VDB
RHSA-2025%3A1115
RHSA-2025%3A1115
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:3f241a7d4fcc1945f5013c99fa2671affbc6b7ed33a7ec54d8a58308b0925b4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:d49a17a340ae3e8dcbe3cf8973605b32f688f1ee621c63fc81c304102b40cb88_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:7c05604396592132cb376b2d516756021df2f9d5130e273a00cec97bdd28b3f6_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:3ca3b2854e984e6a3dc11e3308b213251b120e4d834826dcbf576e4a4c30a0e9_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:3ca3b2854e984e6a3dc11e3308b213251b120e4d834826dcbf576e4a4c30a0e9_amd64 |
| Red Hat | openshift4/ose-helm-operator@sha256:92695e46c504e388bce5cc434a775d3d27c8e0b6b3aa75f254031e94caf188e5_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-helm-operator@sha256:92695e46c504e388bce5cc434a775d3d27c8e0b6b3aa75f254031e94caf188e5_amd64 |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:7571fc5ecfc2fd9eb668db6550df96f51d56503835cc9ac3326e1ff13154d1f4_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:c3512780f7864f54bbdff9acb24002cd4fee0ee89cb011f8934e7aecf3e5e69c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:ee2d4bfe469c659a648b221aa825bc3f8bc45d7cce71b2ecb12a2e1a5921f8f4_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel8@sha256:cc89fcb58b8a138cc63ce4087066411e296621984871e6a6391abe615e9d8ac5_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cloud-event-proxy-rhel8@sha256:cc89fcb58b8a138cc63ce4087066411e296621984871e6a6391abe615e9d8ac5_amd64 |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:c8df101b5ac51db5682622b168e5d4915f427ebbbc2f96cce0abd6825411c0c0_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| golang | x/net/html | |
| Red Hat | openshift4/sriov-cni-rhel9@sha256:8292554e8f9f6c812e1a7a41e5471d2084a400cf0b8791b70908f4c004d633ee_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-ptp@sha256:2132f1b34ef6df5f517e2fb0ec6c6121503dea095afb561f8e6b8991c7e5c5b6_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:1e03073829cc75bbd9d81c447960238c7cca5cbd3620ab3b63ec423a2f4cc441_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:1e03073829cc75bbd9d81c447960238c7cca5cbd3620ab3b63ec423a2f4cc441_amd64 |
| Red Hat | openshift4/ose-ptp-operator@sha256:8d3f3f110211e71391bb7247e58e43ec6123c82acf4407a900e07b2099d42a49_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-cluster-capacity@sha256:b970c483860f95d0b7cdaaac6f2838eea1116278973e8f5d94681ea90195ce43_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-cluster-capacity@sha256:b970c483860f95d0b7cdaaac6f2838eea1116278973e8f5d94681ea90195ce43_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-local-storage-mustgather-rhel8@sha256:e73398ac6757af56d44b6c43aa4117b34052762cafce556d1bc8678c8b29f386_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/frr-rhel8@sha256:6ec87c121aff11ffb5bd815866dbcce9d1c47a6a4eef208156c3d7a7851105d4_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
…and 66 more
Timeline
- Feb 13, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:1115 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1115.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory