Infinite loop in protobuf-go - CVE-2024-24786
Published: March 11, 2024 / Updated: March 28, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when parsing data in an invalid JSON format within the protojson.Unmarshal() function. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
Amazon Linux AMI
Oracle Linux
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
BIG-IP Next CNF
F5OS
BIG-IP Next SPK
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Containers Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Gin
Agent
Storage Defender - Resiliency Service
Guardium Data Security Center (GDSC)
Maximo Application Suite - Visual Inspection Component
Watson CP4D Data Stores
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Ceph
Robotic Process Automation for Cloud Pak
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
Nomad
OpenShift Service Mesh
Multicluster Engine for Kubernetes
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
Migration Toolkit for Containers
buildah
Red Hat OpenShift Container Platform
Consul
Consul Enterprise
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
IBM Observability with Instana
Operations Dashboard
Cluster Observability Operator
VolSync
IBM Concert Software
Red Hat OpenShift Builds
Run Once Duration Override Operator for Red Hat OpenShift
Ansible Automation Platform
IBM Fusion HCI
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
Kube Descheduler Operator for Red Hat OpenShift
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
OpenShift Developer Tools and Services
IBM CICS TX Advanced
IBM CICS TX Standard
Communications Unified Assurance
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Splunk Enterprise
QRadar Suite
BIG-IP Next Central Manager
toolbox-tests
toolbox
toolbox (Red Hat package)
udica
conmon-rs (Red Hat package)
rhc-worker-script (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
runc (Red Hat package)
slirp4netns (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
containernetworking-plugins
skopeo (Red Hat package)
aardvark-dns
fuse-overlayfs (Red Hat package)
netavark
fuse-overlayfs
crun (Red Hat package)
crun
skopeo
skopeo-tests
cri-tools-debuginfo
cri-tools
cri-tools-debugsource
cri-o-debuginfo
cri-o-debugsource
cri-o
buildah (Red Hat package)
kubernetes1.24-scheduler
kubernetes1.24-client
kubernetes1.24-kubeadm
kubernetes1.24-kubelet-common
kubernetes1.24-proxy
kubernetes1.24-kubelet
kubernetes1.24-controller-manager
kubernetes1.24-apiserver
kubernetes1.24-client-fish-completion
kubernetes1.24-client-bash-completion
kubernetes1.24-client-common
cri-tools (Red Hat package)
cri-o (Red Hat package)
kubernetes1.25-apiserver
kubernetes1.25-client-fish-completion
kubernetes1.25-client-bash-completion
kubernetes1.25-controller-manager
kubernetes1.25-scheduler
kubernetes1.25-kubeadm
kubernetes1.25-kubelet-common
kubernetes1.25-proxy
kubernetes1.25-kubelet
kubernetes1.25-client
kubernetes1.25-client-common
kubernetes
buildah-tests
buildah
app-containers/buildah
containers-common (Red Hat package)
containers-common
amazon-cloudwatch-agent
conmon (Red Hat package)
conmon
oath-toolkit (Red Hat package)
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux
container-selinux (Red Hat package)
jenkins (Red Hat package)
kata-containers (Red Hat package)
crit
python3-criu
criu
criu-devel
criu-libs
cephadm-ansible (Red Hat package)
podman (Red Hat package)
libslirp
libslirp-devel
libslirp (Red Hat package)
python3-podman
app-containers/podman
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
podman-docker
podman-remote-debuginfo
podman-debuginfo
podmansh
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
microshift (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
ceph (Red Hat package)
ovn24.03 (Red Hat package)
docker-bash-completion
docker-zsh-completion
docker-rootless-extras
docker-debuginfo
docker-fish-completion
docker
cockpit-podman
ostree (Red Hat package)
google-osconfig-agent (Ubuntu package)
google-guest-agent (Ubuntu package)
Red Hat OpenShift GitOps
Red Hat build of MicroShift
Red Hat Ceph Storage
How to mitigate CVE-2024-24786
Gin - update to 1.10.0
Agent - update to 0.40.4
OpenShift API for Data Protection (OADP) - update to 1.3.1
Nomad - addressed in versions 1.5.16, 1.6.9, 1.7.6
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Consul - addressed in versions 1.15.11, 1.16.7, 1.17.4
Consul Enterprise - update to 1.18.1
buildah - addressed in versions 1.27.4, 1.29.3, 1.32.3
Storage Defender - Resiliency Service - update to 2.0.5
IBM MQ Operator - addressed in versions 2.0.21, 3.1.2
IBM Cloud Pak System - update to 2.3.6.0
OpenShift Service Mesh - addressed in versions 2.5.1, 2.5.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.8.6
Multicluster Engine for Kubernetes - update to 2.8.4
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.12.54, 4.12.57, 4.13.38, 4.13.42, 4.13.46, 4.14.17, 4.14.18, 4.14.21, 4.14.24, 4.14.34, 4.14.38, 4.15.3, 4.15.6, 4.15.9, 4.15.13, 4.15.31, 4.16.0, 4.16.1, 4.16.10, 4.16.14, 4.16.19, 4.16.23, 4.16.24, 4.17.0, 4.17.1, 4.17.3, 4.17.14, 4.17.27, 4.18.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP9 IF02, 7.5.0 UP11 IF03
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.21, 9.0.19, 9.1.12
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
IBM Observability with Instana - update to 282
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - addressed in versions 0.1.0-2.rhaos4.14.el8, 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9
udica - update to 0.2.6-21
Cluster Observability Operator - update to 0.4.1
conmon-rs (Red Hat package) - addressed in versions 0.5.1-4.rhaos4.12.el8, 0.5.1-4.rhaos4.12.el9, 0.5.1-6.rhaos4.13.el8, 0.5.1-6.rhaos4.13.el9, 0.6.3-1.rhaos4.16.el8, 0.6.3-1.rhaos4.16.el9
rhc-worker-script (Red Hat package) - update to 0.7-1.el7_9
VolSync - update to 0.9.1
golang-github-prometheus-promu (Red Hat package) - addressed in versions 0.15.0-15.2.gitd5383c5.el9, 0.15.0-15.3.gitd5383c5.el8
butane (Red Hat package) - addressed in versions 0.16.0-2.2.rhaos4.12.el8, 0.20.0-1.1.rhaos4.15.el8, 0.21.0-1.rhaos4.16.el8
Red Hat OpenShift Serverless - addressed in versions 1, 1.33.0
IBM Concert Software - update to 1.0.1
Red Hat OpenShift Builds - update to 1.1.0
Run Once Duration Override Operator for Red Hat OpenShift - addressed in versions 1.1.1, 1.2.0
runc (Red Hat package) - addressed in versions 1.1.6-5.2.rhaos4.12.el8, 1.1.12-1.1.rhaos4.15.el8, 1.1.12-1.1.rhaos4.15.el9, 1.1.12-3.1.rhaos4.16.el8, 1.1.12-3.1.rhaos4.16.el9
slirp4netns (Red Hat package) - addressed in versions 1.1.8-2.rhaos4.14.el8, 1.1.8-2.rhaos4.16.el8
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.3.0
containernetworking-plugins (Red Hat package) - addressed in versions 1.4.0-1.1.rhaos4.12.el8, 1.4.0-1.2.rhaos4.15.el8, 1.4.0-2.1.rhaos4.16.el8
containernetworking-plugins - update to 1.4.0-2.0.1
Network Observability plugin for the Openshift Console - update to 1.6.0
skopeo (Red Hat package) - addressed in versions 1.9.4-3.2.rhaos4.12.el8, 1.9.4-3.2.rhaos4.12.el9, 1.11.2-21.2.rhaos4.15.el8, 1.11.2-21.2.rhaos4.15.el9, 1.14.3-2.el9_4, 1.14.4-1.rhaos4.16.el8, 1.14.4-1.rhaos4.16.el9
aardvark-dns - update to 1.10.0-2.0.1
fuse-overlayfs (Red Hat package) - addressed in versions 1.10-2.rhaos4.14.el8, 1.10-2.rhaos4.16.el8
netavark - update to 1.10.3-1.0.1
QRadar Suite - update to 1.10.22.0
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.4, 1.12.6
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - addressed in versions 1.14.3-1.rhaos4.16.el8, 1.14.3-1.rhaos4.16.el9
crun - update to 1.14.3-2
skopeo - update to 1.14.3-2.0.1
skopeo-tests - update to 1.14.3-2.0.1
cri-tools-debuginfo - update to 1.22.0-5
cri-tools - update to 1.22.0-5
cri-tools-debugsource - update to 1.22.0-5
cri-o-debuginfo - update to 1.23.2-11
cri-o-debugsource - update to 1.23.2-11
cri-o - update to 1.23.2-11
buildah (Red Hat package) - addressed in versions 1.23.4-5.2.rhaos4.12.el8, 1.23.4-5.2.rhaos4.12.el9, 1.29.1-20.3.rhaos4.15.el8, 1.29.1-20.3.rhaos4.15.el9, 1.33.7-1.el9_4, 1.33.7-1.1.rhaos4.16.el8, 1.33.7-1.1.rhaos4.16.el9
kubernetes1.24-scheduler - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-kubeadm - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-kubelet-common - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-proxy - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-kubelet - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-controller-manager - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-apiserver - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client-fish-completion - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client-bash-completion - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
kubernetes1.24-client-common - addressed in versions 1.24.17-150300.7.6.1, 1.24.17-150400.9.16.1, 1.24.17-150500.3.22.1
cri-tools (Red Hat package) - addressed in versions 1.25.0-2.2.el8, 1.25.0-2.2.el9, 1.28.0-3.1.el8, 1.28.0-3.1.el9, 1.29.0-3.1.el8, 1.29.0-3.1.el9
cri-o (Red Hat package) - addressed in versions 1.25.3-5.2.rhaos4.12.git44a2cb2.el9, 1.25.5-13.1.rhaos4.12.git76343da.el8, 1.26.5-10.rhaos4.13.gita08b329.el8, 1.26.5-10.rhaos4.13.gita08b329.el9, 1.27.4-5.rhaos4.14.git8d40fed.el8, 1.27.4-5.rhaos4.14.git8d40fed.el9, 1.28.4-8.rhaos4.15.git24f50b9.el8, 1.28.4-8.rhaos4.15.git24f50b9.el9, 1.29.5-5.rhaos4.16.git7032128.el8, 1.29.5-5.rhaos4.16.git7032128.el9
kubernetes1.25-apiserver - update to 1.25.16-150400.9.16.1
kubernetes1.25-client-fish-completion - update to 1.25.16-150400.9.16.1
kubernetes1.25-client-bash-completion - update to 1.25.16-150400.9.16.1
kubernetes1.25-controller-manager - update to 1.25.16-150400.9.16.1
kubernetes1.25-scheduler - update to 1.25.16-150400.9.16.1
kubernetes1.25-kubeadm - update to 1.25.16-150400.9.16.1
kubernetes1.25-kubelet-common - update to 1.25.16-150400.9.16.1
kubernetes1.25-proxy - update to 1.25.16-150400.9.16.1
kubernetes1.25-kubelet - update to 1.25.16-150400.9.16.1
kubernetes1.25-client - update to 1.25.16-150400.9.16.1
kubernetes1.25-client-common - update to 1.25.16-150400.9.16.1
kubernetes - update to 1.26.15-1.fc38
buildah-tests - update to 1.33.7-1
buildah - update to 1.33.7-1
app-containers/buildah - update to 1.35.3
buildah - addressed in versions 1.35.4-150300.8.25.1, 1.35.4-150400.3.30.1, 1.35.4-150500.3.10.1
containers-common (Red Hat package) - addressed in versions 1-77.rhaos4.16.el8, 1-77.rhaos4.16.el9
containers-common - update to 1-81.0.1
amazon-cloudwatch-agent - update to 1.300039.0-1
conmon (Red Hat package) - addressed in versions 2.1.2-5.2.rhaos4.12.el8, 2.1.2-6.2.rhaos4.12.el9, 2.1.7-10.1.rhaos4.15.el9, 2.1.10-2.1.rhaos4.16.el8, 2.1.10-2.1.rhaos4.16.el9
conmon - update to 2.1.10-1
Ansible Automation Platform - update to 2.4
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
haproxy (Red Hat package) - addressed in versions 2.6.13-3.rhaos4.16.el8, 2.8.5-2.rhaos4.16.el9
IBM Fusion HCI - update to 2.8.0
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-394
ignition (Red Hat package) - addressed in versions 2.14.0-5.2.rhaos4.12.el9, 2.14.0-7.1.rhaos4.12.el8, 2.16.2-2.1.rhaos4.15.el9, 2.18.0-2.1.rhaos4.16.el9
container-selinux - update to 2.229.0-2
container-selinux (Red Hat package) - addressed in versions 2.231.0-1.rhaos4.16.el8, 2.231.0-1.rhaos4.16.el9
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
kata-containers (Red Hat package) - update to 3.2.0-4.rhaos4.13.el9
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
podman (Red Hat package) - addressed in versions 4.2.0-7.2.rhaos4.12.el9, 4.4.1-2.1.rhaos4.12.el8, 4.4.1-21.1.rhaos4.15.el8, 4.4.1-21.1.rhaos4.15.el9, 4.9.4-3.el9_4, 4.9.4-5.1.rhaos4.16.el8, 4.9.4-5.1.rhaos4.16.el9
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
libslirp (Red Hat package) - addressed in versions 4.4.0-4.rhaos4.12.el8, 4.4.0-4.rhaos4.13.el8, 4.4.0-4.rhaos4.14.el8, 4.4.0-4.rhaos4.16.el8
python3-podman - update to 4.9.0-1
app-containers/podman - update to 4.9.4
podman - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
podman - addressed in versions 4.9.5-150300.9.31.1, 4.9.5-150400.4.27.1, 4.9.5-150500.3.12.1
podman-remote - addressed in versions 4.9.5-150300.9.31.1, 4.9.5-150400.4.27.1, 4.9.5-150500.3.12.1
podman-docker - addressed in versions 4.9.5-150300.9.31.1, 4.9.5-150400.4.27.1, 4.9.5-150500.3.12.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.31.1, 4.9.5-150400.4.27.1, 4.9.5-150500.3.12.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.31.1, 4.9.5-150400.4.27.1, 4.9.5-150500.3.12.1
podmansh - addressed in versions 4.9.5-150300.9.31.1, 4.9.5-150400.4.27.1, 4.9.5-150500.3.12.1
openshift-ansible (Red Hat package) - addressed in versions 4.12.0-202403201504.p0.gd97dd6f.assembly.stream.el8, 4.15.0-202403201503.p0.g1c9b99e.assembly.stream.el8, 4.15.0-202403201503.p0.g1c9b99e.assembly.stream.el9, 4.16.0-202404181812.p0.g7806532.assembly.stream.el8, 4.16.0-202404181812.p0.g7806532.assembly.stream.el9
openshift-kuryr (Red Hat package) - update to 4.12.0-202403201504.p0.g8fd2f8b.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - addressed in versions 4.12.0-202403201504.p0.gd2acdd5.assembly.stream.el8, 4.15.0-202403201503.p0.gd2acdd5.assembly.stream.el8, 4.16.0-202404181812.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el8, 4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el9, 4.15.0-202403211240.p0.g62c4d45.assembly.stream.el8, 4.15.0-202403211240.p0.g62c4d45.assembly.stream.el9, 4.16.0-202406052127.p0.ga245041.assembly.stream.el8, 4.16.0-202406052127.p0.ga245041.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.12.0-202403251017.p0.g9946c63.assembly.stream.el8, 4.12.0-202403251017.p0.g9946c63.assembly.stream.el9, 4.12.0-202406040636.p0.g306a47e.assembly.stream.el8, 4.12.0-202406040636.p0.g306a47e.assembly.stream.el9, 4.13.0-202403081338.p0.g03ee898.assembly.stream.el8, 4.13.0-202403081338.p0.g03ee898.assembly.stream.el9, 4.14.0-202403180010.p0.g749fe1d.assembly.stream.el8, 4.14.0-202403180010.p0.g749fe1d.assembly.stream.el9, 4.15.0-202403211549.p0.gf1b5f6c.assembly.stream.el8, 4.15.0-202403211549.p0.gf1b5f6c.assembly.stream.el9, 4.16.0-202406170957.p0.g29c95f3.assembly.stream.el8, 4.16.0-202406170957.p0.g29c95f3.assembly.stream.el9
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el8, 4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el9, 4.16.0-202405311136.p0.ga53e9de.assembly.stream.el8, 4.16.0-202405311136.p0.ga53e9de.assembly.stream.el9
Red Hat build of MicroShift - update to 4.16.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.16.0, 4.17.0
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.16.0-202404181812.p0.g26b43df.assembly.stream.el8, 4.16.0-202404181812.p0.g26b43df.assembly.stream.el9
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.16.0-202404301345.p0.g0e95532.assembly.stream.el8, 4.16.0-202404301345.p0.g0e95532.assembly.stream.el9
microshift (Red Hat package) - update to 4.16.0-202406260523.p0.gc5a37df.assembly.4.16.0.el9
kernel (Red Hat package) - addressed in versions 4.18.0-372.98.1.el8_6, 4.18.0-372.107.1.el8_6
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.98.1.rt7.258.el8_6, 4.18.0-372.107.1.rt7.267.el8_6
Kube Descheduler Operator for Red Hat OpenShift - addressed in versions 5.0.1, 5.0.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.3
App Connect Enterprise Certified Container - addressed in versions 5.0.22, 12.0.6, 12.6.0
Watson CP4D Data Stores - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Red Hat Migration Toolkit for Applications - update to 7.0.3
Storage Ceph - update to 7.1
Red Hat Ceph Storage - update to 8.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.17-r1, 9.3.5.1-r1
IBM CICS TX Advanced - update to 11.1.0.0 ifix21
IBM CICS TX Standard - update to 11.1.0.0 ifix22
ceph (Red Hat package) - update to 19.2.1-222.el9cp
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
ovn24.03 (Red Hat package) - update to 24.03.2-19.el9fdp
docker-bash-completion - update to 25.0.6_ce-150000.207.1
docker-zsh-completion - update to 25.0.6_ce-150000.207.1
docker-rootless-extras - update to 25.0.6_ce-150000.207.1
docker-debuginfo - update to 25.0.6_ce-150000.207.1
docker-fish-completion - update to 25.0.6_ce-150000.207.1
docker - update to 25.0.6_ce-150000.207.1
cockpit-podman - update to 84.1-1
ostree (Red Hat package) - update to 2024.1-2.el9
google-osconfig-agent (Ubuntu package) - addressed in versions 20230504.00-0ubuntu1~22.04.1, 20230504.00-0ubuntu2.2, 20240320.00-0ubuntu1~24.04.1
google-guest-agent (Ubuntu package) - addressed in versions 20231004.02-0ubuntu1~22.04.4, 20231004.02-0ubuntu1~23.10.3, 20240213.00-0ubuntu3.1
External References
Related Security Bulletins
- Denial of service in protobuf-go
- Multiple vulnerabilities in Nomad
- Fedora 38 update for kubernetes
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Consul
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 for RHEL 9 and 8
- Denial of service in Red Hat OpenShift Container Platform 4.14 for RHEL 9 and 8
- Multiple vulnerabilities in buildah
- Multiple vulnerabilities in HashiCorp Consul
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Denial of service in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Logging Subsystem 5.6 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- openEuler 22.03 LTS SP1 update for cri-tools
- openEuler 22.03 LTS SP2 update for cri-tools
- openEuler 22.03 LTS SP3 update for cri-tools
- Multiple vulnerabilities in Agent
- VolSync update for protobuf-go
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Red Hat Enterprise Linux 7 update for rhc-worker-script
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Ubuntu update for google-guest-agent
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- gin update for protobuf-go
- Infinite loop in IBM Storage Fusion
- Red Hat Product OCP Tools 4.14. Red Hat Product Security has rated this update as having a security impact of Important update for Openshift Jenkins
- Red Hat Product OCP Tools 4.12. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Product OCP Tools 4.13. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- SUSE update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Infinite loop in Red Hat OpenShift Container Platform 4.14
- Infinite loop in Red Hat OpenShift Container Platform 4.12 packages
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.6
- SUSE update for podman
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.12
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- SUSE update for podman
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.33
- Ubuntu update for google-guest-agent
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat build of MicroShift 4.16 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift 1.1
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift (OSSO) 1.3
- Multiple vulnerabilities in Kube Descheduler Operator for Red Hat OpenShift 5.0
- Gentoo update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Gentoo update for Buildah
- SUSE update for podman
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Infinite loop in IBM Storage Ceph
- Amazon Linux AMI update for amazon-cloudwatch-agent
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Concert
- SUSE update for buildah, docker
- SUSE update for buildah
- SUSE update for buildah
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- SUSE update for kubernetes1.23
- SUSE update for kubernetes1.24
- SUSE update for kubernetes1.24
- SUSE update for kubernetes1.25
- Multiple vulnerabilities in Red Hat OpenShift Builds 1.1
- Infinite loop in F5 BIG-IP Next Central Manager endpoints in API Gateway and Telemetry
- Infinite loop in F5 BIG-IP Next SPK/CNF containers
- Infinite loop in F5 F5OS apogee-service
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Instana Observability
- IBM Watson Assistant for IBM Cloud Pak for Data update for Protocol Buffers protobuf-go
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Cluster Observability Operator
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift 1.2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Kube Descheduler Operator for Red Hat OpenShift 5.0
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- IBM Watson CP4D Data Stores update for Protocol Buffers protobuf-go
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Protocol Buffers protobuf-go
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Juniper Secure Analytics update for third-party components
- Multiple vulnerabilities in IBM Guardium Data Security Center
- openEuler 22.03 LTS SP3 update for cri-o
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- IBM Cloud Pak System update for protobuf
- Multiple vulnerabilities in Red Hat Multicluster Engine for Kubernetes 2.8
- IBM Maximo Application Suite - Visual Inspection Component update for protojson
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in Red Hat OpenShift distributed tracing (RHOSDT) 3.2