Bug 2333122 (CVE-2024-45338)
Summary: | CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | MODIFIED --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | aazores, abarbaro, adistefa, akostadi, alcohan, amasferr, amctagga, anjoseph, aoconnor, bkabrda, bniver, brking, cbartlet, cdaley, chazlett, ckandaga, cmah, crizzo, danken, dfreiber, dhanak, dmayorov, drosa, drow, dsimansk, dymurray, eaguilar, ebaron, eglynn, fdeutsch, flucifre, gkamathe, gmeno, gparvin, haoli, hkataria, ibolton, jaharrin, jajackso, jburrell, jcammara, jcantril, jchui, jeder, jforrest, jhe, jjoyce, jkoehler, jlledo, jmatthew, jmitchel, jmontleo, jneedle, jolong, jprabhak, jschluet, jwendell, kegrant, kingland, koliveir, kshier, ktsao, kverlaen, lball, lchilton, lhh, lphiri, lsvaty, mabashia, manissin, matzew, mbenjamin, mburns, mgarciac, mhackett, mkudlej, mmakovy, mnovotny, mwringe, nboldt, ngough, njean, oramraz, owatkins, padillon, pahickey, pbraun, pgaikwad, pgrist, phoracek, pierdipi, pjindal, psrna, pvasanth, rcernich, rguimara, rhaigner, rhuss, rjohnson, rojacob, sakbas, sausingh, sdawley, sfeifer, sfroberg, shvarugh, simaishi, slucidi, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, teagle, tfister, thason, thavo, tjochec, twalsh, vereddy, veshanka, vkumar, whayutin, wtam, yguenane |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | v0.33.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2333195, 2333196, 2333197, 2333207, 2333208, 2333209, 2333210, 2333211, 2333212, 2333213, 2333214, 2333215, 2333216, 2333217, 2333218, 2333242, 2333243, 2333247, 2333248, 2333249, 2333250, 2333251, 2333252, 2333253, 2333254, 2333255, 2333256, 2333259, 2333260, 2333261, 2333263, 2333264, 2350498, 2333198, 2333219, 2333220, 2333221, 2333222, 2333223, 2333224, 2333225, 2333226, 2333227, 2333228, 2333229, 2333230, 2333231, 2333232, 2333233, 2333234, 2333235, 2333236, 2333237, 2333238, 2333239, 2333240, 2333241, 2333244, 2333245, 2333246, 2333257, 2333258, 2333262, 2333265 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2024-12-18 21:01:26 UTC
This issue has been addressed in the following products: RHEL-9-CNV-4.17 Via RHSA-2025:0048 https://access.redhat.com/errata/RHSA-2025:0048 This issue has been addressed in the following products: Cryostat 3 on RHEL 8 Via RHSA-2025:0224 https://access.redhat.com/errata/RHSA-2025:0224 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0115 https://access.redhat.com/errata/RHSA-2025:0115 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:0140 https://access.redhat.com/errata/RHSA-2025:0140 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:0121 https://access.redhat.com/errata/RHSA-2025:0121 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:0385 https://access.redhat.com/errata/RHSA-2025:0385 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0386 https://access.redhat.com/errata/RHSA-2025:0386 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0384 https://access.redhat.com/errata/RHSA-2025:0384 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.4 for RHEL 8 Via RHSA-2025:0552 https://access.redhat.com/errata/RHSA-2025:0552 This issue has been addressed in the following products: multicluster-globalhub 1.2 for RHEL 9 Via RHSA-2025:0560 https://access.redhat.com/errata/RHSA-2025:0560 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 Via RHSA-2025:0576 https://access.redhat.com/errata/RHSA-2025:0576 This issue has been addressed in the following products: multicluster-globalhub 1.3 for RHEL 9 Via RHSA-2025:0577 https://access.redhat.com/errata/RHSA-2025:0577 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:0364 https://access.redhat.com/errata/RHSA-2025:0364 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 Via RHSA-2025:0678 https://access.redhat.com/errata/RHSA-2025:0678 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 Via RHSA-2025:0679 https://access.redhat.com/errata/RHSA-2025:0679 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0653 https://access.redhat.com/errata/RHSA-2025:0653 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0654 https://access.redhat.com/errata/RHSA-2025:0654 This issue has been addressed in the following products: RHODF-4.17-RHEL-9 Via RHSA-2025:0775 https://access.redhat.com/errata/RHSA-2025:0775 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:0783 https://access.redhat.com/errata/RHSA-2025:0783 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.6 for RHEL 9 multicluster engine for Kubernetes 2.6 for RHEL 8 Via RHSA-2025:0778 https://access.redhat.com/errata/RHSA-2025:0778 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0785 https://access.redhat.com/errata/RHSA-2025:0785 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:0649 https://access.redhat.com/errata/RHSA-2025:0649 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:0650 https://access.redhat.com/errata/RHSA-2025:0650 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:0645 https://access.redhat.com/errata/RHSA-2025:0645 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:0646 https://access.redhat.com/errata/RHSA-2025:0646 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 Via RHSA-2025:0821 https://access.redhat.com/errata/RHSA-2025:0821 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:0851 https://access.redhat.com/errata/RHSA-2025:0851 This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2025:0892 https://access.redhat.com/errata/RHSA-2025:0892 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.6 Via RHSA-2025:0907 https://access.redhat.com/errata/RHSA-2025:0907 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:1013 https://access.redhat.com/errata/RHSA-2025:1013 This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.4 for RHEL 8 Via RHSA-2025:1050 https://access.redhat.com/errata/RHSA-2025:1050 This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.5 for RHEL 8 Via RHSA-2025:1051 https://access.redhat.com/errata/RHSA-2025:1051 This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.6 for RHEL 8 Red Hat OpenShift Service Mesh 2.6 for RHEL 9 Via RHSA-2025:1053 https://access.redhat.com/errata/RHSA-2025:1053 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0875 https://access.redhat.com/errata/RHSA-2025:0875 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:0831 https://access.redhat.com/errata/RHSA-2025:0831 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:0832 https://access.redhat.com/errata/RHSA-2025:0832 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:0827 https://access.redhat.com/errata/RHSA-2025:0827 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:0839 https://access.redhat.com/errata/RHSA-2025:0839 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:0840 https://access.redhat.com/errata/RHSA-2025:0840 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:1119 https://access.redhat.com/errata/RHSA-2025:1119 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:1120 https://access.redhat.com/errata/RHSA-2025:1120 This issue has been addressed in the following products: gatekeeper 3.17 for RHEL 9 Via RHSA-2025:1331 https://access.redhat.com/errata/RHSA-2025:1331 This issue has been addressed in the following products: gatekeeper 3.15 for RHEL 9 Via RHSA-2025:1332 https://access.redhat.com/errata/RHSA-2025:1332 This issue has been addressed in the following products: gatekeeper 3.14 for RHEL 9 Via RHSA-2025:1333 https://access.redhat.com/errata/RHSA-2025:1333 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.5 Via RHSA-2025:1334 https://access.redhat.com/errata/RHSA-2025:1334 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:1123 https://access.redhat.com/errata/RHSA-2025:1123 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:1128 https://access.redhat.com/errata/RHSA-2025:1128 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:1115 https://access.redhat.com/errata/RHSA-2025:1115 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:1116 https://access.redhat.com/errata/RHSA-2025:1116 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.4 Via RHSA-2025:1468 https://access.redhat.com/errata/RHSA-2025:1468 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:1450 https://access.redhat.com/errata/RHSA-2025:1450 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:1386 https://access.redhat.com/errata/RHSA-2025:1386 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:1451 https://access.redhat.com/errata/RHSA-2025:1451 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2024:6122 https://access.redhat.com/errata/RHSA-2024:6122 This issue has been addressed in the following products: RHODF-4.17-RHEL-9 Via RHSA-2025:1824 https://access.redhat.com/errata/RHSA-2025:1824 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:1829 https://access.redhat.com/errata/RHSA-2025:1829 This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:1865 https://access.redhat.com/errata/RHSA-2025:1865 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:1866 https://access.redhat.com/errata/RHSA-2025:1866 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:1710 https://access.redhat.com/errata/RHSA-2025:1710 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:1711 https://access.redhat.com/errata/RHSA-2025:1711 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:2449 https://access.redhat.com/errata/RHSA-2025:2449 This issue has been addressed in the following products: RHODF-4.18-RHEL-9 Via RHSA-2025:2652 https://access.redhat.com/errata/RHSA-2025:2652 This issue has been addressed in the following products: RHEL-9-CNV-4.15 Via RHSA-2025:2658 https://access.redhat.com/errata/RHSA-2025:2658 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:2440 https://access.redhat.com/errata/RHSA-2025:2440 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:2441 https://access.redhat.com/errata/RHSA-2025:2441 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:2710 https://access.redhat.com/errata/RHSA-2025:2710 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:2700 https://access.redhat.com/errata/RHSA-2025:2700 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:2701 https://access.redhat.com/errata/RHSA-2025:2701 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.14 Via RHSA-2025:3069 https://access.redhat.com/errata/RHSA-2025:3069 This issue has been addressed in the following products: RHOL-6.0-RHEL-9 Via RHSA-2025:3132 https://access.redhat.com/errata/RHSA-2025:3132 This issue has been addressed in the following products: RHOL-6.1-RHEL-9 Via RHSA-2025:3131 https://access.redhat.com/errata/RHSA-2025:3131 This issue has been addressed in the following products: RHODF-4.17-RHEL-9 Via RHSA-2025:3500 https://access.redhat.com/errata/RHSA-2025:3500 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:3502 https://access.redhat.com/errata/RHSA-2025:3502 This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:3542 https://access.redhat.com/errata/RHSA-2025:3542 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:3560 https://access.redhat.com/errata/RHSA-2025:3560 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:3573 https://access.redhat.com/errata/RHSA-2025:3573 This issue has been addressed in the following products: RHEL-9-CNV-4.16 Via RHSA-2025:3973 https://access.redhat.com/errata/RHSA-2025:3973 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:4007 https://access.redhat.com/errata/RHSA-2025:4007 This issue has been addressed in the following products: RHOL-5.8-RHEL-9 Via RHSA-2025:7451 https://access.redhat.com/errata/RHSA-2025:7451 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:8301 https://access.redhat.com/errata/RHSA-2025:8301 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:8479 https://access.redhat.com/errata/RHSA-2025:8479 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:8280 https://access.redhat.com/errata/RHSA-2025:8280 This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2025:8510 https://access.redhat.com/errata/RHSA-2025:8510 This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:8544 https://access.redhat.com/errata/RHSA-2025:8544 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:8551 https://access.redhat.com/errata/RHSA-2025:8551 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:8556 https://access.redhat.com/errata/RHSA-2025:8556 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2024:11037 https://access.redhat.com/errata/RHSA-2024:11037 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2024:11038 https://access.redhat.com/errata/RHSA-2024:11038 |