Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-34156

Опубликовано: 06 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

A flaw was found in the encoding/gob package of the Golang standard library. Calling Decoder.Decoding, a message that contains deeply nested structures, can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Отчет

This vulnerability in Go's encoding/gob package is of high severity because it exposes applications to potential Denial of Service (DoS) attacks through stack exhaustion. Since gob relies on recursive function calls to decode nested structures, an attacker could exploit this by sending crafted messages with excessively deep nesting, causing the application to panic due to stack overflow. This risk is particularly important in scenarios where untrusted or external input is processed, as it can lead to system unavailability or crashes, undermining the reliability and availability of services.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel8Will not fix
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Migration Toolkit for Applications 7mta/mta-hub-rhel9Will not fix
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-api-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/hive-rhel8Affected
Node Maintenance Operatorworkload-availability/node-maintenance-rhel8-operatorWill not fix
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-clientsWill not fix
OpenShift Service Mesh 2openshift-golang-builder-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/subctl-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2310528encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

EPSS

Процентиль: 31%
0.00114
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
nvd
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
debian
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested struc ...

rocky
8 месяцев назад

Important: skopeo security update

rocky
8 месяцев назад

Important: containernetworking-plugins security update

EPSS

Процентиль: 31%
0.00114
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-34156