Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.4.2 security and bug fix update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion
🎯 Affected products45
- 9Base-OADP-1.4
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:434e9437aa77e4446fda71d3cbfaa2b5fd65e5f4a4dd81d200c1f7e3ff4a7783_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:446ccce4d7e6bf9746bf3d2227b63f43641dafc2283c2778ab24934357f6f260_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:8a46a94131498c2a46883528b2649e21aabbaa656f28f94d2849511208765ac5_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:f97bad0f9da6a369d85ef5f47c20a6e543426031229957495ed8223ed5e1feaa_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-mustgather-rhel9@sha256:0292bec8929b93cedd56e9b1a3889ca631bd094eb76619ce07c0fa784c149457_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-mustgather-rhel9@sha256:551271874902237ac31f43fc0f52d5e30a58ed7b4380f6880f72c112424a322d_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-mustgather-rhel9@sha256:981d1c332435a7d37d9a5471b70e60ed7255fa2e7f376137aa37464fabd827db_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-mustgather-rhel9@sha256:e6dfdd774aa508d1cae598fbde44944239fb3f27dfc6f696d6b9ed7c55168f70_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-operator-bundle@sha256:06eecb7e0b06d3619c90ae929bea860214658ea7a67b8ced548902a15961e5d4_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-operator-bundle@sha256:529880c06d04df8943146b6054733098d6f49049f71c65cb8bb5b90481dc8ec7_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-operator-bundle@sha256:949a00c7960288625b09bcc33f4458d94a654e9c1d8ff62261376e73e8932843_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-operator-bundle@sha256:a6ed4b2bb16917f4c170d7f9f37caa40025b2adf26b7b32e3eb29e7c753ad6ab_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-rhel9-operator@sha256:1cd7a7e2c6c74c405cf08a442257e406ecb14ad54eec3c435de2b57a9493c196_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-rhel9-operator@sha256:42f26f43662ad9b36be9d0a71410f5132e13bcbd633b854f0025144b7668a8d0_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-rhel9-operator@sha256:b3e233bf2bcb9c935b916c3a41f1fde7b4f1548f857c708156686432b2b9c543_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-rhel9-operator@sha256:d892e4081236357a3d77722eee8183dde22d67549ba2abddb8ed1ffebaaa27b1_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:40ec162b7ef042ca15e71458e8131d62bb0738d33601e9e7ed615a9b0a09eccf_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:6de95d50fbdf7d0b2ecb26a418a7d86ab9945693e1b24740573c05cf2f0da6b2_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:7c858242c476b0400c38f7ef8a660c4c6961728268a0a0efb873533a80ad3b50_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:98c4abc2b0d3c4c60ca868c88c93b2ee5e8da275a273cd9b2e353d02a15f2128_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:29800c0bfb92819df712408119d059a2700256b70237c19743b3541c7e38ce99_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:623bd5b25e7d0d57cd4bca080fc87aa6f4c1491064f05b34463cdd42be4e44e7_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:8f3ec7dc587441eab6fbe90972c48655a9e184906092a6eaaec47724b4549bf2_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:d8b03f7ed7c2a36ebcbb04e30d71c9c11180e5103dba60211122f8f606256185_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:16fc462b1947610c47536a9b8abb57b2cd1277867690cfb195d874858ed72463_ppc64le as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:48437e2a84201ddca777297db29a6e2ef9cb39ced750b1abbaa3180cc02ba04b_amd64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:b08bd4365b5ee4f24ee1d192f73d4d1a70440d10adf59a10bfc4214fbeebfe9d_s390x as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:f5f651df2afeb3bd590cd606713f160ef27ab1a8999bc2871bb9e9e9db01ca71_arm64 as a component of 9Base-OADP-1.4
- oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:1e5da2e733d5b9bf9a9407821721f9e99190f95e22e1f4fff3f11b6ab0a0f29a_ppc64le as a component of 9Base-OADP-1.4
- +15 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2025:0771
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310529
- externalhttps://issues.redhat.com/browse/OADP-4995
- externalhttps://issues.redhat.com/browse/OADP-5044
- externalhttps://issues.redhat.com/browse/OADP-5095
- externalhttps://issues.redhat.com/browse/OADP-5362
- externalhttps://issues.redhat.com/browse/OADP-5388
- externalhttps://issues.redhat.com/browse/OADP-5460
- externalhttps://issues.redhat.com/browse/OADP-5470
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0771.json