Resource exhaustion in Go programming language - CVE-2024-34156
Published: September 12, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to encoding/gob does not properly control consumption of internal resources when calling Decoder.Decode. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Note, this vulnerability is related to #VU66068 (CVE-2024-34156).
Affected software
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
trivy
Guardium Data Security Center (GDSC)
IBM Business Automation Manager Open Editions
Business Automation Insights
Watson CP4D Data Stores
IBM Concert Software
IBM Cloud Pak for Security
IBM Process Mining
Cryostat
IBM Observability with Instana
DataPower Operator
Splunk Operator for Kubernetes Add-on
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Spectrum Protect Plus
Red Hat OpenStack
IBM Cloud Pak for Business Automation
QRadar Suite
WAL-G
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Quay
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
toolbox-tests
toolbox
udica
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
containernetworking-plugins (Red Hat package)
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
skopeo (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
golang-devel
golang
golang-help
golang (Red Hat package)
golang-1.17-src (Ubuntu package)
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
delve
go-toolset
golang-src
golang-bin
golang-docs
golang-misc
golang-tests
go1.21-openssl-race
go1.21-openssl-doc
go1.21-openssl
golang-1.22 (Ubuntu package)
golang-1.22-go (Ubuntu package)
golang-1.22-src (Ubuntu package)
go1.22
go1.22-doc
go1.22-openssl
go1.22-openssl-doc
go1.22-openssl-race
go1.22-openssl-debuginfo
go1.22-race
go1.23
go1.23-doc
go1.23-race
go1.23-openssl-race
go1.23-openssl
go1.23-openssl-debuginfo
go1.23-openssl-doc
buildah (Red Hat package)
delve (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah-tests
buildah
containers-common
conmon (Red Hat package)
conmon
haproxy (Red Hat package)
oath-toolkit (Red Hat package)
git-lfs (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
grafana-pcp (Red Hat package)
etcd (Red Hat package)
git-lfs
git-lfs-doc
python3-criu
crit
criu-libs
criu
criu-devel
cephadm-ansible (Red Hat package)
podman (Red Hat package)
libslirp
libslirp-devel
libreswan (Red Hat package)
python3-podman
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
podman-docker
openshift-ansible (Red Hat package)
openshift (Red Hat package)
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
kernel-rt (Red Hat package)
kernel (Red Hat package)
grafana (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
ceph (Red Hat package)
openstack-ironic (Red Hat package)
osbuild-composer (Red Hat package)
cockpit-podman
osbuild-composer
osbuild-composer-core
osbuild-composer-worker
Red Hat OpenShift GitOps
Planning Analytics Local
IBM API Connect
IBM Cloud Pak System
Red Hat Ceph Storage
IBM Security Verify Access
How to mitigate CVE-2024-34156
trivy - update to 0.56.0
IBM Concert Software - update to 1.0.5
QRadar Suite - addressed in versions 1.10.26.0, 1.10.27.0
IBM Process Mining - update to 2.0
WAL-G - update to 3.0.4
Guardium Data Security Center (GDSC) - update to 3.6.1
Quay - addressed in versions 3.9.0, 3.12.0, 3.13.10, 3.16.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.67, 4.12.68, 4.13.52, 4.13.53, 4.14.39, 4.14.40, 4.15.36, 4.15.37, 4.15.38, 4.16.16, 4.16.18, 4.16.19, 4.17.1, 4.17.2, 4.17.3
IBM Business Automation Manager Open Editions - update to 8.0.8
Business Automation Insights - update to 24.0.0.0.2
IBM Observability with Instana - update to 282
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
