RHSA-2024%3A1474
A flaw was found in Golang's protobuf module, where the unmarshal function can enter an infinite loop when processing certain invalid inputs. This issue occurs during unmarshaling into a message that includes a google.protobuf.Any or when the UnmarshalOptions.DiscardUnknown option is enabled. This flaw allows an attacker to craft malicious input tailored to trigger the identified flaw in the unmarshal function. By providing carefully constructed invalid inputs, they could potentially cause the function to enter an infinite loop, resulting in a denial of service condition or other unintended behaviors in the affected system.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:45260f2ea7388adf6baa5d70ba4bcaf8fc214379e63c6d1841f2190146225d7c_amd64 as a component of RHOL 5.8 for RHEL 9 | *, *, openshift-logging/elasticsearch-rhel9-operator@sha256:45260f2ea7388adf6baa5d70ba4bcaf8fc214379e63c6d1841f2190146225d7c_amd64 |
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:01554e429a76b38ff40df478aa0375049de42d3205ce409d20b3727944d6633e_s390x as a component of RHOL 5.8 for RHEL 9 | *, *, * |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le, openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le, openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le |
| Red Hat | openshift-logging/loki-operator-bundle@sha256:26eae522aa2f99346cbbf8ca2398ee5dfa43416874818130f1a4954fbe3fc568_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/loki-operator-bundle@sha256:26eae522aa2f99346cbbf8ca2398ee5dfa43416874818130f1a4954fbe3fc568_amd64, *, openshift-logging/loki-operator-bundle@sha256:26eae522aa2f99346cbbf8ca2398ee5dfa43416874818130f1a4954fbe3fc568_amd64 |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:e675cf08865e719a59908f4c86f10e5a9701abff3f99eea4fbac121c24d22e84_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/loki-rhel9-operator@sha256:e675cf08865e719a59908f4c86f10e5a9701abff3f99eea4fbac121c24d22e84_arm64, openshift-logging/loki-rhel9-operator@sha256:e675cf08865e719a59908f4c86f10e5a9701abff3f99eea4fbac121c24d22e84_arm64, openshift-logging/loki-rhel9-operator@sha256:e675cf08865e719a59908f4c86f10e5a9701abff3f99eea4fbac121c24d22e84_arm64 |
| Red Hat | openshift-logging/lokistack-gateway-rhel9@sha256:477362b69f4b2c70c1f795a127cbc7d94d3a561a26a613a850e5c787e2fdb1ba_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/lokistack-gateway-rhel9@sha256:477362b69f4b2c70c1f795a127cbc7d94d3a561a26a613a850e5c787e2fdb1ba_s390x, openshift-logging/lokistack-gateway-rhel9@sha256:477362b69f4b2c70c1f795a127cbc7d94d3a561a26a613a850e5c787e2fdb1ba_s390x, openshift-logging/lokistack-gateway-rhel9@sha256:477362b69f4b2c70c1f795a127cbc7d94d3a561a26a613a850e5c787e2fdb1ba_s390x |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:6bcd6f0a587735e4fc95c8fdbdb09e5635897f47ac5b7599c618f870a7964b9e_arm64 as a component of RHOL 5.8 for RHEL 9 | *, openshift-logging/opa-openshift-rhel9@sha256:6bcd6f0a587735e4fc95c8fdbdb09e5635897f47ac5b7599c618f870a7964b9e_arm64, * |
| Red Hat | openshift-logging/logging-curator5-rhel9@sha256:b5d6161bf00f02a482d19c0888bba02374227b41441857bd842743c9bf813436_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-curator5-rhel9@sha256:b5d6161bf00f02a482d19c0888bba02374227b41441857bd842743c9bf813436_s390x, *, openshift-logging/logging-curator5-rhel9@sha256:b5d6161bf00f02a482d19c0888bba02374227b41441857bd842743c9bf813436_s390x |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:6788b39171834e8139be9ea6049b18e2321f20a9f8dba49b7347984521f906a9_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/loki-rhel9-operator@sha256:6788b39171834e8139be9ea6049b18e2321f20a9f8dba49b7347984521f906a9_ppc64le, openshift-logging/loki-rhel9-operator@sha256:6788b39171834e8139be9ea6049b18e2321f20a9f8dba49b7347984521f906a9_ppc64le, * |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:258f0f544ddeb993bdb5efe8a24f2b2c057d0a08f15935912931637ee594b1ea_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/fluentd-rhel9@sha256:258f0f544ddeb993bdb5efe8a24f2b2c057d0a08f15935912931637ee594b1ea_arm64, openshift-logging/fluentd-rhel9@sha256:258f0f544ddeb993bdb5efe8a24f2b2c057d0a08f15935912931637ee594b1ea_arm64, openshift-logging/fluentd-rhel9@sha256:258f0f544ddeb993bdb5efe8a24f2b2c057d0a08f15935912931637ee594b1ea_arm64 |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:57cf91af5c4e460ec8efbbb7265f4678f383b637acc88045ee10fbc4d62c18e8_arm64 as a component of RHOL 5.8 for RHEL 9 | *, openshift-logging/eventrouter-rhel9@sha256:57cf91af5c4e460ec8efbbb7265f4678f383b637acc88045ee10fbc4d62c18e8_arm64, openshift-logging/eventrouter-rhel9@sha256:57cf91af5c4e460ec8efbbb7265f4678f383b637acc88045ee10fbc4d62c18e8_arm64 |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:257f2085a55b76bbf538deec00f7bbd80a13164214c674b2dd1e98bcdb3f9dcb_s390x as a component of RHOL 5.8 for RHEL 9 | *, *, openshift-logging/log-file-metric-exporter-rhel9@sha256:257f2085a55b76bbf538deec00f7bbd80a13164214c674b2dd1e98bcdb3f9dcb_s390x |
| Red Hat | openshift-logging/logging-loki-rhel9@sha256:c6da517dc5f645a2031d7767a979758c577933b4e1e1d6099cd449a91e1f08a0_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-loki-rhel9@sha256:c6da517dc5f645a2031d7767a979758c577933b4e1e1d6099cd449a91e1f08a0_s390x, openshift-logging/logging-loki-rhel9@sha256:c6da517dc5f645a2031d7767a979758c577933b4e1e1d6099cd449a91e1f08a0_s390x, openshift-logging/logging-loki-rhel9@sha256:c6da517dc5f645a2031d7767a979758c577933b4e1e1d6099cd449a91e1f08a0_s390x |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel9@sha256:d79ab63de84c5b1f6da4878cb6a4bec03f7beb3b1fd48d4b0cad9c127b97ec3d_amd64 as a component of RHOL 5.8 for RHEL 9 | *, *, openshift-logging/elasticsearch-proxy-rhel9@sha256:d79ab63de84c5b1f6da4878cb6a4bec03f7beb3b1fd48d4b0cad9c127b97ec3d_amd64 |
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:260d4698651482296fb74dfcf711b8211dbb8515ae001f3976a4949f01783384_ppc64le as a component of RHOL 5.8 for RHEL 9 | *, *, openshift-logging/elasticsearch-rhel9-operator@sha256:260d4698651482296fb74dfcf711b8211dbb8515ae001f3976a4949f01783384_ppc64le |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:271f5de065e6842fe381ccec36d97e0690488206cbfa58a3abd0f93ff58e5cd8_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/eventrouter-rhel9@sha256:271f5de065e6842fe381ccec36d97e0690488206cbfa58a3abd0f93ff58e5cd8_s390x, openshift-logging/eventrouter-rhel9@sha256:271f5de065e6842fe381ccec36d97e0690488206cbfa58a3abd0f93ff58e5cd8_s390x, openshift-logging/eventrouter-rhel9@sha256:271f5de065e6842fe381ccec36d97e0690488206cbfa58a3abd0f93ff58e5cd8_s390x |
| Red Hat | openshift-logging/logging-view-plugin-rhel9@sha256:03f8d6cb6dafde7012ce4872aae31ac372ce485601334c2bddff03141fc07103_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-view-plugin-rhel9@sha256:03f8d6cb6dafde7012ce4872aae31ac372ce485601334c2bddff03141fc07103_s390x, openshift-logging/logging-view-plugin-rhel9@sha256:03f8d6cb6dafde7012ce4872aae31ac372ce485601334c2bddff03141fc07103_s390x, * |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:9d3c09c7e8e26c95beeb5d7761f9d29fc0685b366ce61ae163000d78cebb23e3_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:9d3c09c7e8e26c95beeb5d7761f9d29fc0685b366ce61ae163000d78cebb23e3_amd64, *, openshift-logging/log-file-metric-exporter-rhel9@sha256:9d3c09c7e8e26c95beeb5d7761f9d29fc0685b366ce61ae163000d78cebb23e3_amd64 |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le, *, openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le |
| Red Hat | openshift-logging/vector-rhel9@sha256:5fb1d2d210ea492885885a863653049dae8ab8b6fecd24dd81a3fd6ff975e479_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/vector-rhel9@sha256:5fb1d2d210ea492885885a863653049dae8ab8b6fecd24dd81a3fd6ff975e479_ppc64le, *, openshift-logging/vector-rhel9@sha256:5fb1d2d210ea492885885a863653049dae8ab8b6fecd24dd81a3fd6ff975e479_ppc64le |
…and 98 more
Timeline
- Mar 27, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:1474 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268046 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2269576 issue
- https://issues.redhat.com/browse/LOG-5044 advisory
- https://issues.redhat.com/browse/LOG-5171 advisory
- https://issues.redhat.com/browse/LOG-5201 advisory
- https://issues.redhat.com/browse/LOG-5240 advisory
- https://issues.redhat.com/browse/LOG-5250 advisory
- https://issues.redhat.com/browse/LOG-5270 advisory
- https://issues.redhat.com/browse/LOG-5272 advisory
- https://issues.redhat.com/browse/LOG-5274 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1474.json advisory
- https://access.redhat.com/security/cve/CVE-2024-24786 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-24786 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-24786 advisory
- https://go.dev/cl/569356 advisory
- https://groups.google.com/g/golang-announce/c/ArQ6CDgtEjY/ advisory
- https://pkg.go.dev/vuln/GO-2024-2611 advisory
- https://access.redhat.com/security/cve/CVE-2024-28849 advisory
…and 3 more