VDB
RHSA-2024%3A6642
RHSA-2024%3A6642
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-operator-lifecycle-manager@sha256:cb4efecbaf76a57fb4241d6f21d901b14d34ea906cc516c30a72c89af2920161_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-configmap-reloader@sha256:3a12ee6f195beda1df4935975d99ac1e89e7e2f9fbb420f692a4d3905d366cec_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-configmap-reloader@sha256:3a12ee6f195beda1df4935975d99ac1e89e7e2f9fbb420f692a4d3905d366cec_amd64 |
| Red Hat | openshift4/ose-openstack-machine-controllers@sha256:8544d77a5fa23a3e35bf9268770e9f04301e315679da4eb653981cb735f77ee6_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-installer-artifacts@sha256:980b104484f8051771b044a8c113ad650b913e76cce9b46b70530b97cabb70d0_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-ovirt-machine-controllers-rhel8@sha256:6c17ce3003003c185522efc4a743def558c3c15aba0fc29935517047077b3a92_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-multus-admission-controller@sha256:51ff8affafca359ce034951b69e000340e5c30c2b47d4c33c266c5e34d17a23f_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-hypershift-rhel8@sha256:6c238c6ac73cbb6ea46b8004ce8a5422cd1492aaeb49466149e19231c2321561_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:dafa0671c04a22bf73d07371b7812d1f6d8ebe98b6f752f44191fd1292921e9e_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-policy-controller-rhel8@sha256:bdfec527aff0de2032adc126c901c3032e3e16615c83b1866d38553a2b17d86c_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-policy-controller-rhel8@sha256:bdfec527aff0de2032adc126c901c3032e3e16615c83b1866d38553a2b17d86c_amd64 |
| Red Hat | openshift4/ose-docker-builder@sha256:51f33c5eaf725a04c0101dd6832435ad89af6978aaf106b9582cd49a6f67c9de_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-csi-external-snapshotter-rhel8@sha256:6ef73292143f820794713387c0f86b0aa337b3fc5a8ea4ed19108710f40058ea_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-csi-external-snapshotter-rhel8@sha256:6ef73292143f820794713387c0f86b0aa337b3fc5a8ea4ed19108710f40058ea_amd64 |
| Red Hat | openshift4/ose-baremetal-machine-controllers@sha256:2f2ee0d0be2362b8784ddde4671fa22844dee825dfd09446c3a8635154098aa0_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:61afbe6000e93292a61867afe8360db29f65cdd14668ac568c4202de66b5eef2_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-platform-operators-manager-rhel8@sha256:3358e192f4faed6d16d17d56e51804b8981960d164751aa002dea8b8b3f267af_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-agent-installer-csr-approver-rhel8@sha256:2b50cf0748eb52191896942fdd4b0fb741b12b4538d2316d216d58edd9c43889_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-agent-installer-csr-approver-rhel8@sha256:2b50cf0748eb52191896942fdd4b0fb741b12b4538d2316d216d58edd9c43889_amd64 |
| Red Hat | openshift4/ose-powervs-block-csi-driver-rhel8@sha256:77b7da85d35f7e730b66c9ad57f7da0a5061517dcafba87eab4990e1d578f559_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-webhook-rhel8@sha256:588d501a8d85c326148fb43315d7f64d120b2cd78dd0174a95664a239ad17e21_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-csi-driver-shared-resource-webhook-rhel8@sha256:588d501a8d85c326148fb43315d7f64d120b2cd78dd0174a95664a239ad17e21_amd64 |
| Red Hat | openshift4/ose-csi-external-attacher-rhel8@sha256:47dd87319599d15be766c8a3857332fcb1b97934a53cdc0cb5b1c616a24b42a6_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:aa3f83e807d337027160621918882293e3d13e74d3ee1d8b372c89bf7eca4f58_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:aa3f83e807d337027160621918882293e3d13e74d3ee1d8b372c89bf7eca4f58_s390x |
| Red Hat | openshift4/ose-image-customization-controller-rhel8@sha256:14474dc55e9cc6c80ff7c880559fb82b12270f0deb67318063107a97bdf8e78e_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
…and 605 more
Timeline
- Sep 18, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2298893 issue
- https://issues.redhat.com/browse/OCPBUGS-38905 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6642.json advisory
- https://www.cve.org/CVERecord?id=CVE-2023-45288 advisory
- https://access.redhat.com/security/cve/CVE-2024-1737 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-1737 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-1737 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-1975 advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://access.redhat.com/errata/RHSA-2024:6642 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298901 issue
- https://access.redhat.com/security/cve/CVE-2023-45288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45288 advisory
- https://nowotarski.info/http2-continuation-flood/ advisory
- https://pkg.go.dev/vuln/GO-2024-2687 advisory
- https://www.kb.cert.org/vuls/id/421644 advisory
- https://access.redhat.com/security/cve/CVE-2024-1975 advisory
…and 3 more