-rhel9@sha256:2239c59d6e1343498d7e0c65d358be6675156a7f1626bcf0052107acb0445927
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9@sha256:ae5fcba31eb7dde0f03a5a947b765b0492a9a805938bdb9075b7c1c3ca7b53c8
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep-rhel9@sha256:21cc83f45931f6151fb8f4fdf2d06eecaa6d6ce139e41e6946b202adb107db34
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template-rhel9@sha256:932234c21ddbe7a50cb9e0217299ff08bffac42dc6c47fba3a72b542e082c1a4
container-native-virtualization/kubevirt-tekton-tasks-operator-rhel9@sha256:176782274bed233d5a522f63c435c2504b1182f34d49a2fc87166e284d03522c
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status-rhel9@sha256:f8532cc89663d20221bdb01642e8237f9096ba686697fda12a4f3a63ed991726
container-native-virtualization/kubevirt-template-validator-rhel9@sha256:a1c61fac7dd64e8de733db6af840d2c1c0737208634c7bd76bb8970334e456e8
container-native-virtualization/libguestfs-tools-rhel9@sha256:e667c06a7d1f5569038d0a93275da2333a47bca885a76f444d317dac6b8b6657
container-native-virtualization/multus-dynamic-networks-rhel9@sha256:739517ad4e74e5f62f95df8301c8360c09f8a441070673bde68c3a1119b26ecb
container-native-virtualization/ovs-cni-plugin-rhel9@sha256:ffb0c9fe819873c3d923f50aef33f0e253c81df2846a96dbe58516f95080533d
container-native-virtualization/virt-api-rhel9@sha256:eb6fb58636e5f8d2cff86e59f722821522361de25ecd12cb590a2c50184c0f93
container-native-virtualization/virt-artifacts-server-rhel9@sha256:5a0a241bf8b334a5d52b9cefd74146628b7884e31303e9a63d96e52688e88b59
container-native-virtualization/virt-cdi-apiserver-rhel9@sha256:9f23ef7d9ebea242aca099ca05fc59f008c4b812ebfb42400cf83f9dae9d1914
container-native-virtualization/virt-cdi-cloner-rhel9@sha256:754cdf68bd406ac6d7dec2043cc2e18644944d11d3c5a7144cbf642d0104ff27
container-native-virtualization/virt-cdi-controller-rhel9@sha256:e352a385250091e0e5ee314b9f62e5ab45c15226a8e687ef8735988a213bfac9
container-native-virtualization/virt-cdi-importer-rhel9@sha256:64fa194703392dd4048a9f508f7872e04864000b8728773504a09661a14684cb
container-native-virtualization/virt-cdi-operator-rhel9@sha256:accc78929702ab17eed27b5c3c97b7327289b1220a7688b60407489c64f93217
container-native-virtualization/virt-cdi-uploadproxy-rhel9@sha256:7070f54131307aa3de5e76d733b1a1fd502827eca1b0d9e5099caa91a86cc26a
container-native-virtualization/virt-cdi-uploadserver-rhel9@sha256:c0eb37995a2899e06e6a086a458ec52669d25fda5d4fdb7ef88521a91637b318
container-native-virtualization/virt-controller-rhel9@sha256:ab0fef9bd51caa62ef0e900c7fbe72a4fe67a48ef913ba33b6d261648342a0f2
container-native-virtualization/virt-exportproxy-rhel9@sha256:1a7a2bb4de8718c225295b70c4d324c35e915e29e9cd01a22164962bf2f6cf15
container-native-virtualization/virt-exportserver-rhel9@sha256:1d8bf43099edd641ef96605e554723b312d36b1b2d81544f12f1063d7de33826
container-native-virtualization/virt-handler-rhel9@sha256:4ff11fbb4fa3fa2fd9fbc9465a4bef5934101ea2a6201d91ca34c5616aeecf45
container-native-virtualization/virt-launcher-rhel9@sha256:9d7d750377de058f14baca092b7832fc756fc0b31bdf4426556b380012bd69fb
container-native-virtualization/virt-operator-rhel9@sha256:0b7505d513a3a5dec0ceefb1e2337c8f8c7769d1a3a45e21e3ce46f7d87b3b9b
container-native-virtualization/virtio-win-rhel9@sha256:0c8635ad9d5dcb052dd6a840e6a841fbafce15cbe6820878f1921652a0a7dec8
container-native-virtualization/vm-console-proxy-rhel9@sha256:527182f4a91752fe5e1d078c745c8d0763392f94b9f32a8cf2885c69a1ddbc6e
container-native-virtualization/vm-network-latency-checkup-rhel9@sha256:1526bbc64a74f9bd86c119a9f48e83f7b1d4978bb0096624d33d2dd52a2cb2b0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility