RHSA-2024:1538MediumCVSS 5.9
Red Hat Security Advisory: OpenShift Container Platform 4.12 low-latency extras security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products7
- Red Hat OpenShift Container Platform 4.12
- openshift4/cnf-tests-rhel8@sha256:45ea2c0408804e55d7368805547810532c141ac614a410ed445624814003fd45_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/dpdk-base-rhel8@sha256:afa8c39b03e4a1a42d2e0302d6a19d87c7158dab127fb25e2f2da41d5c96d066_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/noderesourcetopology-scheduler-container-rhel8@sha256:1ba2b2da84ea81478301a559346776ce710bba5a35f44722dcd3dd5f84ee9e4f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/numaresources-operator-bundle@sha256:d50a87f4b8bb430065aa2be56a3391bc20e94ce5a622d029d3f34316dc0cdeec_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/numaresources-rhel8-operator@sha256:9c0cecdb9c9b7fe7a68d32eecd0340e91e7591462e9f55dc5c5841b0de7cae16_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/performance-addon-operator-must-gather-rhel8@sha256:4348aab82a7055fdb42454b74e9ef8a6b46ddb93c45c8f4a7b38ec24f054ad2f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:1538
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/cve/cve-2024-24786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1538.json