VDB
RHSA-2025%3A0827
RHSA-2025%3A0827
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/nmstate-console-plugin-rhel9@sha256:a0e0418990060dcc8810108e6e83eb2819748006a021b361475b22296482c549_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel9@sha256:b14acb60d5dbaaf1d4ca25b5b8805e4d70d721a8cbd8c9632c74937ab9e32b3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-egress-http-proxy-rhel9@sha256:8fd384dd5f8c211ae237eb7b1d664ab222e43a3f8de0c8fa96dd8644b95fb3ea_s390x as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-sriov-infiniband-cni-rhel9@sha256:58386f2a777b2c8cd8de4e406fa2fc3d9dfa496106a4e703123aa833ca63963e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:36e2cc7f6dbd0fa6db6cf1e19a9b28b67467b44e276d7c9e0802a642b0f5d80d_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:36e2cc7f6dbd0fa6db6cf1e19a9b28b67467b44e276d7c9e0802a642b0f5d80d_arm64 |
| Red Hat | openshift4/ingress-node-firewall-rhel9-operator@sha256:89f4baf71eda8bae1326c3df8efe471d84261c97102f61a308ff48049a112681_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel9@sha256:7f81a6fc88f56b35d7f3012f1dfa0f03459958229cdaebb322804d9adb34ad6b_s390x as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-dpu-daemon-rhel9@sha256:a89804cfc359ac32c80b373ff9ea16a74c588c4c3bfd3ae27f81aec45d1e5d39_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-dpu-daemon-rhel9@sha256:a89804cfc359ac32c80b373ff9ea16a74c588c4c3bfd3ae27f81aec45d1e5d39_s390x |
| Red Hat | openshift4/ose-helm-rhel9-operator@sha256:7c1eb934c0548b32d77914ab3dd459c07680fb43a73f08edb07692beee65a7e5_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:4b99cc109950ca26530fbfcdf6ac6cf2b56ffd9ce99175e55ac2f9fc30b50779_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:8897cbb490b5bde96717357accbb7039195452fd7c7d47ef3590efb6df552120_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-sriov-network-config-daemon-rhel9@sha256:b5106ea853080694fee3025e56b3126bbd11924971dedd66cabeae9ff314900a_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel9@sha256:cbfd246cd91125e0c94227c7aee42494c02deb04d652c6b3d16513b89728dc0c_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-gcp-filestore-csi-driver-rhel9@sha256:cbfd246cd91125e0c94227c7aee42494c02deb04d652c6b3d16513b89728dc0c_amd64 |
| Red Hat | openshift4/ingress-node-firewall-rhel9@sha256:2a161b3f221852a5c761d522d62c16dba53cd94a6a17dd8674efc7e131bfed05_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-smb-csi-driver-rhel9@sha256:2c96c85016f8eab067bfc5e0cdfbc1afaa130fa11fc1e3582e3d946c21acedf8_s390x as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel9@sha256:722ad5a4e8ef4acf598d46c4db67de2543d159a59ced93c94b5ea67d9721921c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-egress-dns-proxy-rhel9@sha256:2730f1d12257751b420ee305ac4be1d395aaa7136e817eddab9107e2fef4d084_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-egress-dns-proxy-rhel9@sha256:2730f1d12257751b420ee305ac4be1d395aaa7136e817eddab9107e2fef4d084_amd64 |
| Red Hat | openshift4/ose-sriov-infiniband-cni-rhel9@sha256:9cc733f46c7f107f6a2d730da58771edf4b9f3585f86e772994d4a3e1534ad1f_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:c2f0512afd2fd044750f4550be2b87b99f081a84a9771c13fa28a88e1f4aea8e_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:c2f0512afd2fd044750f4550be2b87b99f081a84a9771c13fa28a88e1f4aea8e_arm64 |
| Red Hat | openshift4/ose-dpu-cni-rhel9@sha256:4a1d577d4dc5dd9cd14352fc3f02164f37a6019c97a90b83636bd654c74604ff_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
…and 345 more
Timeline
- Feb 6, 2025 CVE Published
- May 15, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
- Jul 19, 2026 Distribution Patch
- Jul 19, 2026 Distribution Patch
- Jul 19, 2026 Security Advisory
References
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/issue/70906 advisory
- https://access.redhat.com/errata/RHSA-2025:0827 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0827.json advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory