Infinite loop in Go programming language - CVE-2023-24537
Published: April 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when calling any of the Parse functions on Go source code which contains //line directives with very large line numbers. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Astronomer with IBM
Db2 Rest
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Watson CP4D Data Stores
IBM supplied MQ Advanced container images
IBM Sterling Order Management
Storage Protect Plus Container Agent
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Amazon Linux AMI
Oracle Linux
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Fedora
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
AdGuard Home
Event Streams
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Serverless
OpenShift Virtualization
moby
Migration Toolkit for Containers
OpenShift Serverless Client
Red Hat OpenShift Container Platform
cert-manager Operator for Red Hat OpenShift
Consul Enterprise
Ansible Automation Platform
Migration Toolkit for Virtualization
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenStack
Red Hat Application Interconnect
IBM MQ Operator
IBM Spectrum Copy Data Management
Cryostat
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Spectrum Protect Storage Agent
IBM Spectrum Protect Plus
IBM Observability with Instana
Operations Dashboard
QRadar Suite
golang-1.13 (Ubuntu package)
golang-1.13-go (Ubuntu package)
golang-1.13-src (Ubuntu package)
golang-1.16 (Ubuntu package)
golang-1.16-go (Ubuntu package)
golang-1.16-src (Ubuntu package)
toolbox-tests
toolbox
udica
containernetworking-plugins
containernetworking-plugins-debugsource
containernetworking-plugins-debuginfo
containernetworking-plugins-unit-test-devel
containernetworking-plugins-devel
qpid-proton (Red Hat package)
containernetworking-plugins (Red Hat package)
collectd-libpod-stats (Red Hat package)
skopeo-debuginfo
skopeo-debugsource
skopeo
containers-common
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
skupper-cli (Red Hat package)
aardvark-dns
netavark
openshift-serverless-clients (Red Hat package)
crun
jsoncpp (Red Hat package)
skopeo (Red Hat package)
fuse-overlayfs
skopeo-tests
golang
golang-devel
golang-help
golang-1.18 (Ubuntu package)
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.19-go (Ubuntu package)
golang-1.19-src (Ubuntu package)
golang-1.19 (Ubuntu package)
go1.19
go1.19-race
go1.19-doc
go-toolset-1.19-golang (Red Hat package)
go-toolset-1.19 (Red Hat package)
golang-1.20-src (Ubuntu package)
golang-1.20 (Ubuntu package)
golang-1.20-go (Ubuntu package)
go1.20-doc
go1.20-race
go1.20
go1.20-debuginfo
dev-lang/go
buildah
buildah-debuginfo
buildah-debugsource
cri-o (Red Hat package)
buildah (Red Hat package)
buildah-tests
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
skupper-router (Red Hat package)
ignition-validate
ignition
ignition-debuginfo
ignition-debugsource
container-selinux (Red Hat package)
container-selinux
openvswitch3.1 (Red Hat package)
etcd (Red Hat package)
etcd
crit
criu
criu-devel
criu-libs
python3-criu
libwebsockets (Red Hat package)
libslirp
libslirp-devel
podman (Red Hat package)
python3-podman
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-kuryr (Red Hat package)
microshift (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
openstack-ironic (Red Hat package)
ovn23.06 (Red Hat package)
cockpit-podman
watsonx.data
AMQ Broker
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2023-24537
AdGuard Home - addressed in versions 0.107.27, 0.108.0-b.32
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.2
Astronomer with IBM - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.29.0
OpenShift API for Data Protection (OADP) - update to 1.1.5
Migration Toolkit for Containers - update to 1.7.10
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
QRadar Suite - update to 1.10.18.0
Consul Enterprise - addressed in versions 1.13.8, 1.14.7, 1.15.3
OpenShift Serverless Client - update to 1.29.0
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.9.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.2, 4.13.3, 4.13.4, 4.13.5, 4.13.6
OpenShift Virtualization - update to 4.13.3
Red Hat OpenStack - update to 16.2.5
moby - update to 23.0.4
golang-1.13 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.13-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.13-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.13.8-1ubuntu1.2, 1.13.8-1ubuntu2.22.04.2
golang-1.16 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
golang-1.16-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
golang-1.16-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.16.2-0ubuntu1~20.04.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
