RHEA-2024:4835MediumCVSS 5.9
Red Hat Enhancement Advisory: OpenShift Virtualization 4.14.7 Images
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products89
- CNV 4.14 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:f674436335d36d0927c4752498104d6d271e4f0f88eedb5a45da1ed9c71888db_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:fe19bc42ae61902818ace7b96d4b977f894ff7e1ac9ab4951ee92ff43f230c78_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:8888042011273be35ba6b42ba06c6a54a6d57de74bc9693ee4816e9602455f7e_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:bec5d65622cf8cb650884b9213bc0469e4a0dc30379430afd8bbcc3507a5e890_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:72ad18ff34ebaea947f51874b4eb1cf513913907f84015256a03f8baed7456bb_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:e22be6660f00ae8e95f8867bab5e974703f34eed8130883755d5544dc2a2379c_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:180765f468346316692eb88199748c94fa67b8809c9c6aaf4c32f797f989e286_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:62761cebb6d8a9f9099eb3109d2dc9297e58c0af558249f812c1d9c4df18c52c_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:66a0e7e1784f92351c627118772b8a44fe699755fbfb71cd94df787b7dfb6c78_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:db6ebcc4d5a22e5517f49d8664ded019eb3ac67776580feb8c7ee274a0a35c3d_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:45ff8907a32ed17f479286883e180dc80e0dd18453177a293ef1ecdf12ffab64_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:d78a650517b5746d01ad0c9d6aa86553514dcd054ff78377a451a8e63a4a8c63_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:6ac9d98e0fe334189cc4f9105908d6e6084644264c9e5f8f64bf270f54b5de4e_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:aa9688f6718608adf807211823b86289c99afbaa4023e99d2c5ff099aff1b5f4_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:5071491af01e471ffaf81b2089860d857328c9001de9951cf810b4a40244db9b_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:cf8b20338711ec760502b87d4c966d3fdaba3c8997798b61342ea51af5b8ee6f_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:32afdaf9628bf55088ee64da5bb6118d249141a42296854006adcd3e14c07ca4_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:949f0a24a532cd6a2bec7524ac4da8a7a1f40060ea92173cd3351c7af04fc237_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:8600092fc67305e74a45c23644879c7a03fd4345c812143d5c9d2dd147f65e3f_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:a850d5ec817661962a9c20d4b2eaf087f039e4bad1d9294fa0055237a5db6df0_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:9f892f59da16a06344b77d344c33ab24344347adfd7b00825dacdd61610b7e7f_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:ae6bf14291d3cd520b33fe353a157eb9eef186837ab226d89e58e69ac98ae667_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:479f3f93292e5c24d9c72bc690a00e36b69aac369678c2d574fc569268250e90_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:a0d82a4d37ba966e7772f05972aa26f0fd0f2e4e34c90e79ab788d32179cba47_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:d5089b5a17892601112558112a9a3dc58caf3eb3c0846f7b4809965f6a1e2535_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:f9faf7da9fd5850de747578e37e43fb5a349fded5c64253ba6a1250deede144d_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:343b320dc53c1cce82e46cd1b83927b6c52c2393bfbc0dacad3eab67dd5f081f_amd64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:8a0b29e500cd287550c354b0969fd2888852d26f6e3c92d621370632d472e65b_arm64 as a component of CNV 4.14 for RHEL 9
- container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:1abd417ed0f2931fd0d5033140c98712586b1d04163d4a3253a278553e19af1c_amd64 as a component of CNV 4.14 for RHEL 9
- +59 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHEA-2024:4835
- externalhttps://issues.redhat.com/browse/CNV-37739
- externalhttps://issues.redhat.com/browse/CNV-40434
- externalhttps://issues.redhat.com/browse/CNV-41450
- externalhttps://issues.redhat.com/browse/CNV-41950
- externalhttps://issues.redhat.com/browse/CNV-42130
- externalhttps://issues.redhat.com/browse/CNV-42484
- externalhttps://issues.redhat.com/browse/CNV-42918
- externalhttps://issues.redhat.com/browse/CNV-43125
- externalhttps://issues.redhat.com/browse/CNV-43662
- externalhttps://issues.redhat.com/browse/CNV-44479
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhea-2024_4835.json