Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6275 - Security Advisory
Issued:
2023-11-08
Updated:
2023-11-08

RHSA-2023:6275 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.12.42 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.12.42 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.12.

Red Hat Product Security has rated this update as having a security impact of [impact]. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.12.42. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2023:6276

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (Rapid Reset Attack) (CVE-2023-39325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 8 aarch64

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

CVEs

  • CVE-2023-39325

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

aarch64

openshift4/metallb-rhel8@sha256:4c7d12333585a5805a7ed93e458c6df43e4858b0502fa7b5351395506dd36a26
openshift-tech-preview/metallb-rhel8@sha256:4c7d12333585a5805a7ed93e458c6df43e4858b0502fa7b5351395506dd36a26
openshift4/kubernetes-nmstate-rhel8-operator@sha256:64a15ee61ee026f8d7ed4b202f4eb586b7218acb6b1ed40cd37ed3e40551c145
openshift4/metallb-rhel8-operator@sha256:f05d2b346d26f4c8e948f9f0878dd6ace84dfbc38557d154e010f9f37dfd48cf
openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:9e788201d32ca4b5362868ea336c2b744d4050fdb7f0dd6cd8bb00ccb4c018a3
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:abb8de1869be8f874aab3b855d6b71a793ad2b2e7fe80ab1501d6cd184c7142d
openshift4/ose-local-storage-diskmaker@sha256:d8aa538c60d2bd7ae9cfacf26b3d66bbc5a1ed2beb4d762357a616f3b97e5185
openshift4/ose-local-storage-mustgather-rhel8@sha256:5cdb626ced73e8654420157161497e7fc284ee1aaa4de75d368a3f8281a85b73
openshift4/ose-local-storage-operator@sha256:cb857786143e1e99247ade95bff32bc95d5bdda1e3c297dae3982a73a9961276
openshift4/ose-operator-sdk-rhel8@sha256:06431a0944d41f4a28f5f17f74963622cd5e5267f3aaa87fead9b7de082bfb8a

ppc64le

openshift4/metallb-rhel8@sha256:928b08ba3ae94f271988f0d5eee36d8ebd3d3a3b04b7780e9b0cb3a79c874fcd
openshift-tech-preview/metallb-rhel8@sha256:928b08ba3ae94f271988f0d5eee36d8ebd3d3a3b04b7780e9b0cb3a79c874fcd
openshift4/kubernetes-nmstate-rhel8-operator@sha256:419aae6dd41590a224c877509c90215b2ab2bcc1f7e304aaf33a03d55668b1b9
openshift4/metallb-rhel8-operator@sha256:4748df5b5d73aa9ca3f1e9ea760ae695c1c203124588ab08609c080a56042436
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:cb9c913c8b6175fbf61bafab38b7ad9291efa33f61c105b4d4185c502adfa146
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:c86f6786ea993a9096cd2f7e1ba1c8adc4833b6cf1d746729abdc99cfb512331
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6d90803767d6ff007c9767f9f9135bf5316ec754bd8ce5dc4cc259a6133561d2
openshift4/ose-local-storage-diskmaker@sha256:0999637fa57edd55b5af686cbd46d742e46392df43bdd0f9dd4bab4266d2f729
openshift4/ose-local-storage-mustgather-rhel8@sha256:22c740765ed271cbb13f689771d8bfde283bde8bfe11dab7f77349929304b4fe
openshift4/ose-local-storage-operator@sha256:a4321b74acd5483b98b03ff7713beaa2e4fd96460de3a64db3a9f7e5c6d8c44b
openshift4/ose-operator-sdk-rhel8@sha256:3e95df45555aa4ee352081a59a80040f5c7437ab5e32774945f00165fa7d7670

s390x

openshift4/metallb-rhel8@sha256:bd7db0c6b642d2ca0489bc662fb8c90aa49bfad3a4177728a832886a98ff8c24
openshift-tech-preview/metallb-rhel8@sha256:bd7db0c6b642d2ca0489bc662fb8c90aa49bfad3a4177728a832886a98ff8c24
openshift4/kubernetes-nmstate-rhel8-operator@sha256:73275a96c62fa1453c8759d9283c3553ea6c0f3b27e63d715eaa29159a7c7a93
openshift4/metallb-rhel8-operator@sha256:a90b02ce74e0ca4ab76a0ef2ede2528c86d8e0700cb04db7ae4619b5b5fc42cb
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:ea0385db9ddada56305621fcf134d05fd92ae5b299c23b0f74076140a64aac12
openshift4/ose-local-storage-diskmaker@sha256:488bea7413b719f4b1f07009e3f066327616173a6a8e29657d87cd8e3c42792a
openshift4/ose-local-storage-mustgather-rhel8@sha256:52146874b5b3aceaa9196cff6c369eaed17801d0c332fd5d759161c367295886
openshift4/ose-local-storage-operator@sha256:16afdfc1a8b513173592e10db738afa9283b4da49569b6da399c30dfe409a262
openshift4/ose-operator-sdk-rhel8@sha256:7825fbf0e94f5925ec4ebcab8cd3972099a7d6139b3d8730946397ae613a368b

x86_64

openshift4/metallb-rhel8@sha256:e78c66a3d469c99268862c5e5d56dd978c3ec57fe459037be847e2dae5183082
openshift-tech-preview/metallb-rhel8@sha256:e78c66a3d469c99268862c5e5d56dd978c3ec57fe459037be847e2dae5183082
openshift4/kubernetes-nmstate-rhel8-operator@sha256:b9a5d656fcefa3b0079ddefba7aaa9592082a7e7874aca124a659fde62827fe0
openshift4/metallb-rhel8-operator@sha256:6f1166fe2ded0a7b51284518b0beeb256df21d814ae490b491904a474e337c75
openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:1906f26262330e6ad23312081522b8b602b23ebe26aad497e49477734e2ae278
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:4ab97f89ac6136f355034b4c820e54a0452ab07b567f60449f12b152e9bf92a5
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:9f3f64c41333d09b3ed7afae195bb32b8e62611432ffa069a09de7f22c861058
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:110fe344a463c1e7c0587186c15ae2646c8f782fb530cfbde2149fc7ab323055
openshift4/ose-local-storage-diskmaker@sha256:df50501acc1cf7c7031fdcbbb507e3d81e22bf3090ded718f4c717ed826fba09
openshift4/ose-local-storage-mustgather-rhel8@sha256:f39ef83f8df7e2105ca47861d678b195fc47e5a61f332c8322aa0527153279c5
openshift4/ose-local-storage-operator@sha256:f0575f181b1025c7949e90f58eef925b914a914af641aab5e71f95bd34e617e4
openshift4/ose-operator-sdk-rhel8@sha256:8a98789bd0a78db61e6c07b1105a36dd49ec9d2fc12f092440a0a6e17dd54ae2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility