VDB
RHSA-2025%3A1013
RHSA-2025%3A1013
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/submariner-route-agent-rhel9@sha256:5f1c0fc0fafb9d56327005cf4f56a48cbdb20c7dc7c2b525a1296de2bbc09f5b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/submariner-rhel9-operator@sha256:36b939dcc477d9ce9b031e26a0500531945f8efdc609b243706ea15dab531bfd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/submariner-rhel9-operator@sha256:36b939dcc477d9ce9b031e26a0500531945f8efdc609b243706ea15dab531bfd_ppc64le |
| Red Hat | rhacm2/submariner-gateway-rhel9@sha256:7b0ea1b68e1fdf8c41854c0db603b8a3e785b61841d54d3fb1fdc07085a5d6f2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/submariner-gateway-rhel9@sha256:7b0ea1b68e1fdf8c41854c0db603b8a3e785b61841d54d3fb1fdc07085a5d6f2_ppc64le |
| Red Hat | rhacm2/nettest-rhel9@sha256:8bc733639b7db3bb5953c2062ef04009c19cefd989dddc991cdfdba978429f47_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | * |
| Red Hat | rhacm2/lighthouse-agent-rhel9@sha256:dbd3d37afbfb3d1cb9b8012fd952dfeadcd84b7c3f1f5516a8ee1651f4a1be7b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/submariner-operator-bundle@sha256:40fbb1774a82a375cf2522664e18f07821dc8cf315f323660856d0c1eea1b86e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/lighthouse-agent-rhel9@sha256:fc07e35dbff3e5d3ce44b467a69fd42663cb36f7d7946a5e669f6209b7aabbc7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | * |
| Red Hat | rhacm2/lighthouse-coredns-rhel9@sha256:0d83e02fde05674b80703d270e6f480bab7f91871e120a1655bbbd44d28cf701_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/submariner-operator-bundle@sha256:cd21fbb3aaae42d06922328ff6aae30b08b7080c91d33083bed8141072e5998c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/nettest-rhel9@sha256:2198b883205d6dfc1f8f709d00d5edade7cd7a9cacbbb1d3a53ebacaa9e8992e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/nettest-rhel9@sha256:c8871afe59b9786761374b468480b041926af3a40eb88864522b48a49fec0e8c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/nettest-rhel9@sha256:c8871afe59b9786761374b468480b041926af3a40eb88864522b48a49fec0e8c_ppc64le |
| Red Hat | rhacm2/lighthouse-coredns-rhel9@sha256:8fc57758a5df8894f78185e7b6245cb59169733db2f0398fb6aec18e4d93f4e3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/submariner-globalnet-rhel9@sha256:22dc450db507f683f14d00bd60b55ebdf03b6b42db5bc1598abdb0da0a644ca2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/submariner-globalnet-rhel9@sha256:22dc450db507f683f14d00bd60b55ebdf03b6b42db5bc1598abdb0da0a644ca2_arm64 |
| Red Hat | rhacm2/submariner-route-agent-rhel9@sha256:9d41e54fbe7cbe55a90f274539506305620475e3ca422fcb7a4684112e5212b0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/submariner-globalnet-rhel9@sha256:6f6ec8006b4853079b3309d1a2f96fb8db1f3c3b5f6d292d9e19bd61ea4776c2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/submariner-globalnet-rhel9@sha256:6f6ec8006b4853079b3309d1a2f96fb8db1f3c3b5f6d292d9e19bd61ea4776c2_ppc64le |
| Red Hat | rhacm2/submariner-gateway-rhel9@sha256:f98c24056f4d6620e3b612545677a14e0d9ad06eb62d3e58e6cc8ca4927e24c6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/submariner-gateway-rhel9@sha256:f98c24056f4d6620e3b612545677a14e0d9ad06eb62d3e58e6cc8ca4927e24c6_arm64 |
| Red Hat | rhacm2/submariner-route-agent-rhel9@sha256:9d41e54fbe7cbe55a90f274539506305620475e3ca422fcb7a4684112e5212b0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | rhacm2/submariner-route-agent-rhel9@sha256:9d41e54fbe7cbe55a90f274539506305620475e3ca422fcb7a4684112e5212b0_arm64 |
| Red Hat | rhacm2/submariner-globalnet-rhel9@sha256:6f6ec8006b4853079b3309d1a2f96fb8db1f3c3b5f6d292d9e19bd61ea4776c2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
| Red Hat | rhacm2/submariner-operator-bundle@sha256:ec914abfb54de7dd60aa90f45898c0d5c1c8fa55ca86d502e12e6d000d8e5d2a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | *, *, * |
…and 55 more
Timeline
- Feb 4, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:1013 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1013.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory