Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0946 - Security Advisory
Issued:
2024-02-28
Updated:
2024-02-28

RHSA-2024:0946 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.13.35 security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.13.35 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For OpenShift Container Platform 4.13 see the following documentation,
which will be updated shortly for this release, for important instructions
on how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

You may download the oc tool and use it to inspect release image metadata
for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests
may be found at
https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags

The sha values for the release are:

(For x86_64 architecture)
The image digest is sha256:2399ee629b41bf4c4006478260dcffd40849912398c09cba77bfada2fc481247

(For s390x architecture)
The image digest is sha256:76973643be097f7556ec05e715121d5bd19f691acbebf0b62657e7c007e7190b

(For ppc64le architecture)
The image digest is sha256:aa82f2d57af3f1e0024ee5bbb4a1257d8e38c21805ff0e37079a2c1835984da7

(For aarch64 architecture)
The image digest is sha256:1cdcff922de36e291741f05c0efe46a9bc88f8c212859f1a24626b149308f7ec

All OpenShift Container Platform 4.13 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • OCPBUGS-28654 - Fix "depreciated" typo
  • OCPBUGS-29597 - [release-4.13] gather etcd_server_slow metrics

CVEs

  • CVE-2021-33655
  • CVE-2022-2196
  • CVE-2022-3239
  • CVE-2022-3625
  • CVE-2022-20368
  • CVE-2022-23960
  • CVE-2022-29581
  • CVE-2022-36402
  • CVE-2022-38096
  • CVE-2022-38457
  • CVE-2022-40133
  • CVE-2023-1074
  • CVE-2023-6546
  • CVE-2023-6931
  • CVE-2023-30456
  • CVE-2023-31084
  • CVE-2023-39325
  • CVE-2023-51042
  • CVE-2024-1086

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

aarch64

openshift4/network-tools-rhel8@sha256:368c0aa692c128f812c78cca2bde03555ce6dd3ee4fecff625346e027770f714
openshift4/ose-baremetal-installer-rhel8@sha256:ea30ddcd9f6324f3e216bb0afe496a4ba4d77c966915757cb9896aa00dda9d19
openshift4/ose-console@sha256:197ce5bee3cb4e020fd507d052fb3d137571054e91590ba5aef92c6f503b0b83
openshift4/ose-insights-rhel8-operator@sha256:02610634e48548b4eaaa36d130fc8c79820bf7cffb29c1f150e20a07ac037afa
openshift4/ose-installer@sha256:69f483f940db39b61d77b52ad0a31cb046cc55cc010868eb013a62e4b5e53732
openshift4/ose-installer-artifacts@sha256:d96e18cefcc99e3b58eda81bcda46321dd5746d57a97bf3c7a5f7eeebe42428b
openshift4/ose-ironic-agent-rhel9@sha256:e4af5bb12a15c88dbee46d3bc6f80efeb582136ccb803337b63d3ece65e48f10
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:89c19b45730a9bfc0ea1a81a3fbcc71010098b625942a662064b33b3bd281aba
openshift4/ose-ironic-rhel9@sha256:72b669b7f96fc597ecbae610dca36fc5066bc7f0cf612800c38a50a56b3161f4
openshift4/ose-machine-os-images-rhel8@sha256:46c8d751618f510168fce95fa86592cb73dc7e6c65410c27b800e0cb57f20268
openshift4/ose-oauth-apiserver-rhel8@sha256:caadd60c1feb3128b9574e2a675499972cfae9b9ebaeaedf418e42427ef7917b
openshift4/ose-ovn-kubernetes-rhel9@sha256:e1e10c640e08bc34e8deb5da5ad5d097dd807b006bed2d7db1a84d650b3d7f51
openshift4/ose-ovn-kubernetes@sha256:e1e10c640e08bc34e8deb5da5ad5d097dd807b006bed2d7db1a84d650b3d7f51
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:a633b05ff6e709900700f425d9989c1539e93b6ac0a69239fd6f228c66a55822
openshift4/ose-tests@sha256:92f6f5cf150652e433a694c346e59a7dae20fd243c0fa4fd6249b17e80d2a977
openshift4/ose-tools-rhel8@sha256:467f1fd775c3fd02c74a9a6ba69be0926221923694ea8fe446923d1d6b88084a

ppc64le

openshift4/network-tools-rhel8@sha256:5809b051eb86cf15e51b57176572868ba346d94f3abd2fb488633e59a36ece16
openshift4/ose-baremetal-installer-rhel8@sha256:66b3d25cf513839cedaca539bccb9aaacb3994af7ee747d5e3717811fa010779
openshift4/ose-console@sha256:dddd1380680c2770e51840beb2b5063a140670d43634775f3d98fb63eea61b07
openshift4/ose-insights-rhel8-operator@sha256:f4e9f5f638ceb2b8c6b338c2a29ac4051f31aeca2c0e1ad9c50b37da99e8ff3e
openshift4/ose-installer@sha256:a577600ff180e3ded34d811e766ea723f9f95c4646dd06a7efe17e5856dd44bf
openshift4/ose-installer-artifacts@sha256:0aa63b4771d00a471d05d6cd3b34f90b6126db5060db6df2b2e02173591a9526
openshift4/ose-machine-os-images-rhel8@sha256:e40e4c07284cfb600eb31a750563c28178a90ffc264fa80d38abd93bb2354552
openshift4/ose-oauth-apiserver-rhel8@sha256:1c9d08e9241811124c488761866d8f75ae4c7333fb69a9b81f17f4d8b6d6884e
openshift4/ose-ovn-kubernetes-rhel9@sha256:2f00f3163b4e8a3caa395b8c8229b7c932bac6ae4096dacefb311eb94c055500
openshift4/ose-ovn-kubernetes@sha256:2f00f3163b4e8a3caa395b8c8229b7c932bac6ae4096dacefb311eb94c055500
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:ba0c7c13038b8a43a375237cd28991d96bb451e6d2940f62d192e0c40868e900
openshift4/ose-powervs-machine-controllers-rhel8@sha256:ac4cf015b58d22f49850a12bf4bb095d1834899b4dd4c1aab2a0a892e44b626f
openshift4/ose-tests@sha256:15d624f525b19de3a7942706ed50ff17f3bb0da8c208987d3d2e96fcf30d2ef6
openshift4/ose-tools-rhel8@sha256:8690593eb56c8f3211cccafc87fa96fd9224d1b0e655d3ddd74ff7fb070ce075

