VDB
RHSA-2025%3A1450
RHSA-2025%3A1450
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-egress-dns-proxy@sha256:a7f3c8e1b149052f62ba043a0ba42944637a92205629b818ac97368ccc18c43c_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/ose-ptp-operator@sha256:36c168547982d43811bd4f33e33c6f859ae957dd9276d16f6832fbc1fb0eed80_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-ptp-operator@sha256:36c168547982d43811bd4f33e33c6f859ae957dd9276d16f6832fbc1fb0eed80_arm64 |
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8@sha256:91c361012a03db987df33ab914abfde9f365361864434c5c37e3fc42eb965e83_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-clusterresourceoverride-rhel8@sha256:91c361012a03db987df33ab914abfde9f365361864434c5c37e3fc42eb965e83_arm64 |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:0860338207bceb9e574c1f17d3f06293155afc9b6b432065e7b73f2ba431b238_s390x as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ptp-must-gather-rhel8@sha256:b2f08bc722bcaa410a86b8f073f56257859daca843c8536b8a89d2d4cb8da97b_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ptp-must-gather-rhel8@sha256:b2f08bc722bcaa410a86b8f073f56257859daca843c8536b8a89d2d4cb8da97b_arm64 |
| Red Hat | openshift4/ose-ptp-rhel9@sha256:cacc424a1e95ff183cd8bae4be5cae3c98eaebca5a114803d33403c69d5e84a0_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-ptp-rhel9@sha256:cacc424a1e95ff183cd8bae4be5cae3c98eaebca5a114803d33403c69d5e84a0_arm64 |
| Red Hat | openshift4/ingress-node-firewall-rhel9-operator@sha256:cc8164bf66e138f9de18d244a00383cbf68684e9fd140fb639ffa92ca7b1150c_s390x as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel8@sha256:877aeda65dd7dbe4f8e9470fc87ff8f5630f3c0d67cf2766733cbfd76194408b_s390x as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/cloud-event-proxy-rhel8@sha256:f7c9c83a4ff98a0cc04e7b7dd28f99f99a517dc6af3232827d372a2522da25a7_amd64 | |
| Red Hat | openshift4/ose-sriov-network-config-daemon@sha256:a6cdff192cd94eb9fb95c158ea54779d21ffe5aebb5c2a2dc9d97bfd9017a0b6_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:0792336bd84972ee0d2be853e48bf8eb0901318320657f17ac5bd24badedf9f5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:362bb05010a29a992bd21fdf9de04972166765f9d4fe5ba3a9bb7f9e27498ed0_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:362bb05010a29a992bd21fdf9de04972166765f9d4fe5ba3a9bb7f9e27498ed0_s390x |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:59e9cdff6098f1266abfa43e5203a7b49f8a20f8bd77a5ff5c50398c93241e81_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/ose-egress-router@sha256:b6255f5e9a08bfaee8ba82fbe1095deafdfe4789901dcf603988cb3f636c9d48_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:856b5b04ced3a5384efce8a29c6b75ed4638388e78308e9f5ea60989c8a0533c_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:856b5b04ced3a5384efce8a29c6b75ed4638388e78308e9f5ea60989c8a0533c_amd64 |
| Red Hat | openshift4/metallb-rhel9-operator@sha256:7d66e5eb7c8f75a01c67d3ff49ca4795814e24b7665e04c48c25a6c7220097cf_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:a6605aa3258a9385f41fdc52ab25c9f613c5154f082c0f960c51ac8a8feb3d8c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-sriov-network-device-plugin@sha256:a6605aa3258a9385f41fdc52ab25c9f613c5154f082c0f960c51ac8a8feb3d8c_ppc64le |
| Red Hat | openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:50fe02dc3c620bd81ba990f9e3a9f1889fbedc938529100c269d18b612ec6090_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/nmstate-console-plugin-rhel8@sha256:f2007636ee7b9c3c4f0ea0c357e5db46bf24411f172c401cc0f635a97da44ea3_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | *, *, * |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:ce7e9b033d9a2a4e6b8fb8323a067685cec04dac89ba13a1b2d8c77f20133699_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | * |
…and 324 more
Timeline
- Feb 19, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:1450 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1450.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory