Resource exhaustion in Go programming language - CVE-2024-24791
Published: July 7, 2024
Vulnerability identifier: #VU93850
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24791
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of "Expect: 100-continue" HTTP requests. A remote attacker can send multiple such requests and consume all available resources.
Affected software
Go programming language
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
Containers Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Concert Software
Cryostat
IBM Maximo Application Suite
IBM Observability with Instana
Run Once Duration Override Operator for Red Hat OpenShift
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Kube Descheduler Operator for Red Hat OpenShift
OpenShift Logging
IBM Cloud Pak for Business Automation
Terraform
go
watsonx.data
IBM Business Automation Manager Open Editions
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
toolbox
toolbox-tests
toolbox (Red Hat package)
udica
podman-debuginfo
podman-debugsource
podman-help
podman-docker
python3-podman
python3-pypodman
podman
rhc-worker-script (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
containernetworking-plugins (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
golang-devel
golang
golang-help
skopeo (Red Hat package)
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
golang (Red Hat package)
delve
go1.21-doc
go1.21
go1.21-race
go-toolset
go1.21-openssl-race
go1.21-openssl-doc
go1.21-openssl
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
golang-1.22 (Ubuntu package)
golang-1.22-go (Ubuntu package)
golang-1.22-src (Ubuntu package)
go1.22-doc
go1.22
go1.22-race
go1.22-openssl
go1.22-openssl-debuginfo
go1.22-openssl-race
go1.22-openssl-doc
buildah
buildah-debuginfo
buildah-debugsource
buildah-tests
buildah (Red Hat package)
containers-common
conmon
container-suseconnect
oath-toolkit (Red Hat package)
container-selinux
podman-plugins
podman-remote
podman-gvproxy
etcd
crit
criu
criu-devel
python3-criu
criu-libs
cephadm-ansible (Red Hat package)
libslirp-devel
libslirp
podman-tests
podmansh
podman-catatonit
podman (Red Hat package)
grafana (Red Hat package)
grafana-selinux
grafana
ceph (Red Hat package)
cockpit-podman
moby
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
Cost Management
AMQ Streams
Planning Analytics Local
Red Hat Ceph Storage
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
Containers Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Concert Software
Cryostat
IBM Maximo Application Suite
IBM Observability with Instana
Run Once Duration Override Operator for Red Hat OpenShift
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Kube Descheduler Operator for Red Hat OpenShift
OpenShift Logging
IBM Cloud Pak for Business Automation
Terraform
go
watsonx.data
IBM Business Automation Manager Open Editions
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
toolbox
toolbox-tests
toolbox (Red Hat package)
udica
podman-debuginfo
podman-debugsource
podman-help
podman-docker
python3-podman
python3-pypodman
podman
rhc-worker-script (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
containernetworking-plugins (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
golang-devel
golang
golang-help
skopeo (Red Hat package)
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
golang (Red Hat package)
delve
go1.21-doc
go1.21
go1.21-race
go-toolset
go1.21-openssl-race
go1.21-openssl-doc
go1.21-openssl
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
golang-1.22 (Ubuntu package)
golang-1.22-go (Ubuntu package)
golang-1.22-src (Ubuntu package)
go1.22-doc
go1.22
go1.22-race
go1.22-openssl
go1.22-openssl-debuginfo
go1.22-openssl-race
go1.22-openssl-doc
buildah
buildah-debuginfo
buildah-debugsource
buildah-tests
buildah (Red Hat package)
containers-common
conmon
container-suseconnect
oath-toolkit (Red Hat package)
container-selinux
podman-plugins
podman-remote
podman-gvproxy
etcd
crit
criu
criu-devel
python3-criu
criu-libs
cephadm-ansible (Red Hat package)
libslirp-devel
libslirp
podman-tests
podmansh
podman-catatonit
podman (Red Hat package)
grafana (Red Hat package)
grafana-selinux
grafana
ceph (Red Hat package)
cockpit-podman
moby
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
Cost Management
AMQ Streams
Planning Analytics Local
Red Hat Ceph Storage
How to mitigate CVE-2024-24791
Install updates from vendor's website.
Go programming language - addressed in versions 1.21.12, 1.22.5
IBM Concert Software - update to 1.0.5
Terraform - update to 1.9.3
go - update to 1.19.13-7
watsonx.data - update to 2.2
IBM Business Automation Manager Open Editions - update to 8.0.8
IBM Maximo Application Suite - addressed in versions 8.10.25, 8.11.22, 9.0.11
Splunk Enterprise - addressed in versions 9.1.9, 9.2.6, 9.3.4, 9.4.2
moby - update to 25.0.6
IBM Observability with Instana - addressed in versions 279, 282
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.0.99.5-5.el9
udica - update to 0.2.6-21
podman-debuginfo - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-debugsource - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-help - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-docker - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
python3-podman - update to 0.10.1-10
python3-pypodman - update to 0.10.1-10
podman - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
rhc-worker-script (Red Hat package) - update to 0.10-2.el7_9
runc - update to 1.1.12-4.0.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.2.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.2
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
OpenShift API for Data Protection (OADP) - update to 1.3.4
containernetworking-plugins - update to 1.4.0-5.0.1
containernetworking-plugins (Red Hat package) - update to 1.5.1-2.el9
Network Observability plugin for the Openshift Console - update to 1.6.2
Migration Toolkit for Containers - update to 1.8.5
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo - update to 1.14.5-3.0.1
skopeo-tests - update to 1.14.5-3.0.1
Red Hat OpenShift GitOps - update to 1.15.3
golang-devel - addressed in versions 1.15.7-46, 1.17.3-35, 1.21.4-17, 1.21.4-31
golang - addressed in versions 1.15.7-46, 1.17.3-35, 1.21.4-17, 1.21.4-31
golang-help - addressed in versions 1.15.7-46, 1.17.3-35, 1.21.4-17, 1.21.4-31
skopeo (Red Hat package) - update to 1.16.1-1.el9
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang (Red Hat package) - addressed in versions 1.19.13-12.el9_2, 1.21.13-3.el9_4
delve - update to 1.21.2-4.0.1
golang - addressed in versions 1.21.12-1.fc39, 1.22.5-1.fc40
go1.21-doc - addressed in versions 1.21.12-1.39.1, 1.21.12-150000.1.39.1
go1.21 - addressed in versions 1.21.12-1.39.1, 1.21.12-150000.1.39.1
go1.21-race - update to 1.21.12-150000.1.39.1
go-toolset - update to 1.21.13-1
go1.21-openssl-race - update to 1.21.13.1-150600.16.3.1
go1.21-openssl-doc - update to 1.21.13.1-150600.16.3.1
go1.21-openssl - update to 1.21.13.1-150600.16.3.1
golang - update to 1.21.13-2.0.1
golang-tests - update to 1.21.13-2.0.1
golang-src - update to 1.21.13-2.0.1
golang-misc - update to 1.21.13-2.0.1
golang-docs - update to 1.21.13-2.0.1
golang-bin - update to 1.21.13-2.0.1
golang-1.22 (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
golang-1.22-go (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
golang-1.22-src (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
go1.22-doc - addressed in versions 1.22.5-1.15.1, 1.22.5-150000.1.21.1
go1.22 - addressed in versions 1.22.5-1.15.1, 1.22.5-150000.1.21.1
go1.22-race - update to 1.22.5-150000.1.21.1
go1.22-openssl - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-debuginfo - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-race - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-doc - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
buildah - addressed in versions 1.26.1-4, 1.34.1-5
buildah-debuginfo - addressed in versions 1.26.1-4, 1.34.1-5
buildah-debugsource - addressed in versions 1.26.1-4, 1.34.1-5
buildah-tests - update to 1.33.8-4
buildah - update to 1.33.8-4
buildah-tests - update to 1.34.1-5
buildah (Red Hat package) - update to 1.37.2-1.el9
containers-common - update to 1-82.0.1
AMQ Streams - update to 2
Planning Analytics Local - addressed in versions 2.0.0.103, 2.1.10
conmon - update to 2.1.10-1
container-suseconnect - update to 2.5.0-150000.4.55.1
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.14.1-467
container-selinux - update to 2.229.0-2
Cost Management - update to 3.3.1
podman-plugins - addressed in versions 3.4.4-5, 4.9.4-13
podman-remote - addressed in versions 3.4.4-5, 4.9.4-13
podman-gvproxy - addressed in versions 3.4.4-5, 4.9.4-13
etcd - addressed in versions 3.4.14-11, 3.4.14-16
Red Hat OpenShift Dev Spaces - update to 3.17.0
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
python3-podman - update to 4.9.0-2
podman-tests - update to 4.9.4-13
podmansh - update to 4.9.4-13
podman-docker - update to 4.9.4-13.0.1
podman-remote - update to 4.9.4-13.0.1
podman-plugins - update to 4.9.4-13.0.1
