CVE-2024-45338
Red Hat Security Advisory: OpenShift Container Platform 4.14.49 bug fix and security update
Description
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Metrics
Affected operating systems
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_eus8.8
linux
redhat / enterprise_linux_eus9.0
linux
redhat / enterprise_linux_eus9.2
linux
redhat / enterprise_linux_eus9.4
linux
redhat / enterprise_linux_for_arm_648.0_aarch64
linux
redhat / enterprise_linux_for_arm_649.0_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus8.8_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus9.0_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus9.2_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus9.4_aarch64
linux
redhat / enterprise_linux_for_ibm_z_systems8.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems9.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus8.8_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.2_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.4_s390x
linux
redhat / enterprise_linux_for_power_little_endian8.0_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian9.0_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian_eus8.8_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian_eus9.0_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian_eus9.2_ppc64le
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
android
:linux_kernel::0
android
:linux_kernel:Kernel
go
github.com/containers/buildah1.35.0
go
github.com/containers/buildah1.37.0
go
github.com/containers/buildah1.38.0
go
github.com/containers/buildah
go
golang.org/x/net
linuxfoundation
runc1.1.12
References & sources
- https://source.android.com/security/bulletin/2025-03-01advisory
- https://android.googlesource.com/kernel/common/+/f02dd268a08d4e7ec09ec0ddd2a861ab5a51a0aefix
- https://android.googlesource.com/kernel/common/+/853ec04e2de45ae6d1fc9476ce52d06582ad87edfix
- https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50302government-resource
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://go.dev/cl/637536fix
- https://go.dev/issue/70906report
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJweb
- https://pkg.go.dev/vuln/GO-2024-3333
Linked CVEs
- CVE-2024-9676
A vulnerability was found in Podman, Buildah, and CRI-O.
mediumCVSSv3 6.5 - CVE-2024-9675
A vulnerability was found in Buildah.
highCVSSv3 7.8 - CVE-2024-53197Actively exploited
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and…
criticalCVSSv3 7.8 - CVE-2024-50302Actively exploited
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffe…
criticalCVSSv3 5.5 - CVE-2024-21626
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
highCVSSv3 8.6 - CVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race conditi…
highCVSSv3 8.6 - CVE-2024-11187
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional sec…
highCVSSv3 7.5