RHSA-2024:1795MediumCVSS 5.9

Red Hat Security Advisory: VolSync 0.9.1 security fixes and enhancements

Published
April 11, 2024
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

🎯 Affected products6

  • Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9
  • rhacm2/volsync-operator-bundle@sha256:1ccb89c024508d3ffea1d24ec536ddcfbba6d47200fa87052de354ef1bc127f9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9
  • rhacm2/volsync-rhel9@sha256:4a45e1e81d994cca51e8d9126029b7152f0fa4a39061549c52d2f8d88836358d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9
  • rhacm2/volsync-rhel9@sha256:abd52a1d65ab140fe084a5c2e7983075c6883f90252ccf4c8ff0cab62c0660a3_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9
  • rhacm2/volsync-rhel9@sha256:b6fd77aa55250a1a9173a6e069cc9ee20b58cacb449e56f6e02f017ef9f7a322_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9
  • rhacm2/volsync-rhel9@sha256:d7b4f30ee489b4dd36cff82d5e0cb8190964aa1882ee80c65f1050e949ba7287_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/business_continuity/business-cont-overview#volsync Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)