VDB
RHSA-2024%3A10883
RHSA-2024%3A10883
PUBLISHED
CVSS 5.900000095367432 MEDIUM
A flaw was found in the go/parser package of the Golang standard library. Calling any Parse functions on Go source code containing deeply nested literals can cause a panic due to stack exhaustion.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhosp-rhel8/osp-director-agent@sha256:7924ce959b8f61cb616be22d86c827a18d760793efa3c94e4f8126e4c9284435_amd64 as a component of Red Hat OpenStack Platform 16.2 | rhosp-rhel8/osp-director-agent@sha256:7924ce959b8f61cb616be22d86c827a18d760793efa3c94e4f8126e4c9284435_amd64 |
| Red Hat | rhosp-rhel8/osp-director-downloader@sha256:f46899b93e13479c9d9745dade9b492295b4e8837a4860148537b080c87da132_amd64 as a component of Red Hat OpenStack Platform 16.2 | * |
| Red Hat | rhosp-rhel8/osp-director-operator-bundle@sha256:7343bf678b1eaad5782a067ff808052f7c1870d0acbac93bc6da07a4aa86db7a_amd64 as a component of Red Hat OpenStack Platform 16.2 | * |
| Red Hat | rhosp-rhel8/osp-director-operator@sha256:0c12f081a27a205aefcd7aed040a28a156f2e5a78731bc9c6bf088bddacccb05_amd64 as a component of Red Hat OpenStack Platform 16.2 | rhosp-rhel8/osp-director-operator@sha256:0c12f081a27a205aefcd7aed040a28a156f2e5a78731bc9c6bf088bddacccb05_amd64 |
Timeline
- Dec 9, 2024 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:10883 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2310527 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2310528 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10883.json advisory
- https://access.redhat.com/security/cve/CVE-2024-34155 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-34155 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-34155 advisory
- https://go.dev/cl/611238 advisory
- https://go.dev/issue/69138 advisory
- https://groups.google.com/g/golang-dev/c/S9POB9NCTdk advisory
- https://pkg.go.dev/vuln/GO-2024-3105 advisory
- https://access.redhat.com/security/cve/CVE-2024-34156 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-34156 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-34156 advisory
- https://go.dev/cl/611239 advisory
- https://go.dev/issue/69139 advisory
- https://pkg.go.dev/vuln/GO-2024-3106 advisory