Описание
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
A flaw was found in the crypto/x509 golang library. When using ParsePKCS1PrivateKey to parse an RSA key missing the CRT values, causes a panic when verifying the key is well formed.
Отчет
This vulnerability affects only the Go 1.24 release candidates. Red Hat products do not utilize Go 1.24, except Red Hat Ceph Storage 8 which includes a Grafana container that uses Go 1.24 and is therefore affected by this issue.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 | rhai-tech-preview/assisted-installer-rhel8 | Not affected | ||
| Cryostat 3 | cryostat-tech-preview/cryostat-storage-rhel8 | Not affected | ||
| Deployment Validation Operator | deployment-validation-operator-container | Not affected | ||
| Fence Agents Remediation Operator | fence-agents-remediation-operator-container | Not affected | ||
| Kube Descheduler Operator | kube-descheduler-operator/descheduler-rhel9 | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | ||
| Logical Volume Manager Storage | lvms4/topolvm-rhel9 | Not affected | ||
| Machine Deletion Remediation Operator | machine-deletion-remediation-operator-container | Not affected | ||
| Migration Toolkit for Applications 7 | mta/mta-cli-rhel9 | Not affected | ||
| Migration Toolkit for Containers | rhmtc/openshift-migration-registry-rhel8 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT ...
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
Уязвимость функции ParsePKCS1PrivateKey библиотеки crypto/x509 языка программирования Go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
7.5 High
CVSS3