VDB
RHSA-2024%3A1362
RHSA-2024%3A1362
PUBLISHED
CVSS 5.900000095367432 MEDIUM
A flaw was found in Golang's protobuf module, where the unmarshal function can enter an infinite loop when processing certain invalid inputs. This issue occurs during unmarshaling into a message that includes a google.protobuf.Any or when the UnmarshalOptions.DiscardUnknown option is enabled. This flaw allows an attacker to craft malicious input tailored to trigger the identified flaw in the unmarshal function. By providing carefully constructed invalid inputs, they could potentially cause the function to enter an infinite loop, resulting in a denial of service condition or other unintended behaviors in the affected system.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/numaresources-operator-bundle@sha256:ced49845d0a750ca0851ed00b2883553796b46493859f368da77485b55e4faa6_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, openshift4/numaresources-operator-bundle@sha256:ced49845d0a750ca0851ed00b2883553796b46493859f368da77485b55e4faa6_amd64 |
| Red Hat | openshift4/numaresources-must-gather-rhel9@sha256:1dfef3b0b83661a09eda32c3d6a44e7414c212270ff96a9f482fe7451e5a619b_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-must-gather-rhel9@sha256:1dfef3b0b83661a09eda32c3d6a44e7414c212270ff96a9f482fe7451e5a619b_amd64, *, openshift4/numaresources-must-gather-rhel9@sha256:1dfef3b0b83661a09eda32c3d6a44e7414c212270ff96a9f482fe7451e5a619b_amd64 |
| Red Hat | openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64, openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64, openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64 |
| Red Hat | openshift4/numaresources-must-gather-rhel9@sha256:1dfef3b0b83661a09eda32c3d6a44e7414c212270ff96a9f482fe7451e5a619b_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:b45742b51ac994df990a8e2494e15b6db2e3d33c7de87e4a7dc41ea17225a57b_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/cnf-tests-rhel8@sha256:b45742b51ac994df990a8e2494e15b6db2e3d33c7de87e4a7dc41ea17225a57b_amd64, openshift4/cnf-tests-rhel8@sha256:b45742b51ac994df990a8e2494e15b6db2e3d33c7de87e4a7dc41ea17225a57b_amd64 |
| Red Hat | openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:ced49845d0a750ca0851ed00b2883553796b46493859f368da77485b55e4faa6_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/numaresources-operator-bundle@sha256:ced49845d0a750ca0851ed00b2883553796b46493859f368da77485b55e4faa6_amd64, *, openshift4/numaresources-operator-bundle@sha256:ced49845d0a750ca0851ed00b2883553796b46493859f368da77485b55e4faa6_amd64 |
| Red Hat | openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64, openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64, openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64 |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64, openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64, * |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:b45742b51ac994df990a8e2494e15b6db2e3d33c7de87e4a7dc41ea17225a57b_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, openshift4/cnf-tests-rhel8@sha256:b45742b51ac994df990a8e2494e15b6db2e3d33c7de87e4a7dc41ea17225a57b_amd64 |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64, openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64, * |
| Red Hat | openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64, openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64 |
Timeline
- Mar 20, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:1362 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/cve-2024-24786 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268046 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1362.json advisory
- https://access.redhat.com/security/cve/CVE-2024-24786 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-24786 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-24786 advisory
- https://go.dev/cl/569356 advisory
- https://groups.google.com/g/golang-announce/c/ArQ6CDgtEjY/ advisory
- https://pkg.go.dev/vuln/GO-2024-2611 advisory