Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7322 - Security Advisory
Issued:
2023-11-21
Updated:
2023-11-21

RHSA-2023:7322 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.13.23 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.13.23 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.13.23. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2023:7323

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive

work (CVE-2023-44487) (CVE-2023-39325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • OCPBUGS-22905 - Match origin image to configured image reference

CVEs

  • CVE-2023-39325

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

aarch64

openshift4/metallb-rhel8@sha256:ed25204222dd47179b2f539cfe32b3e4b3593a1de1cfde7cf3788cf026c37ba6
openshift-tech-preview/metallb-rhel8@sha256:ed25204222dd47179b2f539cfe32b3e4b3593a1de1cfde7cf3788cf026c37ba6
openshift4/kubernetes-nmstate-rhel8-operator@sha256:d5ec6d63a49e285c4dac04622d240d04c54d8a8e152263f466bac1371e055309
openshift4/metallb-rhel8-operator@sha256:7226c4cc18442e7bdd46f12eda8e6a429b16c648d02b2200863b87371d468ceb
openshift4/ose-cluster-capacity@sha256:c6af63ea2ae176a840e3aec029fc9c594a13038e3a13de0e69658f4efaa8dc6b
openshift4/ose-cluster-kube-descheduler-operator@sha256:660b53c499911957783068e818fbf5515fe6b8c531e90cbf1adc9d32f530c6c9
openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:660b53c499911957783068e818fbf5515fe6b8c531e90cbf1adc9d32f530c6c9
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:ef477b893834ed2380281ddc38b9771c21e5c72f3595cf778b3882c6056d90dc
openshift4/ose-descheduler@sha256:06947c1738c1fcdc07f4dae898b26f84ea630a0643f41bd912807133a7b327bb
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:f975d6be51b87e446c1ca62d515b2d63bfb18de5ed1f5f08bf7ff6f340e1fbf5
openshift4/ose-local-storage-mustgather-rhel8@sha256:5269a49e05a1cb0d550b0f402ac0ee84235b9fcf7d1a8d2049ae7e6d1115dce1
openshift4/ose-sriov-network-config-daemon@sha256:7d168f9741ed9e3092885dce3726f6fc25854ddcd04b6de59cb8312a0ce0693f
openshift4/ose-sriov-network-device-plugin@sha256:feae00885761dfb210d21ae0ff05212166327cfc527ed689efe20c7fbf143d12
openshift4/ose-sriov-network-operator@sha256:320b6942c4305191c05f123eff193f01f46b3b3cb2cd8e3ca02d6d8396d5acbf
openshift4/ose-sriov-network-webhook@sha256:555ea843be4ebaa18241d18bb886b7249e4c9cce862b98e2ef981d9847e8df1b
openshift4/ptp-must-gather-rhel8@sha256:6ba7f624d1f72521e2f1bd1edc2b5cb167c4ddfe312485f7d4727d21b27935c7

ppc64le

openshift4/metallb-rhel8@sha256:0afa8ab414fc3bcfc9f4df354d98433b750d04479c98555ca2d06b1b34d2c00c
openshift-tech-preview/metallb-rhel8@sha256:0afa8ab414fc3bcfc9f4df354d98433b750d04479c98555ca2d06b1b34d2c00c
openshift4/kubernetes-nmstate-rhel8-operator@sha256:e152b38a59e390b1e0193b35b233aff8e743b59d3eac2f2bf922d4b30baf0938
openshift4/metallb-rhel8-operator@sha256:d1d5f14e6aaac23a4c54768bba96722be7d6c1371a98a3197ee8ca14f43e0ea5
openshift4/ose-cluster-capacity@sha256:2861bf310207096499130a15b626f53fd2d02d2f6698a8a0c2851e0cd7ccfa6a
openshift4/ose-cluster-kube-descheduler-operator@sha256:81978c017694e2bdb66e996ce8bf2c65a2167c382f97420f52e5e0068929f818
openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:81978c017694e2bdb66e996ce8bf2c65a2167c382f97420f52e5e0068929f818
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:47fe8d71369b531b7dcc04df6246e898b4231eff6502e1138122a3ab1957aa4d
openshift4/ose-descheduler@sha256:398efcd6257274aa3b75fa7c9240fdc45df8374994e0aabd8f2b832b2b970339
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:d8a9c063ea635d29c0a1ab067a51deed2d324ac5c2d013739e320c283f4c9e90
openshift4/ose-local-storage-mustgather-rhel8@sha256:b0f365b99495ed475b0cab814921e58ccdf00aa0a82919dbba7491ea0d28daf8
openshift4/ose-sriov-network-config-daemon@sha256:90155e0af36249ed9c99be5452ce0c5f9448ffebf10356b3b19e20f78a9bb34c
openshift4/ose-sriov-network-device-plugin@sha256:56cbfcfe8917f2333d01ee5a4d8c3654f7860ea7a3630ddbee51a92eaa0993db
openshift4/ose-sriov-network-operator@sha256:4ceb027c4daf242557913dd78e834bff8fc94758b90b49115731556045175891
openshift4/ose-sriov-network-webhook@sha256:cea5d3c541fba20a426b691dc8bafec1e5b1fc22ef2f711b9d0d58a8cc5257f1
openshift4/ptp-must-gather-rhel8@sha256:9447c3842319472d549dd8779b4d8adc29fb03f2f3ad38da64210e10d9349d78

