CVE-2024-45338

Red Hat Security Advisory: OpenShift Container Platform 4.14.49 bug fix and security update

Description

A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.

Metrics

Severity
high
no public PoC known
56.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-03-19 20:54 UTC

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_eus8.8

  • linux

    redhat / enterprise_linux_eus9.0

  • linux

    redhat / enterprise_linux_eus9.2

  • linux

    redhat / enterprise_linux_eus9.4

  • linux

    redhat / enterprise_linux_for_arm_648.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_649.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus8.8_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.2_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.4_aarch64

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus8.8_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.2_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.4_s390x

  • linux

    redhat / enterprise_linux_for_power_little_endian8.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian9.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus8.8_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus9.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus9.2_ppc64le

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • go

    github.com/containers/buildah1.35.0

  • go

    github.com/containers/buildah1.37.0

  • go

    github.com/containers/buildah1.38.0

  • go

    github.com/containers/buildah

  • go

    golang.org/x/net

  • linuxfoundation

    runc1.1.12

References & sources

Linked CVEs

IDCVE-2024-45338