VDB
RHSA-2024%3A4464
RHSA-2024%3A4464
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/cluster-backup-rhel9-operator@sha256:0d141d0fa859ae0061605f2fe13381be2b6ebd9d8c6b91ca171a8e61e52842be_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | * |
| Red Hat | rhacm2/node-exporter-rhel9@sha256:8bb239eafceaa18a786b78f7bf54c7063d80bce60567d10d81c5a4282b2884b4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/node-exporter-rhel9@sha256:8bb239eafceaa18a786b78f7bf54c7063d80bce60567d10d81c5a4282b2884b4_s390x |
| Red Hat | rhacm2/klusterlet-addon-controller-rhel9@sha256:8528a204787ecde3925c9c3ef31e225f59c5b4b3a21bd314541fe06dd4c1aa73_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/klusterlet-addon-controller-rhel9@sha256:8528a204787ecde3925c9c3ef31e225f59c5b4b3a21bd314541fe06dd4c1aa73_s390x |
| Red Hat | rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0b885dfd28d82220fdb03b7bca0e1ed2fc941bc712e536af71e4e11ee9defee4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0b885dfd28d82220fdb03b7bca0e1ed2fc941bc712e536af71e4e11ee9defee4_amd64 |
| Red Hat | rhacm2/prometheus-rhel9@sha256:556c5d133dd996b86dceb03158d4d463ccdbbf29cc9ca05ff1e3915a48cd8c47_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/prometheus-rhel9@sha256:556c5d133dd996b86dceb03158d4d463ccdbbf29cc9ca05ff1e3915a48cd8c47_s390x |
| Red Hat | rhacm2/prometheus-alertmanager-rhel9@sha256:0e7e5cfd6a953e092eb3ae72b236741f73432f8d262ace74caa2acf8c5fe3863_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | * |
| Red Hat | rhacm2/acm-search-indexer-rhel9@sha256:47083a8e2f6234e7e3743c2f7d5cc433ad76a46a609f65640e047bfa9557082c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/acm-search-indexer-rhel9@sha256:47083a8e2f6234e7e3743c2f7d5cc433ad76a46a609f65640e047bfa9557082c_s390x |
| Red Hat | rhacm2/multiclusterhub-rhel9@sha256:97932a785e8601b170a7c6fd42b1e6a18203b958ccbb712352c2817b8103d9b5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/multiclusterhub-rhel9@sha256:97932a785e8601b170a7c6fd42b1e6a18203b958ccbb712352c2817b8103d9b5_s390x |
| Red Hat | rhacm2/insights-metrics-rhel9@sha256:44f56f7a1ac2720ce815ea7aa824ea37a0bdcf63c637941ca84328578a735142_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/insights-metrics-rhel9@sha256:44f56f7a1ac2720ce815ea7aa824ea37a0bdcf63c637941ca84328578a735142_arm64 |
| Red Hat | rhacm2/insights-metrics-rhel9@sha256:2f7c346cb847e2928715bd4b64a34531b82d0130a89a08f19c3026db5d89c5a1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | * |
| Red Hat | rhacm2/insights-client-rhel9@sha256:0ff4ca5a9703ec58d70178152b5dbbb3aaffa5fce80153eda12f727f7c3e0b6f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/insights-client-rhel9@sha256:0ff4ca5a9703ec58d70178152b5dbbb3aaffa5fce80153eda12f727f7c3e0b6f_ppc64le |
| Red Hat | rhacm2/node-exporter-rhel9@sha256:f9a4446156fd21112854846849c68952e4c336e5782d6aeb3c49bddd3408d388_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/node-exporter-rhel9@sha256:f9a4446156fd21112854846849c68952e4c336e5782d6aeb3c49bddd3408d388_ppc64le |
| Red Hat | rhacm2/memcached-exporter-rhel9@sha256:36529c281273e5346ef5cce6a55e47c27fdaf2507a6f7971576b738b1c543258_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | * |
| Red Hat | rhacm2/iam-policy-controller-rhel9@sha256:63ca0eef9b3febe70ceea5b47a36fea7455eef69da9d1bda70d2bc9661ec2f2c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/iam-policy-controller-rhel9@sha256:63ca0eef9b3febe70ceea5b47a36fea7455eef69da9d1bda70d2bc9661ec2f2c_arm64 |
| Red Hat | rhacm2/acm-grafana-rhel9@sha256:3a59dd5e30b37f1e1feffba959d88d3aab37701500203afb71b2d38958236b85_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/acm-grafana-rhel9@sha256:3a59dd5e30b37f1e1feffba959d88d3aab37701500203afb71b2d38958236b85_amd64 |
| Red Hat | rhacm2/multicluster-operators-application-rhel9@sha256:184f6068b077070b90ede3a2f4e81be398fd2841f042fc6f2f114fdfd4f1095b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/multicluster-operators-application-rhel9@sha256:184f6068b077070b90ede3a2f4e81be398fd2841f042fc6f2f114fdfd4f1095b_arm64 |
| Red Hat | rhacm2/acm-grafana-rhel9@sha256:1cd1c6a91611569a855444430c527a8bebbe113f77dd47dcfc2b8305c3a26a13_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | * |
| Red Hat | rhacm2/kube-rbac-proxy-rhel9@sha256:5e416f1249a77845f81c9cf1a1dfae74feca41afd6dd35e7be55a0fa61632c00_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | * |
| Red Hat | rhacm2/acm-volsync-addon-controller-rhel9@sha256:faee49ca0c46781594189977f3ab5805060cd0a95e47ba575ec05bb549e21a69_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/acm-volsync-addon-controller-rhel9@sha256:faee49ca0c46781594189977f3ab5805060cd0a95e47ba575ec05bb549e21a69_s390x |
| Red Hat | rhacm2/grafana-dashboard-loader-rhel9@sha256:26a08abd967f17e23975b728768e2f561750856b0f98ff5f27506da94fa597ca_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 | rhacm2/grafana-dashboard-loader-rhel9@sha256:26a08abd967f17e23975b728768e2f561750856b0f98ff5f27506da94fa597ca_ppc64le |
…and 155 more
Timeline
- Jul 10, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:4464 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://issues.redhat.com/browse/ACM-11006 advisory
- https://issues.redhat.com/browse/ACM-11662 advisory
- https://issues.redhat.com/browse/ACM-11961 advisory
- https://issues.redhat.com/browse/ACM-11986 advisory
- https://issues.redhat.com/browse/ACM-12028 advisory
- https://issues.redhat.com/browse/ACM-12091 advisory
- https://issues.redhat.com/browse/ACM-12133 advisory
- https://issues.redhat.com/browse/ACM-12258 advisory
- https://issues.redhat.com/browse/ACM-12405 advisory
- https://issues.redhat.com/browse/ACM-12436 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4464.json advisory
- https://access.redhat.com/security/cve/CVE-2023-45288 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://www.cve.org/CVERecord?id=CVE-2023-45288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45288 advisory
- https://nowotarski.info/http2-continuation-flood/ advisory
- https://pkg.go.dev/vuln/GO-2024-2687 advisory
- https://www.kb.cert.org/vuls/id/421644 advisory
…and 7 more