RHSA-2024:3683MediumCVSS 5.9
Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.5.2 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products41
- RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:7efa0f4d0381a663446d99897730c0001ca7af699efbabd22ec3f6f4bd12f3fd_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:8554b0cc538f191f83ac0c0d252563929ec5e4137a2af398538daf77fcb358a5_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:9bcd4b5aca1fc357e9e92b8d940645836d7903377547806df101ea93460398d1_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:a1e314d8b22764a77d9b83ea60e533576b848aa748a67c0104ce694b7ecb2bbd_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:0919bd3209d65d64a59b11f558c7270720b50e0fc6a2b69f60384001ad534eba_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:3f59e13cd8da98df0c34c8e50ae00f2b0fcd018e6030b417e13cc6f087c3b587_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:56567284a3980bc6ec153e29a6485289de9643872ae223f1c080813c58e7603a_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:f17220f19aac2f8687e7533c63139d3c1a63f92b83f85bd6df2d98a0abe82088_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:1cdee6bbd92342d0e14374547fe036e649757ba2a93afc9ff3d4965e6b38c8c8_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:33b93173762a41ce4fd980a0bf5bdfa29512557f589937dbbf343282be0bcf45_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:b8b2df7d807a13bce662b004debdca603b9774e06c046dea1d1650a1c2c4fa90_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:f209d33cac67e7d02db43eb064597a1beafcca0065fbfe1ded1abffeebc6b53c_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:3c2238f829ff0916a52036daa96c506adfb1a18bbd6949cd4360cc50ce63b6c0_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:8f4e32064a6fb0b0c09cb34ff5a8c7849d685215bdf81788ff7ad4262a7235df_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:bd9ce1fab974822b276adf493e4b7546977ab6d6d407de79436591a7de453f89_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:ff27291e13151332de56253805632b56c3c7f4ee01f13814c1b24eb619ebcaa7_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:605b2a317c7a1c91a2f91f04cac66f772da7cbb4f31a18e796a2f49e069291cb_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:86ef5f79cfb77eb6104b5279b644f1580d2b4c870157793043f8b44ed7144540_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:daaef48d36917f5ce702c8f1db2b6f45d2651eaee47b54fedcaa678a25ab773e_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:ee06df6d74144dfa0e30392b0c8e95ab898b0fc9f8b1c9cdfe046b9d2b9df1b0_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:1505deb27fea3f779281fafdb43c369feecc3c8381d455880f6f9698adcea356_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:373682372ef03b6b2e08f6be87b1e4152c8d05aec66672934f9f503c658b28fb_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:56c42a406cc6c823a00e94162b4fde5567a3b596e910924de937244f946a6ea3_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:761f4924f82c44478beadd811c0a6ef35dfa0a54d8c43ffae17b039c78b7d2b0_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:1e9913a3bd580c99a9a88599b85ccdf0a5e881d6319fa66a86b2d9f4b24fe35f_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:3da0bf97edaf6f0bd89fedf45635fcdbdb7dc8a1891f66644f2a68320ab762b0_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:b9fbde1bb4853041156492398fd6041500648f2b1ee602211732db8d633f38de_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:be9b3a837c877a06a21ab5ffd799a44055b3af044c4a87770b35cc373be23135_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/pilot-rhel8@sha256:1afd56ec54aa68bd803d7d8f11f567c6b27ac71db456a77befbf66739dddd58f_amd64 as a component of RHOSSM 2.5 for RHEL 8
- +11 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:3683
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://issues.redhat.com/browse/OSSM-6290
- externalhttps://issues.redhat.com/browse/OSSM-6295
- externalhttps://issues.redhat.com/browse/OSSM-6298
- externalhttps://issues.redhat.com/browse/OSSM-6299
- externalhttps://issues.redhat.com/browse/OSSM-6397
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3683.json