Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6251 - Security Advisory
Issued:
2023-11-01
Updated:
2023-11-01

RHSA-2023:6251 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Virtualization 4.11.7 Images security and bug fix update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Virtualization release 4.11.7 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.11.7 images.

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)
  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
  • net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • 4.11.7 containers (BZ#2246329)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.11 for RHEL 8 x86_64
  • Red Hat Container Native Virtualization 4.11 for RHEL 7 x86_64

Fixes

  • BZ - 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
  • BZ - 2242803 - CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • BZ - 2246329 - 4.11.7 containers

CVEs

  • CVE-2016-3709
  • CVE-2022-41723
  • CVE-2022-48303
  • CVE-2023-3341
  • CVE-2023-4527
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-4911
  • CVE-2023-29491
  • CVE-2023-30630
  • CVE-2023-34969
  • CVE-2023-39325
  • CVE-2023-40217
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

x86_64

container-native-virtualization/bridge-marker@sha256:6ec0d63868d6c69891b96338782db6ddefb6eeeb155a8b316112cfa3b756885c
container-native-virtualization/checkup-framework@sha256:7a9443d47b8f954670ff3a8f0196f26a3a7bb4b16d2c3469a22d01172f31fc26
container-native-virtualization/cluster-network-addons-operator@sha256:bf77cbd3fa96da043778f1f27ccf009097f53a46ca1584b440a15623a6edde88
container-native-virtualization/cnv-containernetworking-plugins@sha256:d34dbb657cb4a631ccca5687f05a9387d679cf03d9899c0843b4f1733ee64103
container-native-virtualization/cnv-must-gather-rhel8@sha256:575bce5098573be251955aca405570171a458f6993d6735aa39b52012dd0320c
container-native-virtualization/hco-bundle-registry@sha256:d2530174f8d682e186b1be97d1e567927c1aaaa7fe5fa1f83eb826608515dccc
container-native-virtualization/hostpath-csi-driver@sha256:20488cf9f269a34be9a3d82e04a28b598b26be0a495f51a47a8dba02f7e9d974
container-native-virtualization/hostpath-csi-driver-rhel8@sha256:20488cf9f269a34be9a3d82e04a28b598b26be0a495f51a47a8dba02f7e9d974
container-native-virtualization/hostpath-provisioner-rhel8@sha256:6a49eb5fa0d5d85d028753ccfda32c66c0d26f1d6bd4d264f0d7f1af7887e131
container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:d0755533e714fde9377688064f67e3949d94db4307c36b16d9e4990caa2080b6
container-native-virtualization/hyperconverged-cluster-operator@sha256:5d446416c7c4ac98bf24b5c0bf7631e7feb55ebb898aedace28f8484ae628cf5
container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:3f8b6e4d39648595a62b087f49b9a8e8844bf2f9a743e32db69bdcc491831b55
container-native-virtualization/kubemacpool@sha256:cfb161f31bc459f160a31cf9ad4ec8f0d7ee9140c13b8ba2e6477cdb971f6384
container-native-virtualization/kubevirt-console-plugin@sha256:3ff40d3759ea6c50aeb143a5aff6f798611267452eb8111361ef9e0a89260bf5
container-native-virtualization/kubevirt-ssp-operator@sha256:81fa9feb8418ebf53d9e386fc98a8ee45fd83c30496e3574626449ab19a10236
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:8c7d9751d790df2471a9e8606afcb2880b800ec713a089b2a801df247a0f3fec
container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:f4b0b6daf093a75fcd8d4cc61496a316f86899e8ce4217e9f761def5f9d0e794
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:33a16329639f805c0d75a0ed6fe699755938f602230104715c0ad3b545aaf7fa
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:caed594ab506d7cf550130d927b68bdcfb3707b8464f2d18da468d9b884c3017
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:4980e6eeadf62bedffff98982f0f5b5e426b0ab01867057dba027e87f9557ce4
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:254f671bc0443d32ba60cfafa4ed4592c2030270b160c1e7b1d302d797bd9a82
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:69ceb3d47f3c8c32abcca8ec5ad7ebce42ce64e8200f77c1b829c2cb5495c478
container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:ec2ac2bedd9f14ff0fbdfe3844d67f1361d59eb379ef6dfcd0fa5727635bdea4
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:a1fac42b6bf868c20ad974a0409cd62e68be20ea9e4ca5ff4ebc211bb9dc85ab
container-native-virtualization/kubevirt-template-validator@sha256:47b866156816f285cf7ea8b8d523e2ec84bc58751e1d593e98bf8ab493c8db09
container-native-virtualization/libguestfs-tools@sha256:0547ff01b9717560fd81ce291acc4b3e70098df3b80d42d35ec2b563b0ce035a
container-native-virtualization/ovs-cni-marker@sha256:7c44a0d3bb352c0327974ccb3c2054c6cff88fa58399b1e40409e197ad78d585
container-native-virtualization/ovs-cni-plugin@sha256:4eb3e9b62fa09edc3e678fa0afad10b8e1042fb95ddecaca7a48e79c392b3029
container-native-virtualization/virt-api@sha256:fd9dd050e1670ffd7f1816ebcced2a77a51aa4bbf96bec893f8b7e84b3824763
container-native-virtualization/virt-artifacts-server@sha256:bedf2d810c355505de7b2dcb24b27d04b0ab94d3adc711d942ee830c71ff49a3
container-native-virtualization/virt-cdi-apiserver@sha256:de581a993f71f57bced78261962524b1e1eaaf8f6c89549735475fad3b997093
container-native-virtualization/virt-cdi-cloner@sha256:9c5ac022e709ac0ecd77814138639b3b9e6d34fa9f98bc3ce4127b1d68af29f2
container-native-virtualization/virt-cdi-controller@sha256:192f40ae9ba79582d0f9ac7ca7f1eb1f8c44abd7c79345bd579807cc94a883f0
container-native-virtualization/virt-cdi-importer@sha256:ce436ec0a51e51ba209da49d6d877c7e07faf264b966849934c72d1c031a78dd
container-native-virtualization/virt-cdi-operator@sha256:1b503bfc4177444b360c4a1a470ac8322d3394fd9e8ebe7f2bad849249d2c6fd
container-native-virtualization/virt-cdi-uploadproxy@sha256:fc0aafe98acf811a0e94091a6dcec5f465ddc64e279ad250f6c8fa4225de7c7f
container-native-virtualization/virt-cdi-uploadserver@sha256:029992238c9723c2760d24d502b95d22a46f3a1586e076da54863fc22f9cca35
container-native-virtualization/virt-controller@sha256:3c80a72772b98e46fc1382c3dc6a7b8a41f50e8bde5a12362a121e1dd1d2cc64
container-native-virtualization/virt-handler@sha256:841aca720b7082e72059f733ead2e02915e6ead7506d79ac6eff0b143390713e
container-native-virtualization/virt-launcher@sha256:1480ad0874186f451bd95b51953940ad7589c2546715770be1b61f3e8dec3ea9
container-native-virtualization/virt-operator@sha256:8dc7b78fea1006af9bb0d62120b50964e2fc73ee049a0efe94d366aad296ab95
container-native-virtualization/virtio-win@sha256:58f2d6b9b41d6a0af3a20d2ce491f2c2bf8b3f07b6ea0170b729f0db0626c21d
container-native-virtualization/vm-network-latency-checkup@sha256:9d28ad64ab3d2858ce9b1144a77816cc1ae07f53b37599fc24609a9429c0a0b8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility