Use of uninitialized variable in Helm - CVE-2024-26147

 

Use of uninitialized variable in Helm - CVE-2024-26147

Published: April 3, 2024 / Updated: December 6, 2024


Vulnerability identifier: #VU88098
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26147
CWE-ID: CWE-457
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to usage of an uninitialized variable when using the LoadIndexFile or DownloadIndexFile functions in the repo package or the LoadDir function in the plugin package. If index.yaml file or a plugins plugin.yaml file are missing in the repository, the application crashes.


Affected software

Helm
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
openSUSE Leap Micro
SUSE Linux Enterprise Micro
Containers Module
SUSE Package Hub 15
openSUSE Leap
SmartFabric Manager
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Concert Software
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift GitOps
helm-debuginfo
helm
helm-zsh-completion
helm-bash-completion
helm-fish-completion
Red Hat OpenShift Container Platform

How to mitigate CVE-2024-26147

Install updates from vendor's website.

Helm - update to 3.14.2
SmartFabric Manager - update to 1.2.0
IBM Cloud Transformation Advisor - update to 3.10.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.9.3
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.6, 4.4.0
IBM Concert Software - update to 1.0.1
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.4
helm-debuginfo - update to 3.16.3-150000.1.38.1
helm - update to 3.16.3-150000.1.38.1
helm-zsh-completion - update to 3.16.3-150000.1.38.1
helm-bash-completion - update to 3.16.3-150000.1.38.1
helm-fish-completion - update to 3.16.3-150000.1.38.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.14.51, 4.15.14, 4.15.30, 4.16.1

External References

Related Security Bulletins