containernetworking-plugins - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-debugsource - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-debuginfo - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-unit-test-devel - update to 0.8.6-6.gitad10b6f
containernetworking-plugins-devel - update to 0.8.6-6.gitad10b6f
qpid-proton (Red Hat package) - addressed in versions 0.37.0-2.el8ai, 0.37.0-2.el9ai
Db2 Rest - update to 1.0.0.266
containernetworking-plugins (Red Hat package) - addressed in versions 1.0.1-7.rhaos4.13.el8, 1.0.1-8.rhaos4.13.el8
collectd-libpod-stats (Red Hat package) - update to 1.0.4-5.el8ost
skopeo-debuginfo - addressed in versions 1.1.0-9, 1.5.2-2, 1.5.2-3
skopeo-debugsource - addressed in versions 1.1.0-9, 1.5.2-2, 1.5.2-3
skopeo - addressed in versions 1.1.0-9, 1.5.2-2, 1.5.2-3
containers-common - addressed in versions 1.1.0-9, 1.5.2-2, 1.5.2-3
runc (Red Hat package) - update to 1.1.6-4.rhaos4.13.el8
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
Red Hat Application Interconnect - update to 1.4
ObjectScale - update to 1.4.0
skupper-cli (Red Hat package) - addressed in versions 1.4.1-2.el8, 1.4.1-2.el9
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
openshift-serverless-clients (Red Hat package) - update to 1.8.1-3.el8
crun - update to 1.8.7-1
jsoncpp (Red Hat package) - update to 1.9.4-3.el9
skopeo (Red Hat package) - addressed in versions 1.11.2-2.rhaos4.13.el8, 1.11.2-2.1.rhaos4.13.el9, 1.13.3-1.el9
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
golang - addressed in versions 1.15.7-26, 1.15.7-50, 1.17.3-38
golang-devel - addressed in versions 1.15.7-26, 1.15.7-50, 1.17.3-38
golang-help - addressed in versions 1.15.7-26, 1.15.7-50, 1.17.3-38
golang-1.18 (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang-1.18-src (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang-1.18-go (Ubuntu package) - addressed in versions 1.18.1-1ubuntu1.1, 1.18.1-1ubuntu1~18.04.4, 1.18.1-1ubuntu1~20.04.2
golang - addressed in versions 1.18.6-1.43, 1.19.8-1
golang-1.19-go (Ubuntu package) - addressed in versions 1.19.2-1ubuntu1.1, 1.19.8-1ubuntu0.1
golang-1.19-src (Ubuntu package) - addressed in versions 1.19.2-1ubuntu1.1, 1.19.8-1ubuntu0.1
golang-1.19 (Ubuntu package) - addressed in versions 1.19.2-1ubuntu1.1, 1.19.8-1ubuntu0.1
go1.19 - addressed in versions 1.19.8-150000.1.26.1, 1.19.9-150000.1.31.1
go1.19-race - addressed in versions 1.19.8-150000.1.26.1, 1.19.9-150000.1.31.1
go1.19-doc - addressed in versions 1.19.8-150000.1.26.1, 1.19.9-150000.1.31.1
golang - update to 1.19.9-1.el7
go-toolset-1.19-golang (Red Hat package) - update to 1.19.9-1.el7_9
go-toolset-1.19 (Red Hat package) - update to 1.19.9-1.el7_9
golang-1.20-src (Ubuntu package) - update to 1.20.3-1ubuntu0.1
golang-1.20 (Ubuntu package) - update to 1.20.3-1ubuntu0.1
golang-1.20-go (Ubuntu package) - update to 1.20.3-1ubuntu0.1
go1.20-doc - addressed in versions 1.20.3-150000.1.8.1, 1.20.4-150000.1.11.1
go1.20-race - addressed in versions 1.20.3-150000.1.8.1, 1.20.4-150000.1.11.1
go1.20 - addressed in versions 1.20.3-150000.1.8.1, 1.20.4-150000.1.11.1
go1.20-debuginfo - update to 1.20.4-150000.1.11.1
dev-lang/go - update to 1.20.10
buildah - update to 1.26.1-4
buildah-debuginfo - update to 1.26.1-4
buildah-debugsource - update to 1.26.1-4
cri-o (Red Hat package) - addressed in versions 1.26.3-9.rhaos4.13.git994242a.el8, 1.26.3-10.rhaos4.13.git78941bf.el8, 1.26.3-10.rhaos4.13.git994242a.el9, 1.26.3-11.rhaos4.13.git78941bf.el9
buildah (Red Hat package) - addressed in versions 1.29.1-2.rhaos4.13.el8, 1.29.1-2.1.rhaos4.13.el9
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
containers-common - update to 1-71.0.1
watsonx.data - update to 2.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
conmon (Red Hat package) - addressed in versions 2.1.7-2.rhaos4.13.el8, 2.1.7-2.1.rhaos4.13.el9
conmon - update to 2.1.8-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.13.el8
IBM Spectrum Copy Data Management - update to 2.2.20.0
Cryostat - update to 2.3.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
skupper-router (Red Hat package) - addressed in versions 2.4.1-2.el8, 2.4.1-2.el9
Cloud Pak for Network Automation - update to 2.4.7
ignition-validate - update to 2.14.0-2
ignition - update to 2.14.0-2
ignition-debuginfo - update to 2.14.0-2
ignition-debugsource - update to 2.14.0-2
container-selinux (Red Hat package) - update to 2.215.0-1.rhaos4.13.el8
container-selinux - update to 2.221.0-1
openvswitch3.1 (Red Hat package) - update to 3.1.0-32.el9fdp
etcd (Red Hat package) - update to 3.3.23-14.el8ost
etcd - update to 3.4.14-11
IBM Cloud Transformation Advisor - update to 3.7.0
crit - update to 3.18-5
criu - update to 3.18-5
criu-devel - update to 3.18-5
criu-libs - update to 3.18-5
python3-criu - update to 3.18-5
IBM Cloud Pak for Watson AIOps - update to 4.1.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.1
libwebsockets (Red Hat package) - addressed in versions 4.3.1-1.el8ai, 4.3.1-1.el9ai
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
podman (Red Hat package) - addressed in versions 4.4.1-4.rhaos4.13.el8, 4.4.1-5.1.rhaos4.13.el9, 4.6.1-5.el9
python3-podman - update to 4.6.0-1
podman-docker - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202307200611.p0.g49844f7.assembly.stream.el8, 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el8, 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.13.0-202306072143.p0.g7d22122.assembly.stream.el8, 4.13.0-202306072143.p0.g7d22122.assembly.stream.el9, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el8, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202306230038.p0.g148be47.assembly.stream.el8, 4.13.0-202306230038.p0.g148be47.assembly.stream.el9
openshift4-aws-iso (Red Hat package) - update to 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package) - update to 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8
microshift (Red Hat package) - update to 4.13.3-202306081201.p0.g16708cc.assembly.4.13.3.el9
Watson CP4D Data Stores - update to 5.0.3
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0
kernel (Red Hat package) - addressed in versions 5.14.0-284.18.1.el9_2, 5.14.0-284.23.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.18.1.rt14.303.el9_2, 5.14.0-284.23.1.rt14.308.el9_2
Red Hat Migration Toolkit for Applications - update to 6.2.0
AMQ Broker - update to 7.12.0
IBM Spectrum Protect Storage Agent - update to 8.1.19
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM Sterling Order Management - update to 10.0.2403.1
Storage Protect Plus Container Agent - update to 10.1.12.6
IBM Spectrum Protect Plus - update to 10.1.15
IBM CICS TX Standard - update to 11.1.0.0 ifix9
IBM CICS TX Advanced - update to 11.1.0.0 ifix9
Event Streams - update to 11.2.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.6, 23.0.6
openstack-ironic (Red Hat package) - update to 21.3.1-0.20230706125653.c8f8157.el9
ovn23.06 (Red Hat package) - update to 23.06.0-13.el9fdp
cockpit-podman - update to 75-1
IBM Observability with Instana - update to 281
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-8, 2022.2.1-9, 2022.4.1-4
Operations Dashboard - update to 2022.2.1-12-lts
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- SUSE update for go1.19
- SUSE update for go1.20
- Multiple vulnerabilities in AdGuard Home
- Multiple vulnerabilities in Moby
- Amazon Linux AMI update for golang
- Ubuntu update for golang-1.18
- Multiple vulnerabilities in IBM Db2 REST
- SUSE update for go1.20
- SUSE update for go1.19
- SUSE update for go1.20
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Red Hat build of Cryostat on RHEL 8
- Red Hat Developer Tools update for go-toolset-1.19 and go-toolset-1.19-golang
- Multiple vulnerabilities in Platform Navigator in IBM Cloud Pak for Integration (CP4I)
- Multiple vulnerabilities in OpenShift Serverless Client
- Red Hat OpenStack Platform 16 update for etcd
- Multiple vulnerabilities in OpenShift Serverless
- Ubuntu update for golang-1.19
- Multiple vulnerabilities in HashiCorp consul
- OpenShift Container Platform 4.13 update for golang
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP)
- Multiple vulnerabilities in Red Hat Advanced Cluster Security (RHACS)
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Infinite loop in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Infinite loop in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container
- Red Hat Ansible Automation Platform 2.3 update for golang
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Red Hat Application Interconnect
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in Red Hat OpenShift Distributed Tracing
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Gentoo update for Go
- Ubuntu update for golang-1.13
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cloud Pak for Data Scheduling
- openEuler update for ignition
- openEuler update for golang
- openEuler 20.03 LTS SP1 update for skopeo
- openEuler 20.03 LTS SP3 update for skopeo
- openEuler 22.03 LTS SP1 update for skopeo
- openEuler 22.03 LTS SP2 update for skopeo
- openEuler update for containernetworking-plugins
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in AMQ Broker 7.12
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Watson CP4D Data Stores
- Multiple vulnerabilities in IBM Observability with Instana
- openEuler 22.03 LTS SP4 update for buildah
- openEuler 22.03 LTS SP3 update for golang
- openEuler 20.03 LTS SP4 update for golang
- openEuler 20.03 LTS SP4 update for etcd
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM Astronomer with IBM