Resource exhaustion in Go programming language - CVE-2023-24534
Published: April 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing HTTP and MIME headers in net/textproto. A remote attacker can cause an HTTP server to allocate large amounts of memory from a small request and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
Oracle Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
AdGuard Home
Red Hat OpenShift Serverless
Nomad
OpenShift Virtualization
moby
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Nomad Enterprise
Service Telemetry Framework
cert-manager Operator for Red Hat OpenShift
Consul Enterprise
Ansible Automation Platform
Migration Toolkit for Virtualization
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenStack
Operations Dashboard
Red Hat Application Interconnect
IBM MQ Operator
Cryostat
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Observability with Instana
Migration Toolkit for Containers
OpenShift Serverless Client
Red Hat OpenShift Container Platform
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
ObjectScale
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Storage Protect Server
IBM Sterling Order Management
Storage Protect Plus Container Agent
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
golang-1.13 (Ubuntu package)
golang-1.16-src (Ubuntu package)
golang-1.13-go (Ubuntu package)
golang-1.13-src (Ubuntu package)
golang-1.16 (Ubuntu package)
golang-1.16-go (Ubuntu package)
toolbox-tests
toolbox
toolbox (Red Hat package)
udica
containernetworking-plugins-debugsource
containernetworking-plugins
containernetworking-plugins-devel
containernetworking-plugins-debuginfo
containernetworking-plugins-unit-test-devel
qpid-proton (Red Hat package)
containernetworking-plugins (Red Hat package)
collectd-libpod-stats (Red Hat package)
skopeo-debuginfo
skopeo-debugsource
containers-common
skopeo
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
skupper-cli (Red Hat package)
netavark
aardvark-dns
openshift-serverless-clients (Red Hat package)
crun
jsoncpp (Red Hat package)
skopeo (Red Hat package)
fuse-overlayfs
skopeo-tests
golang-devel
golang-help
golang
golang-1.18-go (Ubuntu package)
golang-1.18-src (Ubuntu package)
golang-1.18 (Ubuntu package)
golang-1.19-src (Ubuntu package)
golang-1.19 (Ubuntu package)
golang-1.19-go (Ubuntu package)
go1.19
go1.19-doc
go1.19-race
golang-1.20-src (Ubuntu package)
golang-1.20 (Ubuntu package)
golang-1.20-go (Ubuntu package)
go1.20
go1.20-doc
go1.20-race
go1.20-debuginfo
dev-lang/go
buildah-debuginfo
buildah
buildah-debugsource
cri-o (Red Hat package)
buildah (Red Hat package)
buildah-tests
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
skupper-router (Red Hat package)
ignition-debugsource
ignition-validate
ignition-debuginfo
ignition
container-selinux (Red Hat package)
container-selinux
openvswitch3.1 (Red Hat package)
etcd (Red Hat package)
etcd
python3-criu
criu-libs
criu
crit
criu-devel
libwebsockets (Red Hat package)
libslirp-devel
libslirp
podman (Red Hat package)
python3-podman
podman-docker
podman-gvproxy
podman-tests
podman-remote
podman-plugins
podman-catatonit
podman
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-kuryr (Red Hat package)
microshift (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
grafana (Red Hat package)
openstack-ironic (Red Hat package)
ovn23.06 (Red Hat package)
cockpit-podman
watsonx.data
IBM Cloud Pak System
AMQ Broker
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2023-24534
AdGuard Home - addressed in versions 0.107.27, 0.108.0-b.32
Red Hat OpenShift Serverless - update to 1.29.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.2
OpenShift API for Data Protection (OADP) - update to 1.1.5
Nomad - addressed in versions 1.3.13, 1.4.8, 1.5.3
Nomad Enterprise - addressed in versions 1.3.13, 1.4.8, 1.5.3
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - update to 1.7.10
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
Consul Enterprise - addressed in versions 1.13.8, 1.14.7, 1.15.3
OpenShift Serverless Client - update to 1.29.0
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.9.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.2, 4.13.3, 4.13.4, 4.13.5, 4.13.6
OpenShift Virtualization - update to 4.13.3
Red Hat OpenStack - update to 16.2.5
moby - update to 23.0.4
Operations Dashboard - update to 2022.2.1-11-lts
golang-1.13 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.16-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
golang-1.13-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.13-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.16 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
golang-1.16-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
toolbox (Red Hat package) - update to 0.0.99.4-6.el9_3
udica - update to 0.2.6-20
containernetworking-plugins-debugsource - update to 0.8.6-6.gitad10b6f
containernetworking-plugins - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-devel - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-debuginfo - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-unit-test-devel - update to 0.8.6-6.gitad10b6f
qpid-proton (Red Hat package) - addressed in versions 0.37.0-2.el8ai, 0.37.0-2.el9ai
containernetworking-plugins (Red Hat package) - addressed in versions 1.0.1-7.rhaos4.13.el8, 1.0.1-8.rhaos4.13.el8, 1.3.0-4.el9
collectd-libpod-stats (Red Hat package) - update to 1.0.4-5.el8ost
skopeo-debuginfo - addressed in versions 1.1.0-9, 1.5.2-3
skopeo-debugsource - addressed in versions 1.1.0-9, 1.5.2-3
containers-common - addressed in versions 1.1.0-9, 1.5.2-3
skopeo - addressed in versions 1.1.0-9, 1.5.2-3
runc (Red Hat package) - update to 1.1.6-4.rhaos4.13.el8
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
Red Hat Application Interconnect - update to 1.4
ObjectScale - update to 1.4.0
skupper-cli (Red Hat package) - addressed in versions 1.4.1-2.el8, 1.4.1-2.el9
netavark - update to 1.7.0-2.0.1
aardvark-dns - update to 1.7.0-2.0.1
openshift-serverless-clients (Red Hat package) - update to 1.8.1-3.el8
crun - update to 1.8.7-1
jsoncpp (Red Hat package) - update to 1.9.4-3.el9
skopeo (Red Hat package) - addressed in versions 1.11.2-2.rhaos4.13.el8, 1.11.2-2.1.rhaos4.13.el9, 1.13.3-1.el9
fuse-overlayfs - update to 1.12-1.0.1
skopeo-tests - update to 1.13.3-3.0.1
skopeo - update to 1.13.3-3.0.1
golang-devel - addressed in versions 1.15.7-26, 1.15.7-50, 1.17.3-38
golang-help - addressed in versions 1.15.7-26, 1.15.7-50, 1.17.3-38
golang - addressed in versions 1.15.7-26, 1.15.7-50, 1.17.3-38
golang-1.18-go (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang-1.18-src (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang-1.18 (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang - addressed in versions 1.18.6-1.43, 1.19.8-1
golang-1.19-src (Ubuntu package) - addressed in versions 1.19.2-1ubuntu1.1, 1.19.8-1ubuntu0.1
golang-1.19 (Ubuntu package) - addressed in versions 1.19.2-1ubuntu1.1, 1.19.8-1ubuntu0.1
golang-1.19-go (Ubuntu package) - addressed in versions 1.19.2-1ubuntu1.1, 1.19.8-1ubuntu0.1
go1.19 - addressed in versions 1.19.8-150000.1.26.1, 1.19.9-150000.1.31.1
go1.19-doc - addressed in versions 1.19.8-150000.1.26.1, 1.19.9-150000.1.31.1
go1.19-race - addressed in versions 1.19.8-150000.1.26.1, 1.19.9-150000.1.31.1
golang - update to 1.19.9-1.el7
golang-1.20-src (Ubuntu package) - update to 1.20.3-1ubuntu0.1
golang-1.20 (Ubuntu package) - update to 1.20.3-1ubuntu0.1
golang-1.20-go (Ubuntu package) - update to 1.20.3-1ubuntu0.1
go1.20 - addressed in versions 1.20.3-150000.1.8.1, 1.20.4-150000.1.11.1
go1.20-doc - addressed in versions 1.20.3-150000.1.8.1, 1.20.4-150000.1.11.1
go1.20-race - addressed in versions 1.20.3-150000.1.8.1, 1.20.4-150000.1.11.1
go1.20-debuginfo - update to 1.20.4-150000.1.11.1
dev-lang/go - update to 1.20.10
buildah-debuginfo - update to 1.26.1-4
buildah - update to 1.26.1-4
buildah-debugsource - update to 1.26.1-4
cri-o (Red Hat package) - addressed in versions 1.26.3-9.rhaos4.13.git994242a.el8, 1.26.3-10.rhaos4.13.git78941bf.el8, 1.26.3-10.rhaos4.13.git994242a.el9, 1.26.3-11.rhaos4.13.git78941bf.el9
buildah (Red Hat package) - addressed in versions 1.29.1-2.rhaos4.13.el8, 1.29.1-2.1.rhaos4.13.el9, 1.31.3-1.el9
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
containers-common - update to 1-71.0.1
watsonx.data - update to 2.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
conmon (Red Hat package) - addressed in versions 2.1.7-2.rhaos4.13.el8, 2.1.7-2.1.rhaos4.13.el9
conmon - update to 2.1.8-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.13.el8
Cryostat - update to 2.3.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
skupper-router (Red Hat package) - addressed in versions 2.4.1-2.el8, 2.4.1-2.el9
ignition-debugsource - update to 2.14.0-2
ignition-validate - update to 2.14.0-2
ignition-debuginfo - update to 2.14.0-2
ignition - update to 2.14.0-2
container-selinux (Red Hat package) - update to 2.215.0-1.rhaos4.13.el8
container-selinux - update to 2.221.0-1
openvswitch3.1 (Red Hat package) - update to 3.1.0-32.el9fdp
etcd (Red Hat package) - update to 3.3.23-14.el8ost
etcd - update to 3.4.14-11
IBM Cloud Transformation Advisor - update to 3.7.0
python3-criu - update to 3.18-5
criu-libs - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
criu-devel - update to 3.18-5
Red Hat Advanced Cluster Security for Kubernetes - update to 4.1
IBM Cloud Pak for Watson AIOps - update to 4.1.2
libwebsockets (Red Hat package) - addressed in versions 4.3.1-1.el8ai, 4.3.1-1.el9ai
libslirp-devel - update to 4.4.0-1
libslirp - update to 4.4.0-1
podman (Red Hat package) - addressed in versions 4.4.1-4.rhaos4.13.el8, 4.4.1-5.1.rhaos4.13.el9, 4.6.1-5.el9
python3-podman - update to 4.6.0-1
podman-docker - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202307200611.p0.g49844f7.assembly.stream.el8, 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el8, 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.13.0-202306072143.p0.g7d22122.assembly.stream.el8, 4.13.0-202306072143.p0.g7d22122.assembly.stream.el9, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el8, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202306230038.p0.g148be47.assembly.stream.el8, 4.13.0-202306230038.p0.g148be47.assembly.stream.el9
openshift4-aws-iso (Red Hat package) - update to 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package) - update to 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8
microshift (Red Hat package) - update to 4.13.3-202306081201.p0.g16708cc.assembly.4.13.3.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0
kernel (Red Hat package) - addressed in versions 5.14.0-284.18.1.el9_2, 5.14.0-284.23.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.18.1.rt14.303.el9_2, 5.14.0-284.23.1.rt14.308.el9_2
Red Hat Migration Toolkit for Applications - update to 6.2.0
AMQ Broker - update to 7.12.0
Storage Protect Server - update to 8.1.19
grafana (Red Hat package) - update to 9.2.10-7.el9_3
IBM Sterling Order Management - update to 10.0.2403.1
Storage Protect Plus Container Agent - update to 10.1.12.6
IBM CICS TX Advanced - update to 11.1.0.0 ifix9
IBM CICS TX Standard - update to 11.1.0.0 ifix9
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.6, 23.0.6
openstack-ironic (Red Hat package) - update to 21.3.1-0.20230706125653.c8f8157.el9
ovn23.06 (Red Hat package) - update to 23.06.0-13.el9fdp
cockpit-podman - update to 75-1
IBM Observability with Instana - update to 281
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- SUSE update for go1.19
- SUSE update for go1.20
- Multiple vulnerabilities in AdGuard Home
- Multiple vulnerabilities in HashiCorp Nomad
- Multiple vulnerabilities in Moby
- Amazon Linux AMI update for golang
- Ubuntu update for golang-1.18
- SUSE update for go1.20
- SUSE update for go1.19
- SUSE update for go1.20
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Red Hat build of Cryostat on RHEL 8
- Multiple vulnerabilities in OpenShift Serverless Client
- Red Hat OpenStack Platform 16 update for etcd
- Multiple vulnerabilities in OpenShift Serverless
- Ubuntu update for golang-1.19
- Multiple vulnerabilities in HashiCorp consul
- OpenShift Container Platform 4.13 update for golang
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP)
- Multiple vulnerabilities in Red Hat Advanced Cluster Security (RHACS)
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Resource exhaustion in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Denial of service in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Resource exhaustion in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container
- Red Hat Ansible Automation Platform 2.3 update for golang
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Red Hat Application Interconnect
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Distributed Tracing
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Resource exhaustion in Operations Dashboard
- Multiple vulnerabilities in IBM Cloud Pak System
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 9 update for toolbox
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Gentoo update for Go
- Ubuntu update for golang-1.13
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Data Scheduling
- openEuler update for ignition
- openEuler update for golang
- openEuler 20.03 LTS SP1 update for skopeo
- openEuler 20.03 LTS SP3 update for skopeo
- openEuler 22.03 LTS SP1 update for skopeo
- openEuler update for containernetworking-plugins
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in AMQ Broker 7.12
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Observability with Instana
- openEuler 22.03 LTS SP4 update for buildah
- openEuler 22.03 LTS SP3 update for golang
- openEuler 20.03 LTS SP4 update for golang
- openEuler 20.03 LTS SP4 update for etcd
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data