VDB
BDU%3A2024-02371
BDU%3A2024-02371
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость языка программирования Golang, связанная с ошибками освобождения памяти в коде шифрования/дешифрования RSA, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., The Go Project | Red Hat Enterprise Linux, OpenShift Developer Tools and Services, Red Hat Developer Tools, OpenShift Pipelines, Network-bound Disk Encryption (NBDE) Tang Server, Go |
Timeline
- Mar 28, 2024 CVE Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- https://github.com/advisories/GHSA-78hx-gp6g-7mj6 url
- https://github.com/golang-fips/openssl/security/advisories/GHSA-78hx-gp6g-7mj6 url
- https://github.com/golang-fips/openssl/releases/tag/v2.0.1 url
- https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2262921 url
- https://access.redhat.com/errata/RHSA-2024:1462 url
- https://access.redhat.com/errata/RHSA-2024:1468 url
- https://access.redhat.com/errata/RHSA-2024:1472 url
- https://access.redhat.com/errata/RHSA-2024:1501 url
- https://access.redhat.com/errata/RHSA-2024:1502 url
- https://www.cybersecurity-help.cz/vdb/SB2024032651 url
- https://github.com/microsoft/go-crypto-openssl/releases/tag/v0.2.9 advisory
- https://access.redhat.com/security/cve/CVE-2024-1394 advisory