s390x

openshift4/metallb-rhel8@sha256:17876acb170ddfcde340b0cd723eb7d92ee671c2026c6213919372559093f338
openshift-tech-preview/metallb-rhel8@sha256:17876acb170ddfcde340b0cd723eb7d92ee671c2026c6213919372559093f338
openshift4/kubernetes-nmstate-rhel8-operator@sha256:9f17cb2dc5661ba3b7cafe2496e219bd0e9d6fa1ca9c10fec7d837ad6b934153
openshift4/metallb-rhel8-operator@sha256:2a6f2a343654c1688a5e290e09fbfca6c32a88965f9501c87e002fa2a16647b3
openshift4/ose-cluster-capacity@sha256:5806546eeada374b855e90f355e70ec05c120226f9b7cd504668fd1296d89c8c
openshift4/ose-cluster-kube-descheduler-operator@sha256:cbba9380708b1127cbf8763990052c9eec1412efb35d78e760fc7f60fe085ea8
openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:cbba9380708b1127cbf8763990052c9eec1412efb35d78e760fc7f60fe085ea8
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:bc77d9137cf8ba16a0f3d0a8e3c31b30c8f6e8bc8add03bbd5cc25f823710f4f
openshift4/ose-descheduler@sha256:69eb28fa3fa95a407a22991b4c94a89e26a5049318f863419f4aa8c2dcbe493b
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:2aacb342af6d7ba6186518685bca8adb66b904da98626c873496f4ac79e4dea9
openshift4/ose-local-storage-mustgather-rhel8@sha256:5e869b3ffce746f0a105bd093af581e57d05ce36b549f787e5f6dd42147acc84

x86_64

openshift4/metallb-rhel8@sha256:6acba95a5dea48416d07d11afcdc7192b209d157d913859fadf8e186e695b013
openshift-tech-preview/metallb-rhel8@sha256:6acba95a5dea48416d07d11afcdc7192b209d157d913859fadf8e186e695b013
openshift4/kubernetes-nmstate-rhel8-operator@sha256:aee9fd60fc47db7b013c177ba3e7e82fe61832415ee980ce31e7e155f0448ca4
openshift4/metallb-rhel8-operator@sha256:4ecf38a4f15e0c10262197a6c76b9e73d09b8d3ff80d0ffb532390dd627e5f21
openshift4/ose-cluster-capacity@sha256:abe8312b520f6046860eff1458254579f78640a61357f73d10dcfd1d05584cf4
openshift4/ose-cluster-kube-descheduler-operator@sha256:fe8d738ff042e523ec43d42926b13c98d819bec32a78e8c3d81158eca87def83
openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:fe8d738ff042e523ec43d42926b13c98d819bec32a78e8c3d81158eca87def83
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3a2bc8ab9762c1399c299827a5d2e8e1f238608a9b2fb441b4633f968f1bdf3c
openshift4/ose-descheduler@sha256:b2b3f926e74bc8d5077db53ee117f897752628da1559809d1fe5c5b5cf306779
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:ee8acbab7313ae982042dd0b6ff405cced1dad73d817d3c7aa05d234a28d654b
openshift4/ose-local-storage-mustgather-rhel8@sha256:df057b6104c7d8661f38f066f1ef7bce584d8fd3a76e81c401a09d1bf3acb5f4
openshift4/ose-sriov-network-config-daemon@sha256:72633a314ed82d2d2dce061cdb87122d275e5f158282991b7a552a10e3b1494d
openshift4/ose-sriov-network-device-plugin@sha256:573f1366483b5b8e1c012106fc273326259a3fb9081f0df0af18212ccbfe00f6
openshift4/ose-sriov-network-operator@sha256:1ce3a77b8e76c4ed4e6dabd373e31318f8fc63f8d70310f52f7bd2d37f34bfb9
openshift4/ose-sriov-network-webhook@sha256:9c860826ddfc6ad23c7758e5c3f067c231c5eeabca14ccc206d8f7ce73e271c2
openshift4/ptp-must-gather-rhel8@sha256:cd6046ab02fc4c4184c88ee7b852432f354601469f6ec6edbed8380d4b8ddc17

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility