VDB
RHSA-2025%3A1386
RHSA-2025%3A1386
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-cluster-monitoring-rhel9-operator@sha256:4864f540a76aa387e87d5e6ec4910e50bbecac2636f6b48f40d93cbf97b0fc24_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-cluster-monitoring-rhel9-operator@sha256:4864f540a76aa387e87d5e6ec4910e50bbecac2636f6b48f40d93cbf97b0fc24_s390x |
| Red Hat | openshift4/ose-cluster-api-rhel9@sha256:95a4bcf3f40498c9e09488e7afe437ccd23d9eea5dd1c01a68df5fcb50748407_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-oauth-proxy-rhel9@sha256:a6e05f3533cf1560445dbecee416d296f3f43b74009e846f4f78da7c3ef0e56f_s390x as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ovirt-csi-driver-rhel9-operator@sha256:e0c80997e14bfc7464ed4a078f2a8937d9ab49540169837b5985eb65f38c427c_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-oauth-server-rhel9@sha256:7c2cbd91675bdaec218009af8d2524c23067812ee95fec2f0b41a609e5395808_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-kube-state-metrics-rhel9@sha256:f15b5ceb89ce272fab075d350a67bf2eecbb684e90e3e3f653b86412cc1102c1_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-kube-state-metrics-rhel9@sha256:f15b5ceb89ce272fab075d350a67bf2eecbb684e90e3e3f653b86412cc1102c1_s390x |
| Red Hat | openshift4/driver-toolkit-rhel9@sha256:fed2a25ba02c459deebc96e984cdac9ec958b82bb4ed0600d6305d19b6e145f6_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/driver-toolkit-rhel9@sha256:fed2a25ba02c459deebc96e984cdac9ec958b82bb4ed0600d6305d19b6e145f6_s390x |
| Red Hat | openshift4/ose-multus-admission-controller-rhel9@sha256:30cbf8eda5c3471562280e72c181c2baeed1f7c2ec04e69acacf01c0f2d415bf_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-multus-whereabouts-ipam-cni-rhel9@sha256:1a0d890240cc09ecdd6aa3001a7ee11150ad5423a0266ff66e5c400d84402367_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-multus-whereabouts-ipam-cni-rhel9@sha256:1a0d890240cc09ecdd6aa3001a7ee11150ad5423a0266ff66e5c400d84402367_amd64 |
| Red Hat | openshift4/ose-openstack-cinder-csi-driver-rhel9@sha256:66a36e0455d55fad08733524173c02705da0ea9861c7697509f482e170bbe6a1_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-openstack-cinder-csi-driver-rhel9@sha256:66a36e0455d55fad08733524173c02705da0ea9861c7697509f482e170bbe6a1_amd64 |
| Red Hat | openshift4/ose-baremetal-installer-rhel9@sha256:a6415c029a79aa5d131fc5f234546b41c7b3ce52e562e7f1ec180119e1c06cf8_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-baremetal-installer-rhel9@sha256:a6415c029a79aa5d131fc5f234546b41c7b3ce52e562e7f1ec180119e1c06cf8_amd64 |
| Red Hat | openshift4/ose-ironic-agent-rhel9@sha256:f173c21837380f31fbb2a74ecda1bb5966cbc66d2f5bf9d167e07c1a95cdd0a0_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/oc-mirror-plugin-rhel9@sha256:c480831db8a52b8b1481fc4c91fc19643b90298a9369fc90d8715aa0404eb631_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/oc-mirror-plugin-rhel9@sha256:c480831db8a52b8b1481fc4c91fc19643b90298a9369fc90d8715aa0404eb631_amd64 |
| Red Hat | openshift4/ose-service-ca-rhel9-operator@sha256:bda8012932c32e53c861fbe3fae5bcb64f38912ccaa30ea53b10423d8af32b95_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-service-ca-rhel9-operator@sha256:bda8012932c32e53c861fbe3fae5bcb64f38912ccaa30ea53b10423d8af32b95_ppc64le |
| Red Hat | openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:fae11dc2583285a9ac86ab8a286dd0ca8a2d551f8cd4a754310692f00d6858aa_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:fae11dc2583285a9ac86ab8a286dd0ca8a2d551f8cd4a754310692f00d6858aa_amd64 |
| Red Hat | openshift4/openshift-route-controller-manager-rhel9@sha256:f6131fe9b291feb670acd92a97c975a689f65942b11072379533a355a8edb635_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-csi-livenessprobe-rhel9@sha256:d257fc807e0b7c3aa54dff3b619971f3264b4fc524c3652b99bfe4af9edf0636_s390x as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-console-rhel9-operator@sha256:7f3e40eb1dab4bad463d1e8aa4ac1ac69af6695a13c0d0a53508e2d092d0f05c_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-rhel9@sha256:2051f12d187a5b4092a142f996776ce54a990e0c4b47ee137ea5fd7246253f05_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-csi-driver-shared-resource-rhel9@sha256:2051f12d187a5b4092a142f996776ce54a990e0c4b47ee137ea5fd7246253f05_amd64 |
| Red Hat | openshift4/ose-agent-installer-csr-approver-rhel9@sha256:02060126e7caefe135e907f67dd503e8aaf6b8cd710f0426c47a8ee2babaddc1_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
…and 1310 more
Timeline
- Feb 19, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:1386 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2329817 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://issues.redhat.com/browse/OCPBUGS-45010 advisory
- https://issues.redhat.com/browse/OCPBUGS-49416 advisory
- https://issues.redhat.com/browse/OCPBUGS-49656 advisory
- https://issues.redhat.com/browse/OCPBUGS-49703 advisory
- https://issues.redhat.com/browse/OCPBUGS-49862 advisory
- https://issues.redhat.com/browse/OCPBUGS-49976 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1386.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
- https://access.redhat.com/security/cve/CVE-2024-53104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-53104 advisory
…and 5 more