Input validation error in Go programming language - CVE-2024-24790

 

Input validation error in Go programming language - CVE-2024-24790

Published: June 5, 2024


Vulnerability identifier: #VU91160
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-24790
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Go programming language
Oracle Solaris
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Development Tools Module
Containers Module
openSUSE Leap
Ubuntu
openEuler
Nomad
moby
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Rapid Infrastructure Automation
Cloud Pak for Network Automation
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Business Automation Manager Open Editions
Storage Copy Data Management
Dell EMC OpenManage Enterprise Modular
Dell EMC OpenManage Enterprise Services
Watson CP4D Data Stores
Storage Protect Server
go
Traefik
Cryostat
IBM Observability with Instana
Run Once Duration Override Operator for Red Hat OpenShift
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
Kube Descheduler Operator for Red Hat OpenShift
OpenShift Logging
Red Hat Satellite
IBM Spectrum Protect Plus
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
Splunk Enterprise
Splunk Universal Forwarder
Red Hat Ceph Storage
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
yggdrasil-worker-forwarder (Red Hat package)
rubygem-hammer_cli_foreman_tasks (Red Hat package)
rhc-worker-script (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
runc (Red Hat package)
containernetworking-plugins (Red Hat package)
receptor (Red Hat package)
python-pulp-certguard (Red Hat package)
skopeo (Red Hat package)
golang
golang (Red Hat package)
golang-1.21 (Ubuntu package)
golang-1.21-go (Ubuntu package)
golang-1.21-src (Ubuntu package)
delve
golang-devel
golang-help
go-toolset
golang-misc
golang-tests
golang-bin
golang-docs
golang-src
go1.21-doc
go1.21
go1.21-race
go1.21-openssl-race
go1.21-openssl-doc
go1.21-openssl
golang-1.22-src (Ubuntu package)
golang-1.22-go (Ubuntu package)
golang-1.22 (Ubuntu package)
go1.22-doc
go1.22
go1.22-race
go1.22-openssl-debuginfo
go1.22-openssl-doc
go1.22-openssl
go1.22-openssl-race
buildah (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
python3x-urllib3 (Red Hat package)
python-urllib3 (Red Hat package)
NetworkManager (Red Hat package)
python-werkzeug (Red Hat package)
conmon (Red Hat package)
container-suseconnect
oath-toolkit (Red Hat package)
ignition (Red Hat package)
amazon-ssm-agent
foreman (Red Hat package)
foreman-installer (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
cephadm-ansible (Red Hat package)
podman (Red Hat package)
python-django (Red Hat package)
python3x-django (Red Hat package)
automation-controller (Red Hat package)
rubygem-katello (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
satellite (Red Hat package)
rubygem-foreman_rh_cloud (Red Hat package)
grafana
grafana (Red Hat package)
rubygem-foreman_theme_satellite (Red Hat package)
ceph (Red Hat package)
python-gunicorn (Red Hat package)
python-pyOpenSSL (Red Hat package)
python-cryptography (Red Hat package)
google-osconfig-agent
IBM CICS TX Standard
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Red Hat OpenShift GitOps
Cost Management
IBM Cloud Pak System
PowerPath Management Appliance

Detailed vulnerability description

The vulnerability allows a remote attacker to modify application behavior.

The vulnerability exists due to improper handling of IPv4-mapped IPv6 addresses in net/netip within multiple methods, e.g. IsPrivate, IsLoopback. The affected methods return false for addresses which would return true in their traditional IPv4 forms, leading to potential bypass of implemented security features.


How to mitigate CVE-2024-24790

Install updates from vendor's website.

Sources