RHSA-2024:2874MediumCVSS 5.9

Red Hat Security Advisory: OpenShift Container Platform 4.13.42 security and extras update

Published
May 23, 2024
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

🎯 Affected products161

  • Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:2b591707e8d10d1c897067c9c6fd1eddbb3c5eb262a65b9b16105476d504e61d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:8ae08d97216a0652179f0becbc91f33ec2b9923a322f768bc04bca460c268fed_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:99f7569c83d07a7e74b5fcf149600e16e330542a2b383a2628621a190cfc8d76_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:efb9ba771a05965496cad47df9f54146eba375a759e9402d92d1f600e48e5d0b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/dpu-network-rhel8-operator@sha256:4ee73d8a1294109220f2a49cfa9923199bfc5d558fa7267f66d78587c9fd4c73_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/dpu-network-rhel8-operator@sha256:746e232d59d225c138499ed9b6a14a97466d9cb923ee1e91da396e68b737f77f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/frr-rhel8@sha256:2f42fd447e32bc3ea8d49aae9cba7491ea622885d702b5e9ba99cb2750f67a96_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/frr-rhel8@sha256:c35eca7f82fb29b46a48314a5470dc95095917c53077c49079f20b8f45ce7573_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/frr-rhel8@sha256:c76bf179b80609c606ca5798add63effdbacf6f149c8f5729e5397269ba36bc2_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/frr-rhel8@sha256:d94ecb0b27830940f8b7d2b741cddce6630d2ce7e8614a0cdcb0dbd25485d0cc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:156046c2ff0d5ba0f6d7998182498b6f92f6ed4af5b8933be64131d53fbe1d04_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:26b0860542b41bfb3f87676dc7d1d82cd7e4bf4a987f6503e7085059e51f38ad_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:a1ab3abe4e59d4e658d67300d346d44a52b5fed2ff0e5e2f951e1255e28c0f73_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:c9a27760f46c50ef62df490514e963ad0aa1ac7240290a70377bdea2a416ebf1_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall@sha256:8c28144679d53fb3489eba7a9444f2b8ba657b1eede846400216af7fbe56dd17_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall@sha256:c544029db2169e86d828c361826bff7cc0ba79efb24dc8e503b5d2d5112d4bf7_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall@sha256:e4c45c1f483aa791a49c8e28bd2fe47717a3d5cc8467a52ef246197d44cbb55a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ingress-node-firewall@sha256:f3ba88f06ea923a10a867885bd1060a3dc1dec4465692a99db4fdbf282f6c700_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:23ecba97d562b8389a8a8a755c1c0fb6ff14da790479ee74069bc66dbf216945_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:7b4ddc54c3f90f3987c58b1196047af17d697f3d7d0c02a56a49868ce288359b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:934f6db3d87b8cf3734a22f353a7dbd391e3e8b9aef225bcbbacbc09158b5eac_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:b93531a6035d923bdf49a2b86f52100de74291fabf64af248b4b5103e703b75b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:171e35c0ce66859bde043bc79e0960b66c73110df5d3e219530bdebec836a811_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:94f9b63b439e7936a04e368654ec0eb2ad985516060023802dfea5b856e6d372_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:cc66a8b97e1d507aba8517bdc0d1a02fbd941c0dd5078fccac5ff9e5bcac5dd8_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:d038b98f7eebc1582ab4aa07397f0284e9e09616c4562ffd185db45d24715dcb_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:2b591707e8d10d1c897067c9c6fd1eddbb3c5eb262a65b9b16105476d504e61d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:8ae08d97216a0652179f0becbc91f33ec2b9923a322f768bc04bca460c268fed_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:99f7569c83d07a7e74b5fcf149600e16e330542a2b383a2628621a190cfc8d76_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +131 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (4)