Red Hat released security updates across OpenShift Container Platform (OCP), OpenShift Serverless, Service Mesh, API for Data Protection (OADP), Advanced Cluster Security, Virtualization, Distributed Tracing, Cryostat, and related operators. The advisories remediate multiple Go defects, led by CVE-2022-41723, an HTTP/2 HPACK-decoding flaw that lets crafted streams consume excessive CPU through quadratic processing and cause denial of service. Updates also address CVE-2022-41717, where oversized HTTP/2 header keys can allocate roughly 64 MiB per connection, and CVE-2022-41715, which allows certain regular expressions to drive disproportionate memory use during parsing.
Several releases additionally fix CVE-2023-25173 in containerd, which could allow a user with container access to manipulate supplementary-group permissions and bypass primary-group restrictions within that container. OCP 4.13 updates also remediate the FIPS-mode issue tracked as CVE-2023-3089, Kubernetes privilege-escalation and runc mount-race issues, plus other Go resource-exhaustion and template-processing flaws. Red Hat advises affected customers to upgrade packages and container images through supported OpenShift release channels; environments using vulnerable standalone containerd versions should upgrade to 1.6.18 or 1.5.18 and recreate containers.

See real exploitation activity before you spend the cycle.
37 events from the most recent confirmed update back to the earliest known activity.
RHSA-2023:5314 released OpenShift API for Data Protection 1.1.6, fixing CVE-2022-41723, CVE-2023-2253, CVE-2023-24532, CVE-2023-25173, and a Prometheus client denial-of-service flaw.
RHSA-2023:4986 released updated Distributed Tracing 2.9 images, replacing or upgrading version 2.8 images and fixing Go denial-of-service and parsing vulnerabilities CVE-2023-24534, CVE-2023-24536, CVE-2023-24537, and CVE-2023-24538.
RHSA-2023:4664 released OpenShift Virtualization 4.13.3 images and remediated CVE-2023-3089, CVE-2022-41723, and several Go HTTP, parser, and template vulnerabilities.
RHSA-2023:4335 remediated the Go HTTP and MIME header parsing memory-exhaustion flaw CVE-2023-24534 in cert-manager 1.10 for RHEL 9, including cert-manager operator, bundle, and Jetstack cert-manager container components.
RHSA-2023:4472 released OpenShift Serverless 1.29.1 for OpenShift Container Platform 4.10 through 4.13. The update fixed the FIPS-mode issue CVE-2023-3089 and Go html/template flaws CVE-2023-24539 and CVE-2023-29400.
RHSA-2023:4226 released OCP 4.13.6 images, fixing CVE-2022-41723's quadratic HPACK-decoding denial of service and CVE-2023-25173's containerd supplementary-group handling flaw.
RHSA-2023:4091 and RHSA-2023:4093 released OCP 4.13.5 container images and RPMs. The update fixed CVE-2023-3089, kube-apiserver privilege escalation CVE-2023-1260, Go flaws, an runc mount race, and HTTP/2 denial-of-service issues.
RHSA-2023:4113 released OpenShift Service Mesh 2.3.5 images, fixing CVE-2023-3089 and CVE-2022-41723 across supported RHEL 8 architectures.
RHSA-2023:4112 released OpenShift Service Mesh 2.2.8 container updates for RHEL 8, remediating CVE-2023-3089 and the HPACK decoding flaw CVE-2022-41723.
Red Hat closed Bug 2212085 for CVE-2023-3089, the OpenShift Container Platform FIPS-mode issue.
RHSA-2023:3910 made OpenShift Container Platform 4.10.63 RPM packages available, remediating the FIPS-mode issue CVE-2023-3089, Go html/template flaw CVE-2023-24540, and HTTP/2 memory-growth vulnerability CVE-2022-41717. Red Hat issued a separate advisory, RHSA-2023:3911, for the associated container images.
RHSA-2023:3943 updated Red Hat Advanced Cluster Security 4.1 images to fix CVE-2022-41723 and Go SSH, HTTP resource-consumption, parser, and template-processing vulnerabilities.
RHSA-2023:3918 made OpenShift API for Data Protection 1.1.5 available, remediating CVE-2022-41723 and multiple Go denial-of-service and html/template vulnerabilities.
RHSA-2023:3455 released OpenShift Serverless 1.29.0 and fixed CVE-2023-25173 in containerd, CVE-2022-41723 in HTTP/2 HPACK decoding, and additional Go vulnerabilities.
Nick Tait reported Red Hat Bug 2212085 for CVE-2023-3089, also known as woodpecker, concerning OpenShift Container Platform and FIPS mode.
RHSA-2023:3204 released OpenShift Virtualization 4.13.0 kubevirt and virtctl RPM updates for affected RHEL 7, 8, and 9 deployments. The Moderate-severity advisory remediated Go flaws including CVE-2022-41717, CVE-2022-27664, CVE-2022-32149, CVE-2022-32189, and CVE-2022-32190.
RHSA-2023:3167 released Cryostat 2.3.0 RHEL 8 container images with fixes for CVE-2022-41723 and several Go resource-exhaustion, TLS, and parser vulnerabilities.
RHSA-2023:0584 updated the Secondary Scheduler Operator for OpenShift, fixing multiple Go vulnerabilities including CVE-2022-41715, CVE-2022-41717, CVE-2022-41724, and CVE-2022-41725.
Red Hat issued RHSA-2023:1372 for OpenShift support for Windows Containers 8.0.0 on OpenShift Container Platform 4.13 for RHEL 9 x86_64. The Moderate update remediated CVE-2022-41717 in Go HTTP/2 servers and CVE-2023-25173 in containerd, while updating Windows Machine Config Operator components.
RHSA-2023:1174 released OpenShift API for Data Protection 1.1.2 for RHEL 8, fixing CVE-2022-2879, CVE-2022-2880, CVE-2022-41715, and CVE-2022-41717 and updating Velero and Restic to 1.9.5.
RHSA-2023:0632 remediated CVE-2022-41717 in the affected openshift-logging/lokistack-gateway-rhel8 component.
Red Hat released RHSA-2023:0692 to fix CVE-2022-41717 in the OpenShift API for Data Protection 1.0 RHEL 8 oadp-registry component.
RHSA-2023:0709 released OpenShift Serverless 1.27.0, including Eventing and Serving updates that fixed Go regular-expression, HTTP/2, ReverseProxy, and tar-header vulnerabilities.
RHSA-2023:0708 released updated kn client packages for RHEL 8, remediating Go flaws including CVE-2022-41715, CVE-2022-27664, CVE-2022-2880, and CVE-2022-2879.
RHBA-2023:0568 updated several OpenShift Container Platform 4.12 components, including atomic-openshift-service-idler, buildah, containers-common, kernel, and kernel-rt, to remediate the Go net/url JoinPath directory-traversal flaw CVE-2022-32190.
Red Hat published its record for CVE-2022-41717, documenting that large attacker-controlled HTTP/2 header keys could cause approximately 64 MiB of memory allocation per open Go server connection.
Red Hat issued RHSA-2022:8634 for OpenShift API for Data Protection 1.1.1 on RHEL 8 x86_64. The Moderate-severity update fixed Go vulnerabilities including CVE-2022-27191, CVE-2022-27664, CVE-2022-30632, CVE-2022-30635, and CVE-2022-32190, alongside OADP backup and restore fixes.
Red Hat reported Bug 2132872 for CVE-2022-41715, a Go regexp/syntax flaw that could allow crafted regular expressions to exhaust memory during parsing.
Tej Rathi reported CVE-2022-32190, in which Go's JoinPath and URL.JoinPath could leave ../ components appended to a relative path instead of cleaning them as documented. The issue was tracked upstream as golang/go issue 54385.
Red Hat issued RHSA-2022:6040, an Important security advisory, releasing OpenShift Serverless 1.24.0 for RHEL 8 x86_64. The update remediated vulnerabilities in Prometheus client_golang, go-restful, and Go standard-library components, including authorization-bypass, header-sanitization, TLS, panic, and stack-exhaustion flaws.
Red Hat documented CVE-2023-24539, in which Go html/template did not treat angle brackets as dangerous in CSS contexts. Templates with multiple actions separated by a slash could prematurely close the CSS context and enable unintended HTML injection when rendered with untrusted input; Go fixed the issue on master and Go 1.19 and 1.20 branches.
Red Hat documented CVE-2023-29400, a Go html/template flaw in which empty values used in unquoted HTML attributes can be changed by HTML normalization and potentially permit arbitrary attribute injection. Upstream tracked the issue as Go issue 59722 and fixed it on the master, Go 1.19, and Go 1.20 branches.
RHBA-2023:6109 fixed the affected mtv-must-gather-api-rhel8 package in Migration Toolkit for Virtualization 2.4 for CVE-2022-41723.
Red Hat closed Bug 2132872, its tracking record for the Go regexp/syntax memory-exhaustion vulnerability CVE-2022-41715.
RHSA-2023:1817 fixed affected Network Observability 1.2.0 RHEL 9 components for CVE-2022-41717.
RHSA-2023:0934 remediated CVE-2022-41717 in MTA 6.0 RHEL 8 mta-admin-addon, mta-hub, and mta-windup-addon components.
RHSA-2023:0931 fixed CVE-2022-41717 in the affected openshift-logging/eventrouter-rhel8 component.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
39 references tracked. Mallory keeps watching after this page renders.
golang.org
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcegroups.google.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.