跳转到帖子

Red Hat: CVE-2024-34156: encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2024-34156: encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
09/06/2024
Created
09/25/2024
Added
09/24/2024
Modified
02/10/2025

Description

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Solution(s)

  • redhat-upgrade-aardvark-dns
  • redhat-upgrade-buildah
  • redhat-upgrade-buildah-debuginfo
  • redhat-upgrade-buildah-debugsource
  • redhat-upgrade-buildah-tests
  • redhat-upgrade-buildah-tests-debuginfo
  • redhat-upgrade-cockpit-podman
  • redhat-upgrade-conmon
  • redhat-upgrade-conmon-debuginfo
  • redhat-upgrade-conmon-debugsource
  • redhat-upgrade-container-selinux
  • redhat-upgrade-containernetworking-plugins
  • redhat-upgrade-containernetworking-plugins-debuginfo
  • redhat-upgrade-containernetworking-plugins-debugsource
  • redhat-upgrade-containers-common
  • redhat-upgrade-crit
  • redhat-upgrade-criu
  • redhat-upgrade-criu-debuginfo
  • redhat-upgrade-criu-debugsource
  • redhat-upgrade-criu-devel
  • redhat-upgrade-criu-libs
  • redhat-upgrade-criu-libs-debuginfo
  • redhat-upgrade-crun
  • redhat-upgrade-crun-debuginfo
  • redhat-upgrade-crun-debugsource
  • redhat-upgrade-delve
  • redhat-upgrade-delve-debuginfo
  • redhat-upgrade-delve-debugsource
  • redhat-upgrade-fuse-overlayfs
  • redhat-upgrade-fuse-overlayfs-debuginfo
  • redhat-upgrade-fuse-overlayfs-debugsource
  • redhat-upgrade-git-lfs
  • redhat-upgrade-git-lfs-debuginfo
  • redhat-upgrade-git-lfs-debugsource
  • redhat-upgrade-go-toolset
  • redhat-upgrade-golang
  • redhat-upgrade-golang-bin
  • redhat-upgrade-golang-docs
  • redhat-upgrade-golang-misc
  • redhat-upgrade-golang-race
  • redhat-upgrade-golang-src
  • redhat-upgrade-golang-tests
  • redhat-upgrade-grafana
  • redhat-upgrade-grafana-debuginfo
  • redhat-upgrade-grafana-debugsource
  • redhat-upgrade-grafana-pcp
  • redhat-upgrade-grafana-pcp-debuginfo
  • redhat-upgrade-grafana-pcp-debugsource
  • redhat-upgrade-grafana-selinux
  • redhat-upgrade-libslirp
  • redhat-upgrade-libslirp-debuginfo
  • redhat-upgrade-libslirp-debugsource
  • redhat-upgrade-libslirp-devel
  • redhat-upgrade-netavark
  • redhat-upgrade-oci-seccomp-bpf-hook
  • redhat-upgrade-oci-seccomp-bpf-hook-debuginfo
  • redhat-upgrade-oci-seccomp-bpf-hook-debugsource
  • redhat-upgrade-osbuild-composer
  • redhat-upgrade-osbuild-composer-core
  • redhat-upgrade-osbuild-composer-core-debuginfo
  • redhat-upgrade-osbuild-composer-debuginfo
  • redhat-upgrade-osbuild-composer-debugsource
  • redhat-upgrade-osbuild-composer-dnf-json
  • redhat-upgrade-osbuild-composer-tests-debuginfo
  • redhat-upgrade-osbuild-composer-worker
  • redhat-upgrade-osbuild-composer-worker-debuginfo
  • redhat-upgrade-podman
  • redhat-upgrade-podman-catatonit
  • redhat-upgrade-podman-catatonit-debuginfo
  • redhat-upgrade-podman-debuginfo
  • redhat-upgrade-podman-debugsource
  • redhat-upgrade-podman-docker
  • redhat-upgrade-podman-gvproxy
  • redhat-upgrade-podman-gvproxy-debuginfo
  • redhat-upgrade-podman-plugins
  • redhat-upgrade-podman-plugins-debuginfo
  • redhat-upgrade-podman-remote
  • redhat-upgrade-podman-remote-debuginfo
  • redhat-upgrade-podman-tests
  • redhat-upgrade-python3-criu
  • redhat-upgrade-python3-podman
  • redhat-upgrade-runc
  • redhat-upgrade-runc-debuginfo
  • redhat-upgrade-runc-debugsource
  • redhat-upgrade-skopeo
  • redhat-upgrade-skopeo-debuginfo
  • redhat-upgrade-skopeo-debugsource
  • redhat-upgrade-skopeo-tests
  • redhat-upgrade-slirp4netns
  • redhat-upgrade-slirp4netns-debuginfo
  • redhat-upgrade-slirp4netns-debugsource
  • redhat-upgrade-toolbox
  • redhat-upgrade-toolbox-debuginfo
  • redhat-upgrade-toolbox-debugsource
  • redhat-upgrade-toolbox-tests
  • redhat-upgrade-udica

References

  • CVE-2024-34156
  • RHSA-2024:11216
  • RHSA-2024:11217
  • RHSA-2024:6908
  • RHSA-2024:6912
  • RHSA-2024:6913
  • RHSA-2024:6914
  • RHSA-2024:6946
  • RHSA-2024:6947
  • RHSA-2024:7135
  • RHSA-2024:7136
  • RHSA-2024:7202
  • RHSA-2024:7203
  • RHSA-2024:7204
  • RHSA-2024:7206
  • RHSA-2024:7207
  • RHSA-2024:7262
  • RHSA-2024:7350
  • RHSA-2024:7456
  • RHSA-2024:7769
  • RHSA-2024:7818
  • RHSA-2024:7819
  • RHSA-2024:7820
  • RHSA-2024:7821
  • RHSA-2024:8038
  • RHSA-2024:8039
  • RHSA-2024:8110
  • RHSA-2024:8111
  • RHSA-2024:8112
  • RHSA-2024:9454
  • RHSA-2024:9456
  • RHSA-2024:9459
  • RHSA-2024:9472
  • RHSA-2024:9473
View more
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…