RHSA-2024:2781MediumCVSS 5.9

Red Hat Security Advisory: OpenShift Container Platform 4.12.57 security update

Published
May 16, 2024
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

🎯 Affected products166

  • Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:1678f27ce3ddc37295cfc9dffb3fb24c24fc34c85240767a2620fcf57ab8078c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:25908d03fc7920d44f346bd8fc0bade1698cc2f197ccdc52e4ec04c619bf1b1e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:60834b072826146b09aeb5c5af5c73ae5e33e675502b89b0cd006c07a3533a3a_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:766aaccd430ca03e3e08f1c9f6468e71c1d6d7ac441d694876f9c4211c7dd5ca_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:5ca58b8b07f7e011579ca8f53135d46000f83eae1074d160af08a7632b945833_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:785022acdb6c4d00bad867ea91b51f21a21e915c6ffcdffd72ffa899a682da5a_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:94106521ade0ae9d18ca213b16cc184a981cb01ca7fea3a3022c11714f538710_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:5ec1849b5bca3d8fcdc49de0ecf57d81041f4691c2b39b12fcf9d0aa8885077e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:d265fa29474411581f447c1b86f98e42c7560f28b1175260660f848c854a26ca_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:61bba37248af7f28a7e2671452eaef99d2b46f341535166e8159b5c2547a0b13_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:6a1b0a4b40c4b76723bb16809677af55e48ef60a6c58bb8379ac7c6267c87fcd_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:8810eac69b2fed010d2d5ea96f9b08933079c9a13be3f53f36e04c9e561fc46b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:980bf6736328bbdcc8a3331d1d1b1446546ce2ba0626c54a29a66849015051bb_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:2ac5bed35ddc051f9eb06bc309c6fe5c0a5e845dd2f23beebaf8de58a491c3d9_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:8f942a19a5fa88907a3a439b9642d4aad7e566162cd360d775be80de784b4789_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:9d3af62cf6375d9780bba6d0d5a7f559d803cb29f13fb66a5607804e929a7e29_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:dbcffae40a2b88e1578be690f0604ca9563a26d78749d1986a5bc738035658ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:0907f4d4fce174490ac9929fa7b560a3ed9ee6bb38d861b27197549816db3edb_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:0ea75b77cbf04f8a0b98360d4a9c535071126a6e65cd5d46d762de94bbb9b85c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:6984d713fed6446a45c94182d24b93650f5856c9f5c6f027a07afc799e89b076_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:9baed346e3c0c529e6073ed6a25b5a1184980091ebd2fb2fe6fd36246b6f2402_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:21ee219fa1d2107f654a6a22867e72eb6f6a6f402410e446907e541d2abe5834_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:294dda4a4dc390d7d940841113b9ab1a2588953595c5c6a3f015b358ccfe5a73_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:2f2187f52491d343d20ea74c0bf87d99c86a03464872c3bb8d98763fd8626efe_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:e6506a5d084714ab8245a0e9b26f23ab204bbdb6b4e273bc058c1eeead00e945_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:084fe593e10dd897c5c5d3e0bc59b2f53931aeca4e910e5e44544e108bcd7120_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:8639391fc942785071f39c6aee02c3fcc98cb9c03a6cfdd3e1077cc6b5231355_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:d86b5d4806d25079c75791fb15f01c00c844dcdaf291865bbd812160798a2fc6_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:fbe57e57e27afa8fb4875e713f00a5e5f888440c1628575e04cb2e2ec66ca204_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +136 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)