VDB
RHSA-2024%3A8692
RHSA-2024%3A8692
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the go/build/constraint package of the Golang standard library. Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ovirt-csi-driver-rhel7@sha256:106f79490fe6b6a898d4144353624d8d104ace1cec0062275562e5eb8b0d4e7c_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ovirt-csi-driver-rhel7@sha256:106f79490fe6b6a898d4144353624d8d104ace1cec0062275562e5eb8b0d4e7c_s390x |
| Red Hat | openshift4/ose-cluster-autoscaler@sha256:bbcaa6d86df50655867b21f93d06d3982c042a72406db3ad086b7a4efd441c6e_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-autoscaler@sha256:bbcaa6d86df50655867b21f93d06d3982c042a72406db3ad086b7a4efd441c6e_amd64 |
| Red Hat | openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:244fb8e236d3a5676629d6fd55d3a28485ad6a78329b4583368b75f7bc3fcf9d_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:244fb8e236d3a5676629d6fd55d3a28485ad6a78329b4583368b75f7bc3fcf9d_amd64 |
| Red Hat | openshift4/ose-csi-node-driver-registrar@sha256:ecc62250db8976ea48a7183411ac80b69a5b7effa5aeda70ec799c2e560a58e7_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-image-registry-operator@sha256:66882ec66af95f11fbd0369858bf388ca2ace0c4e25f3bd03f96b5e2bf98e910_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-image-registry-operator@sha256:66882ec66af95f11fbd0369858bf388ca2ace0c4e25f3bd03f96b5e2bf98e910_amd64 |
| Red Hat | openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:a7ce29746e7aad24b5193cc180b419103dc6d5172d9b8e6ddd4084859fe1be6d_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:a7ce29746e7aad24b5193cc180b419103dc6d5172d9b8e6ddd4084859fe1be6d_amd64 |
| Red Hat | openshift4/ose-cluster-policy-controller-rhel8@sha256:c64670832b4474af31c81f25a3b405a68766e914575fcb0e566290507120864b_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-policy-controller-rhel8@sha256:c64670832b4474af31c81f25a3b405a68766e914575fcb0e566290507120864b_s390x |
| Red Hat | openshift4/ose-openshift-state-metrics-rhel8@sha256:9fe4fd361c18acd871d9dbe9229c967c2ca7eda6570f5d7ecef67bb247f708d5_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-csi-driver-manila-rhel8@sha256:6bfa01f37b95c5515f3a44979619cc8d033d9f48cf4462172618eaf0dd46db41_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-csi-driver-manila-rhel8@sha256:6bfa01f37b95c5515f3a44979619cc8d033d9f48cf4462172618eaf0dd46db41_amd64 |
| Red Hat | openshift4/ose-agent-installer-orchestrator-rhel8@sha256:8e551cd846b2526582f5dead01d06d89b39e69b4c26b478d16b5c1d391d645ef_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-agent-installer-orchestrator-rhel8@sha256:8e551cd846b2526582f5dead01d06d89b39e69b4c26b478d16b5c1d391d645ef_s390x |
| Red Hat | openshift4/ose-container-networking-plugins-rhel8@sha256:e529ef5698d58bec9963743ec0181e80189ce131e916b7a633cbb511c8930682_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-container-networking-plugins-rhel8@sha256:e529ef5698d58bec9963743ec0181e80189ce131e916b7a633cbb511c8930682_s390x |
| Red Hat | openshift4/ose-vmware-vsphere-csi-driver-rhel8@sha256:1f40741ae1627317725648712a44cd6d8ea7f95d478285f9cd90ec130656c44e_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-vmware-vsphere-csi-driver-rhel8@sha256:1f40741ae1627317725648712a44cd6d8ea7f95d478285f9cd90ec130656c44e_amd64 |
| Red Hat | openshift4/ose-vsphere-csi-driver-rhel8@sha256:1f40741ae1627317725648712a44cd6d8ea7f95d478285f9cd90ec130656c44e_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-installer@sha256:fd0d3abf143de9b34923673accfdbf5651a25167ccc86efa002ddf13bd74f199_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-csi-livenessprobe-rhel8@sha256:01a30e0cc48d9edf23d8bef3ca3c776f37ec01e326d3f3f151cbea3f52f81860_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-csi-livenessprobe-rhel8@sha256:01a30e0cc48d9edf23d8bef3ca3c776f37ec01e326d3f3f151cbea3f52f81860_amd64 |
| Red Hat | openshift4/ose-cluster-ingress-operator@sha256:60b5bb74e655dc9c193be12116ed0fe35d1086d213da73829e01548ad2e0f70e_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-ingress-operator@sha256:60b5bb74e655dc9c193be12116ed0fe35d1086d213da73829e01548ad2e0f70e_s390x |
| Red Hat | openshift4/ose-hyperkube@sha256:539db85e12e1dcbcd3826aa24a269fb60f111f103046b2e3bba4e09d0965b244_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-hyperkube@sha256:539db85e12e1dcbcd3826aa24a269fb60f111f103046b2e3bba4e09d0965b244_amd64 |
| Red Hat | openshift4/ose-oauth-proxy@sha256:ab178653855f4e19962bb202ed14c0727b281ef74dc92e3e9b3d3872cd8c7483_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-oauth-proxy@sha256:ab178653855f4e19962bb202ed14c0727b281ef74dc92e3e9b3d3872cd8c7483_s390x |
| Red Hat | openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:e046e23c1c2807cab43120f2f6fdb1fa635e89289256c0a8e7252821c89a70ef_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-capi-rhel8-operator@sha256:fbe68a2e98f3f271d116d8ad6f63a1c365afae84a17cefed4876d3d89534d401_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-capi-rhel8-operator@sha256:fbe68a2e98f3f271d116d8ad6f63a1c365afae84a17cefed4876d3d89534d401_amd64 |
…and 310 more
Timeline
- Nov 7, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:8692 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2295310 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2310527 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2310528 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2310529 issue
- https://issues.redhat.com/browse/OCPBUGS-25783 advisory
- https://issues.redhat.com/browse/OCPBUGS-33519 advisory
- https://issues.redhat.com/browse/OCPBUGS-37322 advisory
- https://issues.redhat.com/browse/OCPBUGS-38382 advisory
- https://issues.redhat.com/browse/OCPBUGS-41248 advisory
- https://issues.redhat.com/browse/OCPBUGS-43703 advisory
- https://issues.redhat.com/browse/OCPBUGS-43872 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8692.json advisory
- https://access.redhat.com/security/cve/CVE-2023-45288 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-45288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45288 advisory
- https://nowotarski.info/http2-continuation-flood/ advisory
- https://pkg.go.dev/vuln/GO-2024-2687 advisory
…and 26 more