RHSA-2024:1537MediumCVSS 5.9

Red Hat Security Advisory: OpenShift Container Platform 4.13.38 low-latency extras security update

Published
March 27, 2024
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

🎯 Affected products7

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cnf-tests-rhel8@sha256:1557755b7221f41738b6b607af8412d6fb541ceb08fd48f82ad5580d8daafc9f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/dpdk-base-rhel8@sha256:0e6bdd39419572fba8f89c910b9313dc74b96dc0ea7d4efa44f9b69be0f33e28_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:ac0874d92b3204756ddaa4f5b6e4a4d66ecc9e807c5deb0b028d744424d00eb6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/numaresources-operator-bundle@sha256:7f5ddc79b60a283066285fb5fed5e91b9a7b6d50d4c16095b4ee984456352a06_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/numaresources-rhel8-operator@sha256:61046b76f996adb139cdc44cbb142b6999bf8503229a65d18227c2ebdcac18fc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/performance-addon-operator-must-gather-rhel8@sha256:7c62a226b3098c724402201e0fc251d7abbbfc726f18d556ad97d58684eb6373_amd64 as a component of Red Hat OpenShift Container Platform 4.13

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)