Use of Uninitialized Variable in golang (Red Hat package) - CVE-2024-9355

 

Use of Uninitialized Variable in golang (Red Hat package) - CVE-2024-9355

Published: October 3, 2024


Vulnerability identifier: #VU98022
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9355
CWE-ID: CWE-457
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to weaken TLS encryption.

The vulnerability exists due to an uninitialized buffer length variable in the CGO bindings that intermittently return a zeroed buffer from (*boringHMAC).Sum() in FIPS mode. A remote attacker can randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode and weaken TLS security.


Affected software

golang (Red Hat package)
podman-debuginfo
podman-debugsource
podman-help
podman-docker
python3-podman
python3-pypodman
podman
rhc-worker-script (Red Hat package)
delve
go-toolset
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
golang
podman-gvproxy
podman-plugins
podman-remote
etcd
podmansh
podman-tests
grafana-pcp (Red Hat package)
grafana-pcp
grafana (Red Hat package)
grafana
grafana-selinux
osbuild-composer
osbuild-composer-core
osbuild-composer-worker
osbuild-depsolve-dnf
osbuild-doc
osbuild-luks2
osbuild-lvm2
osbuild-ostree
osbuild-selinux
python3-osbuild
osbuild
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Red Hat OpenShift GitOps
AMQ Streams
OpenShift Service Mesh
Red Hat OpenShift Container Platform
IBM Spectrum Protect Plus

How to mitigate CVE-2024-9355

Install updates from vendor's website.

golang (Red Hat package) - update to 1.21.13-4.el9_4
podman-debuginfo - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-debugsource - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-help - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-docker - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
python3-podman - update to 0.10.1-10
python3-pypodman - update to 0.10.1-10
podman - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
rhc-worker-script (Red Hat package) - update to 0.10-2.el7_9
Red Hat OpenShift GitOps - update to 1.15.3
delve - update to 1.21.2-4.0.1
go-toolset - update to 1.21.13-1
golang-tests - update to 1.21.13-3.0.1
golang-src - update to 1.21.13-3.0.1
golang-misc - update to 1.21.13-3.0.1
golang-docs - update to 1.21.13-3.0.1
golang-bin - update to 1.21.13-3.0.1
golang - update to 1.21.13-3.0.1
AMQ Streams - update to 2
OpenShift Service Mesh - update to 2.5.6
podman-gvproxy - addressed in versions 3.4.4-5, 4.9.4-13
podman-plugins - addressed in versions 3.4.4-5, 4.9.4-13
podman-remote - addressed in versions 3.4.4-5, 4.9.4-13
etcd - update to 3.4.14-15
podmansh - update to 4.9.4-13
podman-tests - update to 4.9.4-13
Red Hat OpenShift Container Platform - update to 4.17.1
grafana-pcp (Red Hat package) - addressed in versions 5.1.1-4.el9_4, 5.1.1-9.el8_10
grafana-pcp - update to 5.1.1-9.0.1
grafana (Red Hat package) - addressed in versions 9.2.10-19.el9_4, 9.2.10-20.el8_10
grafana - update to 9.2.10-20.0.1
grafana-selinux - update to 9.2.10-20.0.1
IBM Spectrum Protect Plus - update to 10.1.6.4
osbuild-composer - update to 132.2-1.0.1
osbuild-composer-core - update to 132.2-1.0.1
osbuild-composer-worker - update to 132.2-1.0.1
osbuild-depsolve-dnf - update to 141.2-1.0.1
osbuild-doc - update to 141.2-1.0.1
osbuild-luks2 - update to 141.2-1.0.1
osbuild-lvm2 - update to 141.2-1.0.1
osbuild-ostree - update to 141.2-1.0.1
osbuild-selinux - update to 141.2-1.0.1
python3-osbuild - update to 141.2-1.0.1
osbuild - update to 141.2-1.0.1

External References

Related Security Bulletins