RHEA-2024:4866HighCVSS 7.5
Red Hat Enhancement Advisory: Red Hat Service Interconnect 1.4.7 Release rpms
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion
🎯 Affected products6
- 9Base-Service-Interconnect-1.4
- Red Hat Service Interconnect 1.4
- skupper-cli-0:1.4.7-1.el8.src as a component of Red Hat Service Interconnect 1.4
- skupper-cli-0:1.4.7-1.el8.x86_64 as a component of Red Hat Service Interconnect 1.4
- skupper-cli-0:1.4.7-1.el9.src as a component of 9Base-Service-Interconnect-1.4
- skupper-cli-0:1.4.7-1.el9.x86_64 as a component of 9Base-Service-Interconnect-1.4
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258