Resource exhaustion in Go programming language - CVE-2023-39326

 

Resource exhaustion in Go programming language - CVE-2023-39326

Published: December 6, 2023


Vulnerability identifier: #VU83928
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-39326
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP chunked requests. A remote attacker can send specially crafted HTTP requests to the server and consume excessive memory resources.


Affected software

Go programming language
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Development Tools Module
openSUSE Leap
openEuler
Ubuntu
IBM Cloud Pak for Data Scheduling
Service Interconnect
Service Telemetry Framework
Consul Enterprise
Cryostat
Red Hat OpenShift distributed tracing (RHOSDT)
OpenShift Logging
Red Hat Migration Toolkit for Applications
Operations Dashboard
IBM Concert Software
Run Once Duration Override Operator for Red Hat OpenShift
DataPower Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Splunk Add-on for Amazon Web Services
Red Hat OpenStack
IBM Observability with Instana
AdGuard Home
IBM Qradar SIEM
Event Streams
Red Hat OpenShift Serverless
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
OpenShift Serverless Client
Red Hat OpenShift Container Platform
IBM DataPower Gateway
Juniper Secure Analytics (JSA)
Splunk Enterprise
toolbox (Red Hat package)
toolbox-tests
toolbox
collectd-sensubility (Red Hat package)
udica
rust-bootupd (Red Hat package)
rhc-worker-script (Red Hat package)
amazon-ecr-credential-helper
coreos-installer (Red Hat package)
containernetworking-plugins
runc
runc (Red Hat package)
cni-plugins
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
receptor (Red Hat package)
nerdctl
containerd
crun
aardvark-dns
openshift-serverless-clients (Red Hat package)
netavark
skopeo (Red Hat package)
fuse-overlayfs
crun (Red Hat package)
skopeo-tests
skopeo
golang
golang-devel
golang-help
go-toolset-1.19-golang (Red Hat package)
delve
golang-1.20-src (Ubuntu package)
golang-1.20-go (Ubuntu package)
golang-1.20 (Ubuntu package)
go-toolset
golang (Red Hat package)
go1.20-openssl-doc
go1.20-openssl-race
go1.20-openssl-debuginfo
go1.20-openssl
golang-src
golang-bin
golang-tests
golang-misc
golang-docs
go1.20-race
go1.20-doc
go1.20-debuginfo
go1.20
golang-1.21 (Ubuntu package)
golang-1.21-src (Ubuntu package)
golang-1.21-go (Ubuntu package)
go1.21-openssl-race
go1.21-openssl
go1.21-openssl-doc
go1.21-race
go1.21-doc
go1.21
dev-lang/go
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah-tests
buildah
ecs-init
containers-common
amazon-cloudwatch-agent
conmon (Red Hat package)
conmon
ansible-runner (Red Hat package)
ansible-core (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
amazon-ssm-agent
etcd
etcd (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
criu-devel
python3-criu
criu-libs
crit
criu
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
python3x-django (Red Hat package)
python-django (Red Hat package)
libslirp
libslirp-devel
podman (Red Hat package)
automation-controller (Red Hat package)
python3-podman
ose-aws-ecr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
microshift (Red Hat package)
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
docker
cockpit-podman
ostree (Red Hat package)
rpm-ostree (Red Hat package)
Db2 Rest
DB2 on Cloud Pak for Data
Watson CP4D Data Stores
Storage Protect Server
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
IBM Cloud Pak System
IBM Security Verify Access
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2023-39326

Install updates from vendor's website.

Go programming language - addressed in versions 1.20.12, 1.21.5
AdGuard Home - addressed in versions 0.107.42, 0.108.0-b.51
Red Hat OpenShift Serverless - update to 1.31.1
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
Consul Enterprise - addressed in versions 1.15.8, 1.16.4, 1.17.1
OpenShift Serverless Client - update to 1.31.1
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.56, 4.14.14, 4.15.0
OpenShift Logging - addressed in versions 5.6.16, 5.7.11, 5.8.3
Red Hat Migration Toolkit for Applications - addressed in versions 7.0.2, 7.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Event Streams - update to 11.3.2
toolbox (Red Hat package) - addressed in versions 0.0.99.5-2.el9, 0.1.2-1.rhaos4.15.el9
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
collectd-sensubility (Red Hat package) - addressed in versions 0.2.1-3.el8ost, 0.2.1-3.el9ost
udica - update to 0.2.6-21
rust-bootupd (Red Hat package) - update to 0.2.17-1.el9
rhc-worker-script (Red Hat package) - update to 0.6-1.el7_9
amazon-ecr-credential-helper - update to 0.7.1-4
coreos-installer (Red Hat package) - update to 0.17.0-3.rhaos4.15.el9
Db2 Rest - update to 1.0.0.301
IBM Concert Software - update to 1.0.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.1.0
containernetworking-plugins - addressed in versions 1.1.1-6.0.1, 1.4.0-2.0.1
runc - update to 1.1.11-1.1
runc (Red Hat package) - update to 1.1.12-1.rhaos4.15.el9
runc - update to 1.1.12-1.0.1
cni-plugins - update to 1.2.0-1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - addressed in versions 1.2.5-2.0.1, 1.2.10-1
containernetworking-plugins (Red Hat package) - update to 1.4.0-2.el9_4
receptor (Red Hat package) - addressed in versions 1.4.5-1.el8ap, 1.4.5-1.el9ap
Network Observability plugin for the Openshift Console - update to 1.6.0
DataPower Operator - addressed in versions 1.6.13, 1.9.1
nerdctl - update to 1.7.2-1
containerd - update to 1.7.11-1
crun - addressed in versions 1.8.7-1.0.1, 1.14.3-2
aardvark-dns - update to 1.10.0-2.0.1
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
netavark - update to 1.10.3-1.0.1
skopeo (Red Hat package) - addressed in versions 1.11.2-21.1.rhaos4.15.el9, 1.13.3-4.el9_3
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14-1.rhaos4.15.el9
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - addressed in versions 1.15.7-37, 1.21.4-31
golang-devel - addressed in versions 1.15.7-37, 1.21.4-31
golang-help - addressed in versions 1.15.7-37, 1.21.4-31
go-toolset-1.19-golang (Red Hat package) - update to 1.19.13-5.el7_9
delve - update to 1.20.2-1.0.1
golang-1.20-src (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20-go (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20 (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
go-toolset - update to 1.20.12-1
golang - addressed in versions 1.20.12-1.el7, 1.21.6-1.fc39
golang (Red Hat package) - update to 1.20.12-1.el9_3
golang - update to 1.20.12-1.49
go1.20-openssl-doc - update to 1.20.12.1-150000.1.17.1
go1.20-openssl-race - update to 1.20.12.1-150000.1.17.1
go1.20-openssl-debuginfo - update to 1.20.12.1-150000.1.17.1
go1.20-openssl - update to 1.20.12.1-150000.1.17.1
golang-src - update to 1.20.12-2.0.1
golang-bin - update to 1.20.12-2.0.1
golang-tests - update to 1.20.12-2.0.1
golang-misc - update to 1.20.12-2.0.1
golang - update to 1.20.12-2.0.1
golang-docs - update to 1.20.12-2.0.1
go1.20-race - update to 1.20.12-150000.1.35.1
go1.20-doc - update to 1.20.12-150000.1.35.1
go1.20-debuginfo - update to 1.20.12-150000.1.35.1
go1.20 - update to 1.20.12-150000.1.35.1
golang-1.21 (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-src (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-go (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
go1.21-openssl-race - update to 1.21.5.1-150000.1.8.1
go1.21-openssl - update to 1.21.5.1-150000.1.8.1
go1.21-openssl-doc - update to 1.21.5.1-150000.1.8.1
go1.21-race - update to 1.21.5-150000.1.18.1
go1.21-doc - update to 1.21.5-150000.1.18.1
go1.21 - update to 1.21.5-150000.1.18.1
dev-lang/go - update to 1.22.3
cri-tools (Red Hat package) - update to 1.28.0-3.el9
cri-o (Red Hat package) - update to 1.28.3-14.rhaos4.15.git33aabd8.el9
buildah (Red Hat package) - addressed in versions 1.29.1-20.2.rhaos4.15.el9, 1.33.6-2.el9
buildah-tests - update to 1.33.7-1
buildah - update to 1.33.7-1
ecs-init - update to 1.80.0-1
containers-common - update to 1-81.0.1
amazon-cloudwatch-agent - update to 1.300032.3-1
conmon (Red Hat package) - update to 2.1.7-1.2.rhaos4.14.el9
conmon - update to 2.1.10-1
IBM Cloud Pak System - update to 2.3.4.0
ansible-runner (Red Hat package) - addressed in versions 2.3.6-1.el8ap, 2.3.6-1.el9ap
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
ansible-core (Red Hat package) - addressed in versions 2.15.10-1.el8ap, 2.15.10-1.el9ap
ignition (Red Hat package) - update to 2.16.2-2.rhaos4.15.el9
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.15.el9
container-selinux - update to 2.229.0-2
amazon-ssm-agent - update to 3.2.2222.0-1
etcd - addressed in versions 3.4.14-11, 3.4.14-16
etcd (Red Hat package) - update to 3.4.26-8.el9ost
python3x-aiohttp (Red Hat package) - update to 3.9.3-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.3-1.el9ap
criu-devel - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
python3x-pulpcore (Red Hat package) - update to 3.28.24-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.24-1.el9ap
podman-docker - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-tests - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-remote - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-plugins - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-gvproxy - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-catatonit - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
python3x-django (Red Hat package) - update to 4.2.11-1.el8ap
python-django (Red Hat package) - update to 4.2.11-1.el9ap
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-21.rhaos4.15.el9, 4.9.4-0.1.el9
automation-controller (Red Hat package) - addressed in versions 4.5.5-2.el8ap, 4.5.5-2.el9ap
DB2 on Cloud Pak for Data - update to 4.8.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
ose-aws-ecr-image-credential-provider (Red Hat package) - update to 4.15.0-202401231232.p0.gba252ab.assembly.stream.el9
openshift-clients (Red Hat package) - update to 4.15.0-202402070507.p0.g48dcf59.assembly.stream.el9
openshift (Red Hat package) - update to 4.15.0-202402142009.p0.g6216ea1.assembly.stream.el9
openshift-ansible (Red Hat package) - update to 4.15.0-202402162207.p0.g1c9b99e.assembly.stream.el9
microshift (Red Hat package) - update to 4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9
Watson CP4D Data Stores - update to 5.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.2.0
rust-afterburn (Red Hat package) - update to 5.4.3-2.rhaos4.15.el9
kernel (Red Hat package) - update to 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.54.1.rt14.339.el9_2
Splunk Add-on for Amazon Web Services - update to 7.7.0
Storage Protect Server - update to 8.1.23
IBM DataPower Gateway - addressed in versions 10.0.1.18, 10.5.0.10, 10.5.4
IBM Security Verify Access - update to 10.0.9
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
IBM CICS TX Advanced - update to 11.1.0.0 ifix18
IBM CICS TX Standard - update to 11.1.0.0 ifix18
Red Hat OpenStack - addressed in versions 16.2, 17.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19
docker - update to 25.0.3-1
cockpit-podman - addressed in versions 46-1, 84.1-1
IBM Observability with Instana - update to 281
ostree (Red Hat package) - update to 2023.8-3.el9
rpm-ostree (Red Hat package) - update to 2024.2-1.el9

External References

Related Security Bulletins