Memory leak in Ansible - CVE-2024-0690

 

Memory leak in Ansible - CVE-2024-0690

Published: January 19, 2024


Vulnerability identifier: #VU85621
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0690
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due memory leak caused by a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. A local user can gain access to potentially sensitive information.


Affected software

Ansible
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Manager Retail Branch Server
SUSE Manager Client Tools Beta for SLE Micro
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Manager Client Tools for SLE
SUSE Manager Client Tools Beta for SLE
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Package Hub 15
openSUSE Leap
openEuler
Fedora
Ansible Automation Platform
IBM Fusion HCI
IBM Maximo Application Suite
mgrctl-bash-completion
mgrctl
mgrctl-zsh-completion
POS_Image-Graphical7
POS_Image-JeOS7
dracut-saltboot
golang-github-prometheus-promu
golang-github-prometheus-node_exporter
ansible-automation-platform-installer (Red Hat package)
ansible
ansible-help
ansible-test
ansible-doc
ansible-core
ansible-core (Red Hat package)
ansible-core-doc
spacewalk-koan
python3-spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
python3-spacewalk-client-setup
spacewalk-client-tools
spacewalk-check
spacewalk-client-setup
python3-spacewalk-check
python3-spacewalk-client-tools
spacecmd
automation-controller (Red Hat package)
supportutils-plugin-susemanager-client
grafana
grafana-debuginfo
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data

How to mitigate CVE-2024-0690

Install updates from vendor's website.

mgrctl-bash-completion - update to 0.1.7-159000.3.8.1
mgrctl - update to 0.1.7-159000.3.8.1
mgrctl-zsh-completion - update to 0.1.7-159000.3.8.1
POS_Image-Graphical7 - addressed in versions 0.1.1710765237.46af599-150000.1.21.2, 0.1.1710765237.46af599-159000.3.24.2
POS_Image-JeOS7 - addressed in versions 0.1.1710765237.46af599-150000.1.21.2, 0.1.1710765237.46af599-159000.3.24.2
dracut-saltboot - addressed in versions 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
golang-github-prometheus-node_exporter - update to 1.5.0-159000.6.2.1
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.4-5.el8ap, 2.4-5.el9ap
ansible - update to 2.5.5-7
ansible-help - update to 2.5.5-7
IBM Fusion HCI - update to 2.9.0
ansible - addressed in versions 2.9.27-150000.1.17.2, 2.9.27-159000.3.12.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible-doc - addressed in versions 2.9.27-150000.1.17.2, 2.9.27-159000.3.12.2
ansible-core - addressed in versions 2.14.11-2.fc38, 2.16.2-2.fc39
ansible-core (Red Hat package) - addressed in versions 2.14.14-1.el9, 2.15.9-1.el8ap, 2.15.9-1.el9ap, 2.16.3-2.el8
ansible-core - update to 2.15.3-1
ansible-core-doc - update to 2.16.3-2.0.1
ansible-test - update to 2.16.3-2.0.1
ansible-core - update to 2.16.3-2.0.1
spacewalk-koan - update to 4.3.6-150000.3.33.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
python3-spacewalk-client-setup - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-client-tools - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-check - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-client-setup - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-check - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-client-tools - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacecmd - addressed in versions 4.3.27-150000.3.116.2, 5.0.5-159000.6.48.2
automation-controller (Red Hat package) - addressed in versions 4.5.1-1.el8ap, 4.5.1-1.el9ap
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
supportutils-plugin-susemanager-client - update to 5.0.3-159000.6.21.2
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
grafana - addressed in versions 9.5.16-159000.4.30.2, 9.5.18-150000.1.63.2
grafana-debuginfo - addressed in versions 9.5.16-159000.4.30.2, 9.5.18-150000.1.63.2

External References

Related Security Bulletins