Resource exhaustion in Go programming language - CVE-2023-39326
Published: December 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP chunked requests. A remote attacker can send specially crafted HTTP requests to the server and consume excessive memory resources.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Development Tools Module
openSUSE Leap
openEuler
Ubuntu
IBM Cloud Pak for Data Scheduling
Service Interconnect
Service Telemetry Framework
Consul Enterprise
Cryostat
Red Hat OpenShift distributed tracing (RHOSDT)
OpenShift Logging
Red Hat Migration Toolkit for Applications
Operations Dashboard
IBM Concert Software
Run Once Duration Override Operator for Red Hat OpenShift
DataPower Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Splunk Add-on for Amazon Web Services
Red Hat OpenStack
IBM Observability with Instana
AdGuard Home
IBM Qradar SIEM
Event Streams
Red Hat OpenShift Serverless
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
OpenShift Serverless Client
Red Hat OpenShift Container Platform
IBM DataPower Gateway
Juniper Secure Analytics (JSA)
Splunk Enterprise
toolbox (Red Hat package)
toolbox-tests
toolbox
collectd-sensubility (Red Hat package)
udica
rust-bootupd (Red Hat package)
rhc-worker-script (Red Hat package)
amazon-ecr-credential-helper
coreos-installer (Red Hat package)
containernetworking-plugins
runc
runc (Red Hat package)
cni-plugins
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
receptor (Red Hat package)
nerdctl
containerd
crun
aardvark-dns
openshift-serverless-clients (Red Hat package)
netavark
skopeo (Red Hat package)
fuse-overlayfs
crun (Red Hat package)
skopeo-tests
skopeo
golang
golang-devel
golang-help
go-toolset-1.19-golang (Red Hat package)
delve
golang-1.20-src (Ubuntu package)
golang-1.20-go (Ubuntu package)
golang-1.20 (Ubuntu package)
go-toolset
golang (Red Hat package)
go1.20-openssl-doc
go1.20-openssl-race
go1.20-openssl-debuginfo
go1.20-openssl
golang-src
golang-bin
golang-tests
golang-misc
golang-docs
go1.20-race
go1.20-doc
go1.20-debuginfo
go1.20
golang-1.21 (Ubuntu package)
golang-1.21-src (Ubuntu package)
golang-1.21-go (Ubuntu package)
go1.21-openssl-race
go1.21-openssl
go1.21-openssl-doc
go1.21-race
go1.21-doc
go1.21
dev-lang/go
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah-tests
buildah
ecs-init
containers-common
amazon-cloudwatch-agent
conmon (Red Hat package)
conmon
ansible-runner (Red Hat package)
ansible-core (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
amazon-ssm-agent
etcd
etcd (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
criu-devel
python3-criu
criu-libs
crit
criu
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
python3x-django (Red Hat package)
python-django (Red Hat package)
libslirp
libslirp-devel
podman (Red Hat package)
automation-controller (Red Hat package)
python3-podman
ose-aws-ecr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
microshift (Red Hat package)
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
docker
cockpit-podman
ostree (Red Hat package)
rpm-ostree (Red Hat package)
Db2 Rest
DB2 on Cloud Pak for Data
Watson CP4D Data Stores
Storage Protect Server
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
IBM Cloud Pak System
IBM Security Verify Access
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2023-39326
AdGuard Home - addressed in versions 0.107.42, 0.108.0-b.51
Red Hat OpenShift Serverless - update to 1.31.1
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
Consul Enterprise - addressed in versions 1.15.8, 1.16.4, 1.17.1
OpenShift Serverless Client - update to 1.31.1
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.56, 4.14.14, 4.15.0
OpenShift Logging - addressed in versions 5.6.16, 5.7.11, 5.8.3
Red Hat Migration Toolkit for Applications - addressed in versions 7.0.2, 7.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Event Streams - update to 11.3.2
toolbox (Red Hat package) - addressed in versions 0.0.99.5-2.el9, 0.1.2-1.rhaos4.15.el9
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
collectd-sensubility (Red Hat package) - addressed in versions 0.2.1-3.el8ost, 0.2.1-3.el9ost
udica - update to 0.2.6-21
rust-bootupd (Red Hat package) - update to 0.2.17-1.el9
rhc-worker-script (Red Hat package) - update to 0.6-1.el7_9
amazon-ecr-credential-helper - update to 0.7.1-4
coreos-installer (Red Hat package) - update to 0.17.0-3.rhaos4.15.el9
Db2 Rest - update to 1.0.0.301
IBM Concert Software - update to 1.0.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.1.0
containernetworking-plugins - addressed in versions 1.1.1-6.0.1, 1.4.0-2.0.1
runc - update to 1.1.11-1.1
runc (Red Hat package) - update to 1.1.12-1.rhaos4.15.el9
runc - update to 1.1.12-1.0.1
cni-plugins - update to 1.2.0-1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - addressed in versions 1.2.5-2.0.1, 1.2.10-1
containernetworking-plugins (Red Hat package) - update to 1.4.0-2.el9_4
receptor (Red Hat package) - addressed in versions 1.4.5-1.el8ap, 1.4.5-1.el9ap
Network Observability plugin for the Openshift Console - update to 1.6.0
DataPower Operator - addressed in versions 1.6.13, 1.9.1
nerdctl - update to 1.7.2-1
containerd - update to 1.7.11-1
crun - addressed in versions 1.8.7-1.0.1, 1.14.3-2
aardvark-dns - update to 1.10.0-2.0.1
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
netavark - update to 1.10.3-1.0.1
skopeo (Red Hat package) - addressed in versions 1.11.2-21.1.rhaos4.15.el9, 1.13.3-4.el9_3
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14-1.rhaos4.15.el9
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - addressed in versions 1.15.7-37, 1.21.4-31
golang-devel - addressed in versions 1.15.7-37, 1.21.4-31
golang-help - addressed in versions 1.15.7-37, 1.21.4-31
go-toolset-1.19-golang (Red Hat package) - update to 1.19.13-5.el7_9
delve - update to 1.20.2-1.0.1
golang-1.20-src (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20-go (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20 (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
go-toolset - update to 1.20.12-1
golang - addressed in versions 1.20.12-1.el7, 1.21.6-1.fc39
golang (Red Hat package) - update to 1.20.12-1.el9_3
golang - update to 1.20.12-1.49
go1.20-openssl-doc - update to 1.20.12.1-150000.1.17.1
go1.20-openssl-race - update to 1.20.12.1-150000.1.17.1
go1.20-openssl-debuginfo - update to 1.20.12.1-150000.1.17.1
go1.20-openssl - update to 1.20.12.1-150000.1.17.1
golang-src - update to 1.20.12-2.0.1
golang-bin - update to 1.20.12-2.0.1
golang-tests - update to 1.20.12-2.0.1
golang-misc - update to 1.20.12-2.0.1
golang - update to 1.20.12-2.0.1
golang-docs - update to 1.20.12-2.0.1
go1.20-race - update to 1.20.12-150000.1.35.1
go1.20-doc - update to 1.20.12-150000.1.35.1
go1.20-debuginfo - update to 1.20.12-150000.1.35.1
go1.20 - update to 1.20.12-150000.1.35.1
golang-1.21 (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-src (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-go (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
go1.21-openssl-race - update to 1.21.5.1-150000.1.8.1
go1.21-openssl - update to 1.21.5.1-150000.1.8.1
go1.21-openssl-doc - update to 1.21.5.1-150000.1.8.1
go1.21-race - update to 1.21.5-150000.1.18.1
go1.21-doc - update to 1.21.5-150000.1.18.1
go1.21 - update to 1.21.5-150000.1.18.1
dev-lang/go - update to 1.22.3
cri-tools (Red Hat package) - update to 1.28.0-3.el9
cri-o (Red Hat package) - update to 1.28.3-14.rhaos4.15.git33aabd8.el9
buildah (Red Hat package) - addressed in versions 1.29.1-20.2.rhaos4.15.el9, 1.33.6-2.el9
buildah-tests - update to 1.33.7-1
buildah - update to 1.33.7-1
ecs-init - update to 1.80.0-1
containers-common - update to 1-81.0.1
amazon-cloudwatch-agent - update to 1.300032.3-1
conmon (Red Hat package) - update to 2.1.7-1.2.rhaos4.14.el9
conmon - update to 2.1.10-1
IBM Cloud Pak System - update to 2.3.4.0
ansible-runner (Red Hat package) - addressed in versions 2.3.6-1.el8ap, 2.3.6-1.el9ap
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
ansible-core (Red Hat package) - addressed in versions 2.15.10-1.el8ap, 2.15.10-1.el9ap
ignition (Red Hat package) - update to 2.16.2-2.rhaos4.15.el9
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.15.el9
container-selinux - update to 2.229.0-2
amazon-ssm-agent - update to 3.2.2222.0-1
etcd - addressed in versions 3.4.14-11, 3.4.14-16
etcd (Red Hat package) - update to 3.4.26-8.el9ost
python3x-aiohttp (Red Hat package) - update to 3.9.3-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.3-1.el9ap
criu-devel - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
python3x-pulpcore (Red Hat package) - update to 3.28.24-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.24-1.el9ap
podman-docker - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-tests - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-remote - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-plugins - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-gvproxy - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-catatonit - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
python3x-django (Red Hat package) - update to 4.2.11-1.el8ap
python-django (Red Hat package) - update to 4.2.11-1.el9ap
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-21.rhaos4.15.el9, 4.9.4-0.1.el9
automation-controller (Red Hat package) - addressed in versions 4.5.5-2.el8ap, 4.5.5-2.el9ap
DB2 on Cloud Pak for Data - update to 4.8.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
