VDB
RHSA-2024%3A1363
RHSA-2024%3A1363
PUBLISHED
CVSS 5.900000095367432 MEDIUM
A flaw was found in Golang's protobuf module, where the unmarshal function can enter an infinite loop when processing certain invalid inputs. This issue occurs during unmarshaling into a message that includes a google.protobuf.Any or when the UnmarshalOptions.DiscardUnknown option is enabled. This flaw allows an attacker to craft malicious input tailored to trigger the identified flaw in the unmarshal function. By providing carefully constructed invalid inputs, they could potentially cause the function to enter an infinite loop, resulting in a denial of service condition or other unintended behaviors in the affected system.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64, openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64, openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64 |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64, openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64, openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64 |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64, openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64, openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64 |
| Red Hat | openshift4/noderesourcetopology-scheduler-rhel9@sha256:aacfeaa5f1f750434195327d064524ac879f83901b6650eea8eec20103d23d60_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, openshift4/noderesourcetopology-scheduler-rhel9@sha256:aacfeaa5f1f750434195327d064524ac879f83901b6650eea8eec20103d23d60_amd64 |
| Red Hat | openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64, openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:841a2c113c031b8f4af107359feec70e74996b42d71a503e2e43483f0e73ffcc_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/numaresources-operator-bundle@sha256:841a2c113c031b8f4af107359feec70e74996b42d71a503e2e43483f0e73ffcc_amd64, *, openshift4/numaresources-operator-bundle@sha256:841a2c113c031b8f4af107359feec70e74996b42d71a503e2e43483f0e73ffcc_amd64 |
| Red Hat | openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64, openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64 |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:841a2c113c031b8f4af107359feec70e74996b42d71a503e2e43483f0e73ffcc_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/numaresources-operator-bundle@sha256:841a2c113c031b8f4af107359feec70e74996b42d71a503e2e43483f0e73ffcc_amd64, *, * |
| Red Hat | openshift4/noderesourcetopology-scheduler-rhel9@sha256:aacfeaa5f1f750434195327d064524ac879f83901b6650eea8eec20103d23d60_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/noderesourcetopology-scheduler-rhel9@sha256:aacfeaa5f1f750434195327d064524ac879f83901b6650eea8eec20103d23d60_amd64, *, * |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64, openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64, openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64 |
| Red Hat | openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64, openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64, openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64 |
Timeline
- Mar 19, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:1363 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/cve-2024-24786 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268046 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1363.json advisory
- https://access.redhat.com/security/cve/CVE-2024-24786 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-24786 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-24786 advisory
- https://go.dev/cl/569356 advisory
- https://groups.google.com/g/golang-announce/c/ArQ6CDgtEjY/ advisory
- https://pkg.go.dev/vuln/GO-2024-2611 advisory