s390x

openshift4/network-tools-rhel8@sha256:df5449cc95045714f30676f6f494faea949695d62d1dcd905717d4b3d3f4ae89
openshift4/ose-baremetal-installer-rhel8@sha256:d6e5ea81bf740daa31704e7aebf9d63916e073b68b326595f4e478166cd1cb3e
openshift4/ose-console@sha256:1603978dfdf90cef116e401684d81b85d4810e9fb2f0ceeb2b2eeb07380a90eb
openshift4/ose-insights-rhel8-operator@sha256:3e14d220ab255c0a1e66d687b4eed282ae7a692e61d612270cb5246da2ccf528
openshift4/ose-installer@sha256:9030d43a7d495618eb451fe8297ee593c02cc22dff7c8cc86808b75993345b35
openshift4/ose-installer-artifacts@sha256:0acf8988b7f4d03937774452536580b93a08918622344f5009e8adfda231d19f
openshift4/ose-oauth-apiserver-rhel8@sha256:fdbf9b93a0e45bf566a958ba1195c782d1f846261cdaf92a069f4d5d9c68a08d
openshift4/ose-ovn-kubernetes-rhel9@sha256:4a1c704f7d50eb5606ccf088a4aca50b3060581fb462b9f7a3127d09777e157d
openshift4/ose-ovn-kubernetes@sha256:4a1c704f7d50eb5606ccf088a4aca50b3060581fb462b9f7a3127d09777e157d
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:657ababb7e793e1ed9ba7e13908f2c345f56e25998e0f2c55e4b0255b3a8addb
openshift4/ose-tests@sha256:1bdbceb12d14a38ae1370b4e82e9a89663b74df2ea8c95ccc6a1d722175defc9
openshift4/ose-tools-rhel8@sha256:9bc21bca229e56c550baccc434f6f98b488ae4eb2e689cea67c4a149ab760f06

x86_64

openshift4/network-tools-rhel8@sha256:60269a5aa29426b83a521dfef0e998a35ed2b08db51d4dbae7a2500a9d1f9df0
openshift4/ose-baremetal-installer-rhel8@sha256:1e547960cd8774707494f30a00fdb00527ab1fcda7c74e41ab59711ad4504b0d
openshift4/ose-console@sha256:eb7941c1fb4b375610f60a685285e772cb494d8815811a6d121029cb3bd54544
openshift4/ose-insights-rhel8-operator@sha256:6cb35f4f02eaaf492c32a91ee5f9abaa846b6558267e87c0500d0df30652c53b
openshift4/ose-installer@sha256:72919253e509dfb7c776a74cf82c343414c5ed1b4ed3ad0e8e17047f17ec4681
openshift4/ose-installer-artifacts@sha256:ac84cefd85343c92f98b28257c2ebee68b6d42be83ba689d7a6edfbb688143b2
openshift4/ose-ironic-agent-rhel9@sha256:cd3627b822cd8074ca60337d3eefd67b2a716b67d163bd43d56e74e2088be380
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:a22eb11dc468482f9343e9060962577cd3ca939091954df21dc9c62d9db375a6
openshift4/ose-ironic-rhel9@sha256:bfcba4edcb97b835780f94564ef0c51e7dd4ff0b13cc8451f5d808d42683555f
openshift4/ose-machine-os-images-rhel8@sha256:f01d757a3a7349f99d59178f4ee962837ea83c85d102b075c6164ea8c0780f88
openshift4/ose-oauth-apiserver-rhel8@sha256:9a8ca31081d10abd43130fe8e30f489e09a41f7379f4d39a46006182a0946def
openshift4/ose-ovn-kubernetes-rhel9@sha256:1f22b54c21925946cbc7615d753e292e5856d901293d5d93785894218520be0f
openshift4/ose-ovn-kubernetes@sha256:1f22b54c21925946cbc7615d753e292e5856d901293d5d93785894218520be0f
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:4870562a9c917404094bfc0d714c156fbf6c4ea562de948761ea64ca23fb3ec4
openshift4/ose-powervs-machine-controllers-rhel8@sha256:713502845dc6380fc6e5bafa7df7c904b87b7ec8c65dcc8ef0526899bbc7c6d3
openshift4/ose-tests@sha256:a6c10ce5fd33833be1b49d48ebcb218d4adb9ee41531458f0b94729dc16a56cc
openshift4/ose-tools-rhel8@sha256:1abe60e127497932ef3fcb669f0b0dd01b051714d6cbd533257538095641edff

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility