Red Hat released Important updates for the etcd component in Red Hat OpenStack Platform 16.1 and 16.2 on RHEL 8, correcting incomplete OpenStack-specific fixes tracked as CVE-2024-4436, CVE-2024-4437, and CVE-2024-4438. CVE-2024-4438 left prior remediation for CVE-2023-39325 and the HTTP/2 Rapid Reset flaw, CVE-2023-44487, incomplete because the package compiled against the upstream golang.org/x/net/http2 implementation rather than Red Hat's supplied version.
The advisories also remediate Go vulnerabilities affecting HTTP/2, HTTP request resource consumption, TLS/QUIC post-handshake processing, and HTML template handling. Organizations running affected OpenStack deployments should install etcd version 3.3.23-16.el8ost for x86_64 or ppc64le; Red Hat also issued remediation for OpenStack Platform 17.1 on RHEL 9 through RHSA-2024:2729.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:3467 for etcd in Red Hat OpenStack Platform 16.1 on RHEL 8, supplying etcd-3.3.23-16.el8ost packages for x86_64 and ppc64le. The update addressed the three OpenStack-specific incomplete fixes and several Go HTTP/2, TLS/QUIC, and HTML-template vulnerabilities.
Red Hat issued Important advisory RHSA-2024:3352 for etcd in Red Hat OpenStack Platform 16.2, providing version 3.3.23-16.el8ost packages for x86_64 and IBM Power ppc64le. The update remediated incomplete fixes tracked as CVE-2024-4436, CVE-2024-4437, and CVE-2024-4438, along with multiple Go vulnerabilities.
Red Hat issued Important advisory RHSA-2023:5965 for etcd and collectd-libpod-stats in Red Hat OpenStack Platform 16.2.5 (Train), providing etcd-3.3.23-15.el8ost for x86_64 and ppc64le. The update addressed HTTP/2 Rapid Reset (CVE-2023-44487), Go excessive-work flaw CVE-2023-39325, and Go Host-header and TLS certificate-chain issues including CVE-2023-29406 and CVE-2023-29409.
Red Hat issued Important advisory RHSA-2023:5964 for collectd-libpod-stats in Red Hat OpenStack Platform 16.2.5, supplying version 1.0.4-5.el8ost for x86_64 and IBM Power ppc64le. The update addressed HTTP/2 Rapid Reset (CVE-2023-44487), Go excessive-work flaw CVE-2023-39325, and seven additional Go vulnerabilities.
Red Hat issued Important advisory RHSA-2023:5967 for Red Hat OpenStack Platform 16.1.9 (Train), updating etcd and collectd-libpod-stats for x86_64 and IBM Power ppc64le. The update addressed HTTP/2 Rapid Reset (CVE-2023-44487) and Go excessive-work flaw CVE-2023-39325.
Red Hat issued Important advisory RHSA-2023:5969 for Red Hat OpenStack Platform 17.1.1 on RHEL 9 x86_64. The update revised collectd-libpod-stats, etcd, and python-octavia-tests-tempest to address HTTP/2 Rapid Reset (CVE-2023-44487), the related Go excessive-work flaw (CVE-2023-39325), and CVE-2023-29409.
Red Hat remediated CVE-2023-24580, in which Go HTML/template escaping failed to treat ES6 backticks as JavaScript string delimiters, permitting attacker-controlled template-action content to inject JavaScript. Fixes were issued for Developer Tools, OpenShift, OpenStack, RHEL, Ceph Storage, middleware, and other products through advisories from May 2023 through May 2024.
Red Hat tracked CVE-2023-24534, a Go net/http and net/textproto parsing flaw that can cause excessive memory allocation and denial of service from attacker-controlled HTTP or MIME headers. Red Hat issued fixes across EPEL, Fedora, RHEL, OpenShift, OpenStack, container, cloud, automation, and middleware products through numerous RHSA advisories.
Red Hat addressed CVE-2024-4438 in Red Hat OpenStack Platform 17.1 for RHEL 9 through RHSA-2024:2729. The incomplete remediation for CVE-2023-39325 and Rapid Reset (CVE-2023-44487) resulted from etcd using upstream golang.org/x/net/http2 rather than the RHEL-supplied implementation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.