VDB

RHSA-2024%3A5438

RHSA-2024%3A5438 PUBLISHED CVSS 5.900000095367432 MEDIUM

A flaw was found in the SSH channel integrity. By manipulating sequence numbers during the handshake, an attacker can remove the initial messages on the secure channel without causing a MAC failure. For example, an attacker could disable the ping extension and thus disable the new countermeasure in OpenSSH 9.5 against keystroke timing attacks.

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-clusterresourceoverride-rhel9@sha256:3822cae76e37e297c76855e9204c93fbda26eeb038e13a7bf4c173264a2b5752_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-clusterresourceoverride-rhel9@sha256:3822cae76e37e297c76855e9204c93fbda26eeb038e13a7bf4c173264a2b5752_arm64
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:718db839a9be5211f32061df8a5636e7fbc44f9f595d92f78189d9dfb0ba25e1_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:718db839a9be5211f32061df8a5636e7fbc44f9f595d92f78189d9dfb0ba25e1_arm64
Red Hatopenshift4/sriov-cni-rhel9@sha256:92700c3fa5dd4ce2879ffd36c0ae26d79b953ec3a2551f4fe322cd85f4eaaf9d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*, *
Red Hatopenshift4/ose-cloud-event-proxy-rhel9@sha256:a208efe0b84e55356a3082ee63e84b40a4b470af4d9433a8b349b605449040b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-cloud-event-proxy-rhel9@sha256:a208efe0b84e55356a3082ee63e84b40a4b470af4d9433a8b349b605449040b7_ppc64le
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:a2a4cc4297e039bd8de20fd8656490dd5d6fba7f1f1ed59861a741b0162c0f84_ppc64le as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:a2a4cc4297e039bd8de20fd8656490dd5d6fba7f1f1ed59861a741b0162c0f84_ppc64le, openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:a2a4cc4297e039bd8de20fd8656490dd5d6fba7f1f1ed59861a741b0162c0f84_ppc64le
Red Hatopenshift4/ose-local-storage-diskmaker-rhel9@sha256:52617e72dc9a62cad51339dda4bf8dc5ec61bb7e83ff13473f2449f2ff7a0795_ppc64le as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-local-storage-diskmaker-rhel9@sha256:52617e72dc9a62cad51339dda4bf8dc5ec61bb7e83ff13473f2449f2ff7a0795_ppc64le
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel9@sha256:919191702587ae7bae2c0a40a1233ca0770e8837c63b6c0078a5078972ed0c3f_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:919191702587ae7bae2c0a40a1233ca0770e8837c63b6c0078a5078972ed0c3f_arm64, openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:919191702587ae7bae2c0a40a1233ca0770e8837c63b6c0078a5078972ed0c3f_arm64
Red Hatopenshift4/sriov-cni-rhel9@sha256:cdba55a22f6e98f28c8663944cbe016f961263b67da9a12efc0bcde0478614e0_arm64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel9@sha256:1d58bf89582f8e06cf3a61391159301530d37f1bb7fad8f561f4ff17f5848a13_s390x as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:1d58bf89582f8e06cf3a61391159301530d37f1bb7fad8f561f4ff17f5848a13_s390x
Red Hatopenshift4/ose-helm-operator@sha256:b68a1f5e1177081040442a10e1d07b7462a8a7ab6910a91c1d5998704989cf3a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-clusterresourceoverride-rhel9@sha256:36aee2e330570e48b126be5991bba83d0593553ad8a6d9a130137ea54ff23b20_amd64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-clusterresourceoverride-rhel9@sha256:36aee2e330570e48b126be5991bba83d0593553ad8a6d9a130137ea54ff23b20_amd64
Red Hatopenshift4/ose-sriov-dp-admission-controller-rhel9@sha256:7fac56334f68dda1e86a067dd164e39dce06131db7b95f071fd63c73adcce360_ppc64le as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:7fac56334f68dda1e86a067dd164e39dce06131db7b95f071fd63c73adcce360_ppc64le, *
Red Hatopenshift4/frr-rhel9@sha256:a72e7f02410b0af96460881ff259e0591aa044509bb0acf51121fd351ab05121_amd64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/frr-rhel9@sha256:a72e7f02410b0af96460881ff259e0591aa044509bb0acf51121fd351ab05121_amd64, *
Red Hatopenshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:6636261662708587223542c4728ad12cf28ad3a7809ee7547ad8993c67496f7f_arm64 as a component of Red Hat OpenShift Container Platform 4.15*, *
Red Hatopenshift4/ose-cluster-nfd-rhel9-operator@sha256:6f5c5260147d1b014ae681d737f70fd412808dcf55291be22deb357bf1be3dfe_arm64 as a component of Red Hat OpenShift Container Platform 4.15*, openshift4/ose-cluster-nfd-rhel9-operator@sha256:6f5c5260147d1b014ae681d737f70fd412808dcf55291be22deb357bf1be3dfe_arm64
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:bc73a553a43994b13caee507459c19d560dbe52eea4cf31263d404370c79650c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:bc73a553a43994b13caee507459c19d560dbe52eea4cf31263d404370c79650c_ppc64le
Red Hatopenshift4/ose-node-feature-discovery-rhel9@sha256:8186bf3abbba68a7a1d9bd202d19c07f92832c3945c03e20e8d9804b0a9afee6_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-node-feature-discovery-rhel9@sha256:8186bf3abbba68a7a1d9bd202d19c07f92832c3945c03e20e8d9804b0a9afee6_arm64
Red Hatopenshift4/ingress-node-firewall-rhel9-operator@sha256:b5481d778c4033139fc2ca855d852345c8cf5bfa44bfaedc63a50bb5735d4757_s390x as a component of Red Hat OpenShift Container Platform 4.15openshift4/ingress-node-firewall-rhel9-operator@sha256:b5481d778c4033139fc2ca855d852345c8cf5bfa44bfaedc63a50bb5735d4757_s390x
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:8229eb0524e34eb93a5b90296578f86aeeb3210c88e9559f9114ba0469751217_amd64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-operator-sdk-rhel8@sha256:8229eb0524e34eb93a5b90296578f86aeeb3210c88e9559f9114ba0469751217_amd64
Red Hatopenshift4/ingress-node-firewall-rhel9@sha256:021c0c130ad2583ab762a8e77cd0acffd6dbc2ccc5a867c1340c13bfd7712f05_s390x as a component of Red Hat OpenShift Container Platform 4.15openshift4/ingress-node-firewall-rhel9@sha256:021c0c130ad2583ab762a8e77cd0acffd6dbc2ccc5a867c1340c13bfd7712f05_s390x, *

…and 274 more

Timeline

  • Aug 21, 2024 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • May 11, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›