Resource exhaustion in Go programming language - CVE-2024-24791

 

Resource exhaustion in Go programming language - CVE-2024-24791

Published: July 7, 2024


Vulnerability identifier: #VU93850
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-24791
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Go programming language
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
Containers Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Concert Software
Cryostat
IBM Maximo Application Suite
IBM Observability with Instana
Run Once Duration Override Operator for Red Hat OpenShift
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Kube Descheduler Operator for Red Hat OpenShift
OpenShift Logging
IBM Cloud Pak for Business Automation
Terraform
go
watsonx.data
IBM Business Automation Manager Open Editions
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
toolbox
toolbox-tests
toolbox (Red Hat package)
udica
podman-debuginfo
podman-debugsource
podman-help
podman-docker
python3-podman
python3-pypodman
podman
rhc-worker-script (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
containernetworking-plugins (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
golang-devel
golang
golang-help
skopeo (Red Hat package)
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
golang (Red Hat package)
delve
go1.21-doc
go1.21
go1.21-race
go-toolset
go1.21-openssl-race
go1.21-openssl-doc
go1.21-openssl
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
golang-1.22 (Ubuntu package)
golang-1.22-go (Ubuntu package)
golang-1.22-src (Ubuntu package)
go1.22-doc
go1.22
go1.22-race
go1.22-openssl
go1.22-openssl-debuginfo
go1.22-openssl-race
go1.22-openssl-doc
buildah
buildah-debuginfo
buildah-debugsource
buildah-tests
buildah (Red Hat package)
containers-common
conmon
container-suseconnect
oath-toolkit (Red Hat package)
container-selinux
podman-plugins
podman-remote
podman-gvproxy
etcd
crit
criu
criu-devel
python3-criu
criu-libs
cephadm-ansible (Red Hat package)
libslirp-devel
libslirp
podman-tests
podmansh
podman-catatonit
podman (Red Hat package)
grafana (Red Hat package)
grafana-selinux
grafana
ceph (Red Hat package)
cockpit-podman
moby
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
Cost Management
AMQ Streams
Planning Analytics Local
Red Hat Ceph Storage

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of "Expect: 100-continue" HTTP requests. A remote attacker can send multiple such requests and consume all available resources.


How to mitigate CVE-2024-24791

Install updates from vendor's website.

Sources