podman-tests - update to 4.9.4-13.0.1
podman-gvproxy - update to 4.9.4-13.0.1
podman-catatonit - update to 4.9.4-13.0.1
podman - update to 4.9.4-13.0.1
OpenShift Virtualization - addressed in versions 4.12.15, 4.13.11, 4.16.7
Red Hat OpenShift Container Platform - addressed in versions 4.12.68, 4.13.53, 4.14.40, 4.15.37, 4.16.18, 4.17.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.5
Kube Descheduler Operator for Red Hat OpenShift - update to 5.1.0
podman (Red Hat package) - update to 5.2.2-1.el9
OpenShift Logging - addressed in versions 5.6.25, 5.8.14, 5.9.8, 6.0.1
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
grafana (Red Hat package) - addressed in versions 9.2.10-18.el8_10, 10.2.6-4.el9
grafana-selinux - update to 9.2.10-18.0.1
grafana - update to 9.2.10-18.0.1
ceph (Red Hat package) - update to 19.2.1-222.el9cp
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
cockpit-podman - update to 84.1-1
IBM Concert Software - update to 1.0.5
Terraform - update to 1.9.3
go - update to 1.19.13-7
watsonx.data - update to 2.2
IBM Business Automation Manager Open Editions - update to 8.0.8
IBM Maximo Application Suite - addressed in versions 8.10.25, 8.11.22, 9.0.11
Splunk Enterprise - addressed in versions 9.1.9, 9.2.6, 9.3.4, 9.4.2
moby - update to 25.0.6
IBM Observability with Instana - addressed in versions 279, 282
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.0.99.5-5.el9
udica - update to 0.2.6-21
podman-debuginfo - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-debugsource - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-help - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-docker - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
python3-podman - update to 0.10.1-10
python3-pypodman - update to 0.10.1-10
podman - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
rhc-worker-script (Red Hat package) - update to 0.10-2.el7_9
runc - update to 1.1.12-4.0.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.2.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.2
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
OpenShift API for Data Protection (OADP) - update to 1.3.4
containernetworking-plugins - update to 1.4.0-5.0.1
containernetworking-plugins (Red Hat package) - update to 1.5.1-2.el9
Network Observability plugin for the Openshift Console - update to 1.6.2
Migration Toolkit for Containers - update to 1.8.5
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo - update to 1.14.5-3.0.1
skopeo-tests - update to 1.14.5-3.0.1
Red Hat OpenShift GitOps - update to 1.15.3
golang-devel - addressed in versions 1.15.7-46, 1.17.3-35, 1.21.4-17, 1.21.4-31
golang - addressed in versions 1.15.7-46, 1.17.3-35, 1.21.4-17, 1.21.4-31
golang-help - addressed in versions 1.15.7-46, 1.17.3-35, 1.21.4-17, 1.21.4-31
skopeo (Red Hat package) - update to 1.16.1-1.el9
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang (Red Hat package) - addressed in versions 1.19.13-12.el9_2, 1.21.13-3.el9_4
delve - update to 1.21.2-4.0.1
golang - addressed in versions 1.21.12-1.fc39, 1.22.5-1.fc40
go1.21-doc - addressed in versions 1.21.12-1.39.1, 1.21.12-150000.1.39.1
go1.21 - addressed in versions 1.21.12-1.39.1, 1.21.12-150000.1.39.1
go1.21-race - update to 1.21.12-150000.1.39.1
go-toolset - update to 1.21.13-1
go1.21-openssl-race - update to 1.21.13.1-150600.16.3.1
go1.21-openssl-doc - update to 1.21.13.1-150600.16.3.1
go1.21-openssl - update to 1.21.13.1-150600.16.3.1
golang - update to 1.21.13-2.0.1
golang-tests - update to 1.21.13-2.0.1
golang-src - update to 1.21.13-2.0.1
golang-misc - update to 1.21.13-2.0.1
golang-docs - update to 1.21.13-2.0.1
golang-bin - update to 1.21.13-2.0.1
golang-1.22 (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
golang-1.22-go (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
golang-1.22-src (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
go1.22-doc - addressed in versions 1.22.5-1.15.1, 1.22.5-150000.1.21.1
go1.22 - addressed in versions 1.22.5-1.15.1, 1.22.5-150000.1.21.1
go1.22-race - update to 1.22.5-150000.1.21.1
go1.22-openssl - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-debuginfo - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-race - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-doc - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
buildah - addressed in versions 1.26.1-4, 1.34.1-5
buildah-debuginfo - addressed in versions 1.26.1-4, 1.34.1-5
buildah-debugsource - addressed in versions 1.26.1-4, 1.34.1-5
buildah-tests - update to 1.33.8-4
buildah - update to 1.33.8-4
buildah-tests - update to 1.34.1-5
buildah (Red Hat package) - update to 1.37.2-1.el9
containers-common - update to 1-82.0.1