golang-github-prometheus-promu (Red Hat package) - addressed in versions 0.15.0-18.gitd5383c5.el8, 0.16.0-19.gitf6c51c9.el9
butane (Red Hat package) - addressed in versions 0.16.0-5.rhaos4.12.el8, 0.19.0-4.rhaos4.14.el8, 0.20.0-4.rhaos4.15.el8, 0.21.0-4.rhaos4.16.el8, 0.22.0-2.rhaos4.17.el8
containernetworking-plugins (Red Hat package) - addressed in versions 1.0.1-6.el9_0.1, 1.2.0-3.el9_2.1, 1.4.0-4.rhaos4.12.el8, 1.4.0-4.rhaos4.14.el8, 1.4.0-4.rhaos4.15.el8, 1.4.0-4.rhaos4.17.el8, 1.4.0-5.rhaos4.13.el8, 1.4.0-5.rhaos4.16.el8, 1.4.0-6.el9_4, 1.5.1-3.el9_5
runc (Red Hat package) - addressed in versions 1.1.6-9.rhaos4.12.el8, 1.1.14-2.rhaos4.13.el8, 1.1.14-2.rhaos4.13.el9, 1.1.14-2.rhaos4.14.el8, 1.1.14-2.rhaos4.14.el9, 1.1.14-2.rhaos4.15.el8, 1.1.14-2.rhaos4.15.el9, 1.1.14-2.rhaos4.17.el9, 1.1.14-3.rhaos4.16.el8, 1.1.14-3.rhaos4.16.el9
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
containernetworking-plugins - update to 1.4.0-5.0.1
DataPower Operator - addressed in versions 1.6.17, 1.11.3, 1.12.0
Network Observability plugin for the Openshift Console - update to 1.7.0
skopeo (Red Hat package) - addressed in versions 1.8.0-4.1.el9_0, 1.9.4-7.rhaos4.12.el8, 1.9.4-7.rhaos4.12.el9, 1.11.2-0.1.el9_2.2, 1.11.3-4.rhaos4.13.el8, 1.11.3-4.rhaos4.13.el9, 1.11.3-4.rhaos4.14.el8, 1.11.3-4.rhaos4.14.el9, 1.11.3-5.rhaos4.15.el8, 1.11.3-6.rhaos4.15.el9, 1.14.5-2.el9_4, 1.14.5-3.rhaos4.16.el8, 1.14.5-3.rhaos4.16.el9, 1.16.0-3.rhaos4.17.el8, 1.16.0-3.rhaos4.17.el9, 1.16.1-2.el9_5
Migration Toolkit for Containers - update to 1.8.5
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo - update to 1.14.5-3.0.1
skopeo-tests - update to 1.14.5-3.0.1
golang-devel - addressed in versions 1.15.7-48, 1.17.3-37, 1.21.4-26
golang - addressed in versions 1.15.7-48, 1.17.3-37, 1.21.4-26
golang-help - addressed in versions 1.15.7-48, 1.17.3-37, 1.21.4-26
golang (Red Hat package) - addressed in versions 1.17.13-2.el9_0, 1.19.13-12.el9_2, 1.21.13-3.el9_4, 1.23.6-2.el9_5
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.3
delve - update to 1.21.2-4.0.1
go-toolset - update to 1.21.13-1
golang-src - update to 1.21.13-2.0.1
golang - update to 1.21.13-2.0.1
golang-bin - update to 1.21.13-2.0.1
golang-docs - update to 1.21.13-2.0.1
golang-misc - update to 1.21.13-2.0.1
golang-tests - update to 1.21.13-2.0.1
go1.21-openssl-race - update to 1.21.13.4-150000.1.14.1
go1.21-openssl-doc - update to 1.21.13.4-150000.1.14.1
go1.21-openssl - update to 1.21.13.4-150000.1.14.1
golang-1.22 (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
golang-1.22-go (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
golang-1.22-src (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.3, 1.22.2-2~20.04.2, 1.22.2-2~22.04.2
go1.22 - addressed in versions 1.22.7-1.21.1, 1.22.7-150000.1.27.1
go1.22-doc - addressed in versions 1.22.7-1.21.1, 1.22.7-150000.1.27.1
go1.22-openssl - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-doc - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-race - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-openssl-debuginfo - addressed in versions 1.22.7.1-150000.1.3.1, 1.22.7.1-150600.13.3.1
go1.22-race - update to 1.22.7-150000.1.27.1
go1.23 - addressed in versions 1.23.1-1.6.1, 1.23.1-150000.1.6.1
go1.23-doc - addressed in versions 1.23.1-1.6.1, 1.23.1-150000.1.6.1
go1.23-race - update to 1.23.1-150000.1.6.1
go1.23-openssl-race - addressed in versions 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1
go1.23-openssl - addressed in versions 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1
go1.23-openssl-debuginfo - addressed in versions 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1
go1.23-openssl-doc - addressed in versions 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1
