RHSA-2024:1362MediumCVSS 5.9
Red Hat Security Advisory: OpenShift Container Platform 4.14.17 low-latency extras security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products7
- Red Hat OpenShift Container Platform 4.14
- openshift4/cnf-tests-rhel8@sha256:b45742b51ac994df990a8e2494e15b6db2e3d33c7de87e4a7dc41ea17225a57b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/dpdk-base-rhel8@sha256:b97d399e4d69fe91a117293f626c4ac5af147ead787799079d6efdce60185702_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/noderesourcetopology-scheduler-rhel9@sha256:e1e70c7dde2dd057d215366c606db981e1db14dd453e5bd5c961ca86a4018f48_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/numaresources-must-gather-rhel9@sha256:1dfef3b0b83661a09eda32c3d6a44e7414c212270ff96a9f482fe7451e5a619b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/numaresources-operator-bundle@sha256:ced49845d0a750ca0851ed00b2883553796b46493859f368da77485b55e4faa6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/numaresources-rhel9-operator@sha256:7f87531a89da16c4607d73a5eceae1002cb21242ff26901dbee8c64d15a2ecef_amd64 as a component of Red Hat OpenShift Container Platform 4.14
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:1362
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/cve/cve-2024-24786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1362.json