Lucene search

K
redhatRedHatRHSA-2023:6839
HistoryNov 15, 2023 - 12:00 p.m.

(RHSA-2023:6839) Important: OpenShift Container Platform 4.14.2 security update

2023-11-1512:00:28
access.redhat.com
20
red hat microshift
security update
kubernetes orchestration
edge device deployment
rpm packages
cve-2023-44487
rapid reset attack
ddos attack

7.3 High

AI Score

Confidence

Low

0.732 High

EPSS

Percentile

98.1%

Red Hat build of MicroShift is Red Hat’s light-weight Kubernetes
orchestration solution designed for edge device deployments and is built
from the edge capabilities of Red Hat OpenShift. MicroShift is an
application that is deployed on top of Red Hat Enterprise Linux devices at
the edge, providing an efficient way to operate single-node clusters in
these low-resource environments.

This advisory contains the RPM packages for Red Hat build of MicroShift
4.14.2. Read the following advisory for the container images for this
release:

https://access.redhat.com/errata/RHSA-2023:6837

All of the bug fixes may not be documented in this advisory. Read the
following release notes documentation for details about these changes:

https://access.redhat.com/documentation/en-us/red_hat_build_of_microshift/4.14/html/release_notes/index

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive
    work (CVE-2023-44487) (CVE-2023-39325)
  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS
    attack (Rapid Reset Attack) (CVE-2023-44487)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s)
listed in the References section.