ose-aws-ecr-image-credential-provider (Red Hat package) - update to 4.15.0-202401231232.p0.gba252ab.assembly.stream.el9
openshift-clients (Red Hat package) - update to 4.15.0-202402070507.p0.g48dcf59.assembly.stream.el9
openshift (Red Hat package) - update to 4.15.0-202402142009.p0.g6216ea1.assembly.stream.el9
openshift-ansible (Red Hat package) - update to 4.15.0-202402162207.p0.g1c9b99e.assembly.stream.el9
microshift (Red Hat package) - update to 4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9
Watson CP4D Data Stores - update to 5.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.2.0
rust-afterburn (Red Hat package) - update to 5.4.3-2.rhaos4.15.el9
kernel (Red Hat package) - update to 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.54.1.rt14.339.el9_2
Splunk Add-on for Amazon Web Services - update to 7.7.0
Storage Protect Server - update to 8.1.23
IBM DataPower Gateway - addressed in versions 10.0.1.18, 10.5.0.10, 10.5.4
IBM Security Verify Access - update to 10.0.9
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
IBM CICS TX Advanced - update to 11.1.0.0 ifix18
IBM CICS TX Standard - update to 11.1.0.0 ifix18
Red Hat OpenStack - addressed in versions 16.2, 17.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19
docker - update to 25.0.3-1
cockpit-podman - addressed in versions 46-1, 84.1-1
IBM Observability with Instana - update to 281
ostree (Red Hat package) - update to 2023.8-3.el9
rpm-ostree (Red Hat package) - update to 2024.2-1.el9
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- Multiple vulnerabilities in AdGuardHome
- SUSE update for go1.21
- SUSE update for go1.20
- Multiple vulnerabilities in HashiCorp Consul
- SUSE update for go1.21-openssl
- SUSE update for go1.20-openssl
- Amazon Linux AMI update for golang
- Ubuntu update for golang-1.20
- Fedora 39 update for golang
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Denial of service in Logging Subsystem 5.7 for Red Hat OpenShift
- Denial of service in Logging Subsystem 5.6 for Red Hat OpenShift
- Denial of service in Logging Subsystem 5.8 for Red Hat OpenShift
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless Client
- Red Hat Developer Tools update for go-toolset-1.19-golang
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat build of MicroShift
- Red Hat Enterprise Linux 9 update for golang
- Resource exhaustion in IBM App Connect Enterprise Certified Container
- openEuler update for golang
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 7 update for rhc-worker-script
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
- Multiple vulnerabilities in Migration Toolkit for Applications 7.0
- Denial of service in Red Hat Openshift distributed tracing
- Multiple vulnerabilities in IBM CICS TX Advanced
- Resource exhaustion in IBM DataPower Operator and IBM DataPower Gateway
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4 for RHEL 9
- Resource exhaustion in IBM Cloud Pak for Data Scheduling
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Service Interconnect 1.5
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 9 update for toolbox
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Multiple vulnerabilities in IBM Watson Discovery
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.6
- Multiple vulnerabilities in Red Hat OpenStack 17 packages
- Multiple vulnerabilities in Red Hat OpenStack 17 packages
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Resource exhaustion in IBM Watson CP4D Data Stores
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Amazon Linux AMI update for oci-add-hooks
- Amazon Linux AMI update for amazon-ecr-credential-helper
- Amazon Linux AMI update for ecs-init
- Amazon Linux AMI update for cni-plugins
- Amazon Linux AMI update for docker
- Amazon Linux AMI update for nerdctl
- Amazon Linux AMI update for amazon-ssm-agent
- Amazon Linux AMI update for runc
- Amazon Linux AMI update for containerd
- Amazon Linux AMI update for amazon-cloudwatch-agent
- Amazon Linux AMI update for golang
- Gentoo update for Go
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Storage Protect Plus Server
- Multiple vulnerabilities in IBM Concert
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Splunk Add-on for Amazon Web Services update for third-party components
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Security Verify Access
- openEuler 24.03 LTS update for golang
- openEuler 20.03 LTS SP4 update for etcd
- openEuler 24.03 LTS SP1 update for etcd
- Anolis OS update for container-tools:4.0 module
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for container-tools:an8 module
- Fedora EPEL 7 update for golang
- openEuler 24.03 LTS update for etcd
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0