VDB
RHSA-2024:1538
RHSA-2024:1538
PUBLISHED
CVSS 5.900000095367432 MEDIUM
A flaw was found in Golang's protobuf module, where the unmarshal function can enter an infinite loop when processing certain invalid inputs. This issue occurs during unmarshaling into a message that includes a google.protobuf.Any or when the UnmarshalOptions.DiscardUnknown option is enabled. This flaw allows an attacker to craft malicious input tailored to trigger the identified flaw in the unmarshal function. By providing carefully constructed invalid inputs, they could potentially cause the function to enter an infinite loop, resulting in a denial of service condition or other unintended behaviors in the affected system.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/numaresources-rhel8-operator@sha256:9c0cecdb9c9b7fe7a68d32eecd0340e91e7591462e9f55dc5c5841b0de7cae16_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/numaresources-rhel8-operator@sha256:9c0cecdb9c9b7fe7a68d32eecd0340e91e7591462e9f55dc5c5841b0de7cae16_amd64, openshift4/numaresources-rhel8-operator@sha256:9c0cecdb9c9b7fe7a68d32eecd0340e91e7591462e9f55dc5c5841b0de7cae16_amd64 |
| Red Hat | openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64, * |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:afa8c39b03e4a1a42d2e0302d6a19d87c7158dab127fb25e2f2da41d5c96d066_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/dpdk-base-rhel8@sha256:afa8c39b03e4a1a42d2e0302d6a19d87c7158dab127fb25e2f2da41d5c96d066_amd64, openshift4/dpdk-base-rhel8@sha256:afa8c39b03e4a1a42d2e0302d6a19d87c7158dab127fb25e2f2da41d5c96d066_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:d50a87f4b8bb430065aa2be56a3391bc20e94ce5a622d029d3f34316dc0cdeec_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/numaresources-operator-bundle@sha256:d50a87f4b8bb430065aa2be56a3391bc20e94ce5a622d029d3f34316dc0cdeec_amd64, openshift4/numaresources-operator-bundle@sha256:d50a87f4b8bb430065aa2be56a3391bc20e94ce5a622d029d3f34316dc0cdeec_amd64, * |
| Red Hat | openshift4/numaresources-rhel8-operator@sha256:9c0cecdb9c9b7fe7a68d32eecd0340e91e7591462e9f55dc5c5841b0de7cae16_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/dpdk-base-rhel8@sha256:afa8c39b03e4a1a42d2e0302d6a19d87c7158dab127fb25e2f2da41d5c96d066_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/dpdk-base-rhel8@sha256:afa8c39b03e4a1a42d2e0302d6a19d87c7158dab127fb25e2f2da41d5c96d066_amd64 |
| Red Hat | openshift4/performance-addon-operator-must-gather-rhel8@sha256:4348aab82a7055fdb42454b74e9ef8a6b46ddb93c45c8f4a7b38ec24f054ad2f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/performance-addon-operator-must-gather-rhel8@sha256:4348aab82a7055fdb42454b74e9ef8a6b46ddb93c45c8f4a7b38ec24f054ad2f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/performance-addon-operator-must-gather-rhel8@sha256:4348aab82a7055fdb42454b74e9ef8a6b46ddb93c45c8f4a7b38ec24f054ad2f_amd64, openshift4/performance-addon-operator-must-gather-rhel8@sha256:4348aab82a7055fdb42454b74e9ef8a6b46ddb93c45c8f4a7b38ec24f054ad2f_amd64, openshift4/performance-addon-operator-must-gather-rhel8@sha256:4348aab82a7055fdb42454b74e9ef8a6b46ddb93c45c8f4a7b38ec24f054ad2f_amd64 |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:45ea2c0408804e55d7368805547810532c141ac614a410ed445624814003fd45_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/cnf-tests-rhel8@sha256:45ea2c0408804e55d7368805547810532c141ac614a410ed445624814003fd45_amd64, *, * |
| Red Hat | openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64, openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64 |
| Red Hat | openshift4/numaresources-operator-bundle@sha256:d50a87f4b8bb430065aa2be56a3391bc20e94ce5a622d029d3f34316dc0cdeec_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/numaresources-operator-bundle@sha256:d50a87f4b8bb430065aa2be56a3391bc20e94ce5a622d029d3f34316dc0cdeec_amd64, *, * |
| Red Hat | openshift4/cnf-tests-rhel8@sha256:45ea2c0408804e55d7368805547810532c141ac614a410ed445624814003fd45_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/cnf-tests-rhel8@sha256:45ea2c0408804e55d7368805547810532c141ac614a410ed445624814003fd45_amd64, *, * |
Timeline
- Mar 27, 2024 CVE Published
- May 2, 2026 Distribution Patch
- May 2, 2026 Security Advisory
- May 7, 2026 Distribution Patch
- May 16, 2026 CVE Updated
- May 16, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2268046 issue
- https://www.cve.org/CVERecord?id=CVE-2024-24786 advisory
- https://access.redhat.com/errata/RHSA-2024:1538 advisory
- https://access.redhat.com/security/cve/cve-2024-24786 advisory
- https://access.redhat.com/security/cve/CVE-2024-24786 advisory
- https://pkg.go.dev/vuln/GO-2024-2611 advisory
- https://go.dev/cl/569356 advisory
- https://groups.google.com/g/golang-announce/c/ArQ6CDgtEjY/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1538.json advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-24786 advisory