跳转到帖子

Red Hat OpenShift: CVE-2024-24786: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

recommended_posts

发布于
  • Members

Red Hat OpenShift: CVE-2024-24786: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
03/05/2024
Created
03/29/2024
Added
03/28/2024
Modified
02/10/2025

Description

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

Solution(s)

  • linuxrpm-upgrade-cri-o
  • linuxrpm-upgrade-cri-tools
  • linuxrpm-upgrade-microshift
  • linuxrpm-upgrade-openshift
  • linuxrpm-upgrade-ose-azure-acr-image-credential-provider
  • linuxrpm-upgrade-ose-gcp-gcr-image-credential-provider
  • linuxrpm-upgrade-podman

References

  • https://attackerkb.com/topics/cve-2024-24786
  • CVE - 2024-24786
  • RHSA-2024:0040
  • RHSA-2024:0041
  • RHSA-2024:0043
  • RHSA-2024:0045
  • RHSA-2024:10147
  • RHSA-2024:10852
  • RHSA-2024:1362
  • RHSA-2024:1363
  • RHSA-2024:1456
  • RHSA-2024:1461
  • RHSA-2024:1474
  • RHSA-2024:1507
  • RHSA-2024:1508
  • RHSA-2024:1537
  • RHSA-2024:1538
  • RHSA-2024:1559
  • RHSA-2024:1563
  • RHSA-2024:1574
  • RHSA-2024:1616
  • RHSA-2024:1665
  • RHSA-2024:1765
  • RHSA-2024:1795
  • RHSA-2024:1859
  • RHSA-2024:1874
  • RHSA-2024:1925
  • RHSA-2024:1946
  • RHSA-2024:2096
  • RHSA-2024:2548
  • RHSA-2024:2549
  • RHSA-2024:2550
  • RHSA-2024:2639
  • RHSA-2024:2666
  • RHSA-2024:2773
  • RHSA-2024:2781
  • RHSA-2024:2874
  • RHSA-2024:2901
  • RHSA-2024:3254
  • RHSA-2024:3316
  • RHSA-2024:3617
  • RHSA-2024:3621
  • RHSA-2024:3634
  • RHSA-2024:3635
  • RHSA-2024:3636
  • RHSA-2024:3637
  • RHSA-2024:3683
  • RHSA-2024:3715
  • RHSA-2024:3717
  • RHSA-2024:3718
  • RHSA-2024:3868
  • RHSA-2024:4028
  • RHSA-2024:4150
  • RHSA-2024:4163
  • RHSA-2024:4246
  • RHSA-2024:4455
  • RHSA-2024:4591
  • RHSA-2024:4597
  • RHSA-2024:4626
  • RHSA-2024:5013
  • RHSA-2024:5054
  • RHSA-2024:5422
  • RHSA-2024:6004
  • RHSA-2024:6221
  • RHSA-2024:6409
  • RHSA-2024:6824
  • RHSA-2024:7184
  • RHSA-2024:7548
  • RHSA-2024:7922
  • RHSA-2024:8040
  • RHSA-2024:8415
  • RHSA-2024:8434
  • RHSA-2024:8676
  • RHSA-2024:8677
  • RHSA-2024:8704
  • RHSA-2024:9615
  • RHSA-2025:0654
  • RHSA-2025:0664
View more
  • 查看数 705
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…