Use of Uninitialized Variable in golang (Red Hat package) - CVE-2024-9355
Published: October 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to weaken TLS encryption.
The vulnerability exists due to an uninitialized buffer length variable in the CGO bindings that intermittently return a zeroed buffer from (*boringHMAC).Sum() in FIPS mode. A remote attacker can randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode and weaken TLS security.
Affected software
podman-debuginfo
podman-debugsource
podman-help
podman-docker
python3-podman
python3-pypodman
podman
rhc-worker-script (Red Hat package)
delve
go-toolset
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
golang
podman-gvproxy
podman-plugins
podman-remote
etcd
podmansh
podman-tests
grafana-pcp (Red Hat package)
grafana-pcp
grafana (Red Hat package)
grafana
grafana-selinux
osbuild-composer
osbuild-composer-core
osbuild-composer-worker
osbuild-depsolve-dnf
osbuild-doc
osbuild-luks2
osbuild-lvm2
osbuild-ostree
osbuild-selinux
python3-osbuild
osbuild
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Red Hat OpenShift GitOps
AMQ Streams
OpenShift Service Mesh
Red Hat OpenShift Container Platform
IBM Spectrum Protect Plus
How to mitigate CVE-2024-9355
podman-debuginfo - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-debugsource - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-help - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
podman-docker - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
python3-podman - update to 0.10.1-10
python3-pypodman - update to 0.10.1-10
podman - addressed in versions 0.10.1-10, 3.4.4-5, 4.9.4-13
rhc-worker-script (Red Hat package) - update to 0.10-2.el7_9
Red Hat OpenShift GitOps - update to 1.15.3
delve - update to 1.21.2-4.0.1
go-toolset - update to 1.21.13-1
golang-tests - update to 1.21.13-3.0.1
golang-src - update to 1.21.13-3.0.1
golang-misc - update to 1.21.13-3.0.1
golang-docs - update to 1.21.13-3.0.1
golang-bin - update to 1.21.13-3.0.1
golang - update to 1.21.13-3.0.1
AMQ Streams - update to 2
OpenShift Service Mesh - update to 2.5.6
podman-gvproxy - addressed in versions 3.4.4-5, 4.9.4-13
podman-plugins - addressed in versions 3.4.4-5, 4.9.4-13
podman-remote - addressed in versions 3.4.4-5, 4.9.4-13
etcd - update to 3.4.14-15
podmansh - update to 4.9.4-13
podman-tests - update to 4.9.4-13
Red Hat OpenShift Container Platform - update to 4.17.1
grafana-pcp (Red Hat package) - addressed in versions 5.1.1-4.el9_4, 5.1.1-9.el8_10
grafana-pcp - update to 5.1.1-9.0.1
grafana (Red Hat package) - addressed in versions 9.2.10-19.el9_4, 9.2.10-20.el8_10
grafana - update to 9.2.10-20.0.1
grafana-selinux - update to 9.2.10-20.0.1
IBM Spectrum Protect Plus - update to 10.1.6.4
osbuild-composer - update to 132.2-1.0.1
osbuild-composer-core - update to 132.2-1.0.1
osbuild-composer-worker - update to 132.2-1.0.1
osbuild-depsolve-dnf - update to 141.2-1.0.1
osbuild-doc - update to 141.2-1.0.1
osbuild-luks2 - update to 141.2-1.0.1
osbuild-lvm2 - update to 141.2-1.0.1
osbuild-ostree - update to 141.2-1.0.1
osbuild-selinux - update to 141.2-1.0.1
python3-osbuild - update to 141.2-1.0.1
osbuild - update to 141.2-1.0.1
External References
Related Security Bulletins
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 9 update for golang
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 8 update for grafana-pcp
- Red Hat Enterprise Linux 9 update for grafana-pcp
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for rhc-worker-script
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- openEuler 22.03 LTS SP3 update for podman
- openEuler 24.03 LTS SP1 update for podman
- openEuler 22.03 LTS SP4 update for podman
- openEuler 24.03 LTS update for podman
- openEuler 20.03 LTS SP4 update for podman
- openEuler 24.03 LTS update for etcd
- openEuler 24.03 LTS SP1 update for etcd
- Multiple vulnerabilities in AMQ Streams
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for grafana
- Anolis OS update for grafana-pcp
- Anolis OS update for osbuild
- Anolis OS update for osbuild-composer
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.15