RHSA-2024:1363MediumCVSS 5.9
Red Hat Security Advisory: OpenShift Container Platform 4.15.3 low-latency extras security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products7
- Red Hat OpenShift Container Platform 4.15
- openshift4/cnf-tests-rhel8@sha256:5f9e3dbddc7d06346bc430c49fe24e002938e4d4b841adf5b3cf8a08a3542a7a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/dpdk-base-rhel8@sha256:2d8e7d2a767b6588ebfc5676aadcf8e283d94e20542ae7743b008fcd58eb848e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/noderesourcetopology-scheduler-rhel9@sha256:aacfeaa5f1f750434195327d064524ac879f83901b6650eea8eec20103d23d60_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/numaresources-must-gather-rhel9@sha256:cc34fdc855c4c5bfac7a16fe00332f617a42e2dbd4e99279b202e0a12248dad7_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/numaresources-operator-bundle@sha256:841a2c113c031b8f4af107359feec70e74996b42d71a503e2e43483f0e73ffcc_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/numaresources-rhel9-operator@sha256:3e889e5c3be7e51909925521f7b62fcdeeddc7693528815823051bfa9251a771_amd64 as a component of Red Hat OpenShift Container Platform 4.15
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:1363
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/cve/cve-2024-24786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1363.json