buildah (Red Hat package) - addressed in versions 1.23.4-8.rhaos4.12.el8, 1.23.4-8.rhaos4.12.el9, 1.26.7-1.el9_0.1, 1.29.1-5.rhaos4.13.el9, 1.29.1-13.rhaos4.14.el8, 1.29.1-13.rhaos4.14.el9, 1.29.1-24.rhaos4.15.el8, 1.29.1-24.rhaos4.15.el9, 1.29.3-1.el9_2.1, 1.33.7-3.rhaos4.17.el8, 1.33.7-3.rhaos4.17.el9, 1.33.7-4.rhaos4.16.el8, 1.33.7-4.rhaos4.16.el9, 1.33.9-1.el9_4, 1.37.5-1.el9_5
delve (Red Hat package) - update to 1.24.1-2.el9_5
cri-tools (Red Hat package) - addressed in versions 1.25.0-5.el8, 1.25.0-5.el9, 1.26.0-7.el8, 1.26.0-7.el9, 1.27.0-6.el8, 1.27.0-6.el9, 1.28.0-7.el8, 1.28.0-7.el9, 1.29.0-6.el8, 1.29.0-6.el9, 1.30.0-5.el8, 1.30.0-5.el9
cri-o (Red Hat package) - addressed in versions 1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-5.rhaos4.16.git34690b9.el8, 1.29.9-5.rhaos4.16.git34690b9.el9, 1.30.6-5.rhaos4.17.git690d4d6.el8, 1.30.6-5.rhaos4.17.git690d4d6.el9
buildah-tests - update to 1.33.8-4
buildah - update to 1.33.8-4
containers-common - update to 1-82.0.1
Planning Analytics Local - addressed in versions 2.0.0.103, 2.1.10
conmon (Red Hat package) - addressed in versions 2.1.2-8.rhaos4.12.el8, 2.1.2-9.rhaos4.12.el9, 2.1.7-5.rhaos4.13.el8, 2.1.7-5.rhaos4.13.el9, 2.1.7-6.rhaos4.14.el8, 2.1.7-6.rhaos4.14.el9, 2.1.7-10.rhaos4.15.el8, 2.1.7-15.rhaos4.15.el9, 2.1.10-5.rhaos4.16.el8, 2.1.10-5.rhaos4.16.el9, 2.1.12-5.rhaos4.17.el8, 2.1.12-5.rhaos4.17.el9
conmon - update to 2.1.10-1
haproxy (Red Hat package) - addressed in versions 2.2.24-5.rhaos4.12.el8, 2.2.24-5.rhaos4.13.el8
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.7.3
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
git-lfs (Red Hat package) - addressed in versions 2.11.0-2.el8_4.3, 2.13.3-3.el8_6.2, 2.13.3-5.el9_0.2, 3.2.0-2.el8_8.2, 3.2.0-2.el9_2.1, 3.4.1-3.el8_10, 3.4.1-4.el9_4
ignition (Red Hat package) - addressed in versions 2.14.0-8.rhaos4.12.el9, 2.14.0-10.rhaos4.12.el8, 2.15.0-10.rhaos4.13.el9, 2.16.2-5.rhaos4.14.el9, 2.16.2-6.rhaos4.15.el9, 2.18.0-5.rhaos4.16.el9
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.12.el8
container-selinux - update to 2.229.0-2
Splunk Operator for Kubernetes Add-on - update to 3.0.0
grafana-pcp (Red Hat package) - addressed in versions 3.2.0-3.el9_0, 5.1.1-2.el9_2, 5.1.1-3.el9_4, 5.1.1-9.el9_5
etcd (Red Hat package) - addressed in versions 3.3.23-17.el8ost, 3.4.26-9.1.el9ost
git-lfs - update to 3.4.1-3.0.1
git-lfs-doc - update to 3.4.1-3.0.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
python3-criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
podman (Red Hat package) - addressed in versions 4.2.0-5.el9_0.1, 4.2.0-12.rhaos4.12.el9, 4.4.1-8.rhaos4.12.el8, 4.4.1-15.rhaos4.13.el8, 4.4.1-16.rhaos4.13.el9, 4.4.1-20.el9_2.1, 4.4.1-21.rhaos4.14.el8, 4.4.1-21.rhaos4.14.el9, 4.4.1-31.rhaos4.15.el8, 4.4.1-31.rhaos4.15.el9, 4.9.4-10.rhaos4.16.el8, 4.9.4-12.rhaos4.16.el9, 4.9.4-13.el9_4, 5.2.2-9.el9_5, 5.2.3-2.rhaos4.17.el8, 5.2.3-2.rhaos4.17.el9
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.5.5
libreswan (Red Hat package) - update to 4.5-1.el9
python3-podman - update to 4.9.0-2
podman - update to 4.9.4-13.0.1
podman-catatonit - update to 4.9.4-13.0.1
podman-gvproxy - update to 4.9.4-13.0.1
podman-plugins - update to 4.9.4-13.0.1
podman-remote - update to 4.9.4-13.0.1
podman-tests - update to 4.9.4-13.0.1
podman-docker - update to 4.9.4-13.0.1
openshift-ansible (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd97dd6f.assembly.stream.el8, 4.13.0-202410181847.p0.g1397e80.assembly.stream.el8, 4.13.0-202410181847.p0.g1397e80.assembly.stream.el9, 4.14.0-202410181711.p0.g846e89b.assembly.stream.el8, 4.14.0-202410181711.p0.g846e89b.assembly.stream.el9, 4.15.0-202410181710.p0.g41f6580.assembly.stream.el8, 4.15.0-202410181710.p0.g41f6580.assembly.stream.el9, 4.16.0-202410172045.p0.g06f35b9.assembly.stream.el8, 4.16.0-202410172045.p0.g06f35b9.assembly.stream.el9, 4.17.0-202410111511.p0.g7fe7411.assembly.stream.el8, 4.17.0-202410111511.p0.g7fe7411.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.g1eb8682.assembly.stream.el8, 4.12.0-202410181935.p0.g1eb8682.assembly.stream.el9, 4.13.0-202410181847.p0.g53fd427.assembly.stream.el8, 4.13.0-202410181847.p0.g53fd427.assembly.stream.el9, 4.14.0-202410181711.p0.g03a907c.assembly.stream.el8, 4.14.0-202410181711.p0.g03a907c.assembly.stream.el9, 4.15.0-202410232006.p0.g502c5ce.assembly.stream.el8, 4.15.0-202410232006.p0.g502c5ce.assembly.stream.el9, 4.16.0-202410172045.p0.g632b078.assembly.stream.el8, 4.16.0-202410172045.p0.g632b078.assembly.stream.el9, 4.17.0-202410151605.p0.g6816ea6.assembly.stream.el8, 4.17.0-202410151605.p0.g6816ea6.assembly.stream.el9
openshift-kuryr (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.g8fd2f8b.assembly.stream.el8, 4.13.0-202410181847.p0.g36754b7.assembly.stream.el8, 4.14.0-202410181711.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd2acdd5.assembly.stream.el8, 4.13.0-202410181847.p0.gd2acdd5.assembly.stream.el8, 4.14.0-202410181711.p0.gd2acdd5.assembly.stream.el8, 4.15.0-202410181710.p0.gd2acdd5.assembly.stream.el8, 4.16.0-202410172045.p0.gd2acdd5.assembly.stream.el8, 4.17.0-202410111511.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd691257.assembly.stream.el8, 4.12.0-202410181935.p0.gd691257.assembly.stream.el9, 4.13.0-202410181847.p0.gd192e90.assembly.stream.el8, 4.13.0-202410181847.p0.gd192e90.assembly.stream.el9, 4.14.0-202410181711.p0.g44b3ac2.assembly.stream.el8, 4.14.0-202410181711.p0.g44b3ac2.assembly.stream.el9, 4.15.0-202410181710.p0.g8231637.assembly.stream.el8, 4.15.0-202410181710.p0.g8231637.assembly.stream.el9, 4.16.0-202410172045.p0.gcf533b5.assembly.stream.el8, 4.16.0-202410172045.p0.gcf533b5.assembly.stream.el9, 4.17.0-202410160306.p0.g6bf65cc.assembly.stream.el8, 4.17.0-202410160306.p0.g6bf65cc.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.14.0-202410181711.p0.g9a7820e.assembly.stream.el8, 4.14.0-202410181711.p0.g9a7820e.assembly.stream.el9, 4.15.0-202410181710.p0.gfd77d92.assembly.stream.el8, 4.15.0-202410181710.p0.gfd77d92.assembly.stream.el9, 4.16.0-202410172045.p0.ga53e9de.assembly.stream.el8, 4.16.0-202410172045.p0.ga53e9de.assembly.stream.el9, 4.17.0-202410111511.p0.g8c77f41.assembly.stream.el8, 4.17.0-202410111511.p0.g8c77f41.assembly.stream.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.13, 4.15.9, 4.16.4, 4.17.1
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.g0d799a2.assembly.stream.el8, 4.15.0-202410181710.p0.g0d799a2.assembly.stream.el9, 4.16.0-202410172045.p0.g0e95532.assembly.stream.el8, 4.16.0-202410172045.p0.g0e95532.assembly.stream.el9, 4.17.0-202410111511.p0.gb9204e2.assembly.stream.el8, 4.17.0-202410111511.p0.gb9204e2.assembly.stream.el9
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.gfc50272.assembly.stream.el8, 4.15.0-202410181710.p0.gfc50272.assembly.stream.el9, 4.16.0-202410172045.p0.g26b43df.assembly.stream.el8, 4.16.0-202410172045.p0.g26b43df.assembly.stream.el9, 4.17.0-202410111511.p0.g8ce997d.assembly.stream.el8, 4.17.0-202410111511.p0.g8ce997d.assembly.stream.el9
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.127.1.rt7.287.el8_6, 5.14.0-284.90.1.rt14.375.el9_2
Watson CP4D Data Stores - update to 5.1
OpenShift Logging - addressed in versions 5.6.25, 5.8.14, 5.9.8, 6.0.1
kernel (Red Hat package) - update to 5.14.0-284.90.1.el9_2
Red Hat Ceph Storage - addressed in versions 6.1, 8.1
grafana (Red Hat package) - addressed in versions 7.5.11-7.el9_0, 9.0.9-5.el9_2, 9.2.10-17.el9_4, 10.2.6-7.el9_5