AMQ Streams - update to 2
Planning Analytics Local - addressed in versions 2.0.0.103, 2.1.10
conmon - update to 2.1.10-1
container-suseconnect - update to 2.5.0-150000.4.55.1
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.14.1-467
container-selinux - update to 2.229.0-2
Cost Management - update to 3.3.1
podman-plugins - addressed in versions 3.4.4-5, 4.9.4-13
podman-remote - addressed in versions 3.4.4-5, 4.9.4-13
podman-gvproxy - addressed in versions 3.4.4-5, 4.9.4-13
etcd - addressed in versions 3.4.14-11, 3.4.14-16
Red Hat OpenShift Dev Spaces - update to 3.17.0
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
python3-podman - update to 4.9.0-2
podman-tests - update to 4.9.4-13
podmansh - update to 4.9.4-13
podman-docker - update to 4.9.4-13.0.1
podman-remote - update to 4.9.4-13.0.1
podman-plugins - update to 4.9.4-13.0.1
podman-tests - update to 4.9.4-13.0.1
podman-gvproxy - update to 4.9.4-13.0.1
podman-catatonit - update to 4.9.4-13.0.1
podman - update to 4.9.4-13.0.1
OpenShift Virtualization - addressed in versions 4.12.15, 4.13.11, 4.16.7
Red Hat OpenShift Container Platform - addressed in versions 4.12.68, 4.13.53, 4.14.40, 4.15.37, 4.16.18, 4.17.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.5
Kube Descheduler Operator for Red Hat OpenShift - update to 5.1.0
podman (Red Hat package) - update to 5.2.2-1.el9
OpenShift Logging - addressed in versions 5.6.25, 5.8.14, 5.9.8, 6.0.1
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
grafana (Red Hat package) - addressed in versions 9.2.10-18.el8_10, 10.2.6-4.el9
grafana-selinux - update to 9.2.10-18.0.1
grafana - update to 9.2.10-18.0.1
ceph (Red Hat package) - update to 19.2.1-222.el9cp
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Denial of service in Go programming language
- SUSE update for go1.21
- SUSE update for go1.22
- SUSE update for go1.21
- SUSE update for go1.22
- Fedora 40 update for golang
- Fedora 39 update for golang
- Multiple vulnerabilities in Terraform
- Moby update for Go
- openEuler 24.03 LTS update for golang
- openEuler 22.03 LTS SP3 update for golang
- openEuler 20.03 LTS SP4 update for golang
- openEuler 22.03 LTS SP1 update for golang
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- openEuler 22.03 LTS SP4 update for golang
- Multiple vulnerabilities in Red Hat Cost Management
- Multiple vulnerabilities in IBM Observability with Instana
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 9 update for golang
- SUSE update for container-suseconnect
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.6
- Multiple vulnerabilities in IBM Instana Observability
- Red Hat Enterprise Linux 8 update for grafana
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Denial of service in Go openssl-fips
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.14
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift 1.2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Kube Descheduler Operator for Red Hat OpenShift 5.1
- Ubuntu update for golang-1.22
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in OpenShift Logging 6.0
- Multiple vulnerabilities in OpenShift Logging 5.8
- SUSE update for go1.21-openssl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- SUSE update for go1.22-openssl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- SUSE update for go1.22-openssl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for toolbox
- Ubuntu update for golang-1.17
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift (OSSO) 1.2
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for rhc-worker-script
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Ubuntu update for golang-1.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- openEuler 22.03 LTS SP4 update for buildah
- openEuler 24.03 LTS update for buildah
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 22.03 LTS SP3 update for podman
- openEuler 24.03 LTS SP1 update for podman
- openEuler 22.03 LTS SP4 update for podman
- openEuler 24.03 LTS update for podman
- openEuler 20.03 LTS SP4 update for podman
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- openEuler 24.03 LTS SP1 update for golang
- openEuler 20.03 LTS SP4 update for etcd
- openEuler 24.03 LTS SP1 update for etcd
- Multiple vulnerabilities in AMQ Streams
- Multiple vulnerabilities in IBM Concert Software
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for container-tools:an8 module
- Anolis OS update for grafana
- Multiple vulnerabilities in OpenShift Virtualization 4.16
- openEuler 24.03 LTS update for etcd
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.15
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Red Hat Ceph Storage 7