VDB
RHSA-2025%3A0771
RHSA-2025%3A0771
PUBLISHED
CVSS 5.900000095367432 MEDIUM
A flaw was found in the go/parser package of the Golang standard library. Calling any Parse functions on Go source code containing deeply nested literals can cause a panic due to stack exhaustion.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel9@sha256:2ec06aa6fef877f580ae4be39a56a2da94cd12e1b0eb615e3cbb7056682cbc19_arm64 as a component of 9Base-OADP-1.4 | oadp/oadp-velero-restic-restore-helper-rhel9@sha256:2ec06aa6fef877f580ae4be39a56a2da94cd12e1b0eb615e3cbb7056682cbc19_arm64 |
| Red Hat | oadp/oadp-rhel9-operator@sha256:42f26f43662ad9b36be9d0a71410f5132e13bcbd633b854f0025144b7668a8d0_arm64 as a component of 9Base-OADP-1.4 | oadp/oadp-rhel9-operator@sha256:42f26f43662ad9b36be9d0a71410f5132e13bcbd633b854f0025144b7668a8d0_arm64 |
| Red Hat | oadp/oadp-rhel9-operator@sha256:d892e4081236357a3d77722eee8183dde22d67549ba2abddb8ed1ffebaaa27b1_amd64 as a component of 9Base-OADP-1.4 | oadp/oadp-rhel9-operator@sha256:d892e4081236357a3d77722eee8183dde22d67549ba2abddb8ed1ffebaaa27b1_amd64 |
| Red Hat | oadp/oadp-rhel9-operator@sha256:1cd7a7e2c6c74c405cf08a442257e406ecb14ad54eec3c435de2b57a9493c196_s390x as a component of 9Base-OADP-1.4 | oadp/oadp-rhel9-operator@sha256:1cd7a7e2c6c74c405cf08a442257e406ecb14ad54eec3c435de2b57a9493c196_s390x |
| Red Hat | oadp/oadp-velero-rhel9@sha256:16152f1958c39b2f7796f381acb27927096f33ac1a7202219d4da019b188c9ef_ppc64le as a component of 9Base-OADP-1.4 | * |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:446ccce4d7e6bf9746bf3d2227b63f43641dafc2283c2778ab24934357f6f260_s390x as a component of 9Base-OADP-1.4 | oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:446ccce4d7e6bf9746bf3d2227b63f43641dafc2283c2778ab24934357f6f260_s390x |
| Red Hat | oadp/oadp-operator-bundle@sha256:529880c06d04df8943146b6054733098d6f49049f71c65cb8bb5b90481dc8ec7_arm64 as a component of 9Base-OADP-1.4 | oadp/oadp-operator-bundle@sha256:529880c06d04df8943146b6054733098d6f49049f71c65cb8bb5b90481dc8ec7_arm64 |
| Red Hat | oadp/oadp-velero-plugin-rhel9@sha256:a19dfd7d025ea46540213c42383d28ad90a2fb87e478293bdf4bd06c2631c2be_arm64 as a component of 9Base-OADP-1.4 | oadp/oadp-velero-plugin-rhel9@sha256:a19dfd7d025ea46540213c42383d28ad90a2fb87e478293bdf4bd06c2631c2be_arm64 |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel9@sha256:77c004f3326e7ca629ab4d5de51c36e4fe909c6dede867b69b90011ea5bcb01c_s390x as a component of 9Base-OADP-1.4 | oadp/oadp-velero-restic-restore-helper-rhel9@sha256:77c004f3326e7ca629ab4d5de51c36e4fe909c6dede867b69b90011ea5bcb01c_s390x |
| Red Hat | oadp/oadp-velero-plugin-for-aws-rhel9@sha256:98c4abc2b0d3c4c60ca868c88c93b2ee5e8da275a273cd9b2e353d02a15f2128_ppc64le as a component of 9Base-OADP-1.4 | oadp/oadp-velero-plugin-for-aws-rhel9@sha256:98c4abc2b0d3c4c60ca868c88c93b2ee5e8da275a273cd9b2e353d02a15f2128_ppc64le |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel9@sha256:cbf501256a8f4252cc830f259722094c0a81ed2806507b2e92d0442e0c502f4b_ppc64le as a component of 9Base-OADP-1.4 | * |
| Red Hat | oadp/oadp-mustgather-rhel9@sha256:0292bec8929b93cedd56e9b1a3889ca631bd094eb76619ce07c0fa784c149457_arm64 as a component of 9Base-OADP-1.4 | oadp/oadp-mustgather-rhel9@sha256:0292bec8929b93cedd56e9b1a3889ca631bd094eb76619ce07c0fa784c149457_arm64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:f97bad0f9da6a369d85ef5f47c20a6e543426031229957495ed8223ed5e1feaa_ppc64le as a component of 9Base-OADP-1.4 | oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:f97bad0f9da6a369d85ef5f47c20a6e543426031229957495ed8223ed5e1feaa_ppc64le |
| Red Hat | oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:62730230ae5edb7584ba66e3ac1c9745cb5b890c8c740006e69a657725590c4a_amd64 as a component of 9Base-OADP-1.4 | * |
| Red Hat | oadp/oadp-mustgather-rhel9@sha256:551271874902237ac31f43fc0f52d5e30a58ed7b4380f6880f72c112424a322d_s390x as a component of 9Base-OADP-1.4 | oadp/oadp-mustgather-rhel9@sha256:551271874902237ac31f43fc0f52d5e30a58ed7b4380f6880f72c112424a322d_s390x |
| Red Hat | oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:48437e2a84201ddca777297db29a6e2ef9cb39ced750b1abbaa3180cc02ba04b_amd64 as a component of 9Base-OADP-1.4 | oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:48437e2a84201ddca777297db29a6e2ef9cb39ced750b1abbaa3180cc02ba04b_amd64 |
| Red Hat | oadp/oadp-velero-plugin-rhel9@sha256:567a2dafe906090b5e6d6b0ae69419cf5826ab2ebefd3d4253bac42ebc940655_amd64 as a component of 9Base-OADP-1.4 | oadp/oadp-velero-plugin-rhel9@sha256:567a2dafe906090b5e6d6b0ae69419cf5826ab2ebefd3d4253bac42ebc940655_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:623bd5b25e7d0d57cd4bca080fc87aa6f4c1491064f05b34463cdd42be4e44e7_ppc64le as a component of 9Base-OADP-1.4 | oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:623bd5b25e7d0d57cd4bca080fc87aa6f4c1491064f05b34463cdd42be4e44e7_ppc64le |
| Red Hat | oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:b08bd4365b5ee4f24ee1d192f73d4d1a70440d10adf59a10bfc4214fbeebfe9d_s390x as a component of 9Base-OADP-1.4 | * |
| Red Hat | oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:1e5da2e733d5b9bf9a9407821721f9e99190f95e22e1f4fff3f11b6ab0a0f29a_ppc64le as a component of 9Base-OADP-1.4 | oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:1e5da2e733d5b9bf9a9407821721f9e99190f95e22e1f4fff3f11b6ab0a0f29a_ppc64le |
…and 24 more
Timeline
- Jan 28, 2025 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://go.dev/cl/611240 advisory
- https://go.dev/issue/69141 advisory
- https://pkg.go.dev/vuln/GO-2024-3107 advisory
- https://access.redhat.com/errata/RHSA-2025:0771 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2310527 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2310528 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2310529 issue
- https://issues.redhat.com/browse/OADP-4995 advisory
- https://issues.redhat.com/browse/OADP-5044 advisory
- https://issues.redhat.com/browse/OADP-5095 advisory
- https://issues.redhat.com/browse/OADP-5362 advisory
- https://issues.redhat.com/browse/OADP-5388 advisory
- https://issues.redhat.com/browse/OADP-5460 advisory
- https://issues.redhat.com/browse/OADP-5470 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0771.json advisory
- https://access.redhat.com/security/cve/CVE-2024-34155 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-34155 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-34155 advisory
- https://go.dev/cl/611238 advisory
…and 12 more