openstack-ironic-python-agent (Red Hat package) - update to 9.0.1-0.20240913135525.2b2dd8f.el9
IBM Security Verify Access - update to 10.0.9
IBM API Connect - update to 10.0.9.0
IBM Spectrum Protect Plus - update to 10.1.6.4
Red Hat OpenStack - addressed in versions 16.2, 17.1
ceph (Red Hat package) - update to 19.2.1-222.el9cp
openstack-ironic (Red Hat package) - update to 21.0.1-0.20240913135525.114badc.el9
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
osbuild-composer (Red Hat package) - addressed in versions 28.7-2.el8_4, 46.3-2.el8_6, 46.3-2.el9_0, 75-2.el8_8, 76-3.el9_2.2, 101-2.el8_10, 101-2.el9_4, 118-2.el9_5
cockpit-podman - update to 84.1-1
osbuild-composer - addressed in versions 101-2.0.1, 118-2.0.1
osbuild-composer-core - addressed in versions 101-2.0.1, 118-2.0.1
osbuild-composer-worker - addressed in versions 101-2.0.1, 118-2.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- SUSE update for go1.22
- SUSE update for go1.23
- SUSE update for go1.22
- SUSE update for go1.23
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 9 update for grafana-pcp
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for grafana-pcp
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Multiple vulnerabilities in IBM Instana Observability
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Red Hat Enterprise Linux 9 update for grafana-pcp
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM QRadar Suite Software
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Trivy update for Go
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.7
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17 packages
- Ubuntu update for golang-1.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in OpenShift Logging 6.0
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in IBM Cloud Pak System
- SUSE update for go1.22-openssl
- SUSE update for go1.23-openssl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- SUSE update for go1.21-openssl
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in IBM DataPower Operator
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- wal-g update for Go
- SUSE update for go1.23-openssl
- SUSE update for go1.22-openssl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in QRadar Suite Software
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for grafana-pcp
- Red Hat Enterprise Linux 9 update for grafana
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Ubuntu update for golang-1.17
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- openEuler 20.03 LTS SP4 update for golang
- openEuler 22.03 LTS SP3 update for golang
- openEuler 24.03 LTS update for golang
- openEuler 22.03 LTS SP1 update for golang
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Ubuntu update for golang-1.18
- openEuler 22.03 LTS SP4 update for golang
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- IBM Watson CP4D Data Stores update for Golang Go
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Resource exhaustion in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Resource exhaustion in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Concert Software
- Anolis OS update for git-lfs
- Anolis OS update for osbuild-composer
- Anolis OS update for osbuild-composer
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for container-tools:an8 module
- Red Hat Enterprise Linux 9 update for delve and golang
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in Red Hat Ceph Storage 6
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Splunk Operator for Kubernetes Add-on update for third-party components
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat Quay 3.13
- Multiple vulnerabilities in Red Hat Quay