A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small. https://go.dev/cl/547335 https://go.dev/issue/64433 https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ https://pkg.go.dev/vuln/GO-2023-2382
Created golang tracking bugs for this issue: Affects: epel-all [bug 2253332] Affects: fedora-all [bug 2253333]
We are missing the RHEL 9 tracking bug for toolbox, even though the bugs for RHEL 8 are there.
This issue has been addressed in the following products: Cryostat 2 on RHEL 8 Via RHSA-2024:0530 https://access.redhat.com/errata/RHSA-2024:0530
This issue has been addressed in the following products: RHOL-5.7-RHEL-8 Via RHSA-2024:0694 https://access.redhat.com/errata/RHSA-2024:0694
This issue has been addressed in the following products: RHOL-5.6-RHEL-8 Via RHSA-2024:0695 https://access.redhat.com/errata/RHSA-2024:0695
This issue has been addressed in the following products: RHOL-5.8-RHEL-9 Via RHSA-2024:0728 https://access.redhat.com/errata/RHSA-2024:0728
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:0748 https://access.redhat.com/errata/RHSA-2024:0748
This issue has been addressed in the following products: RHOSS-1.31-RHEL-8 Via RHSA-2024:0843 https://access.redhat.com/errata/RHSA-2024:0843
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2024:0880 https://access.redhat.com/errata/RHSA-2024:0880
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:0887 https://access.redhat.com/errata/RHSA-2024:0887
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2023:7198 https://access.redhat.com/errata/RHSA-2023:7198
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2023:7201 https://access.redhat.com/errata/RHSA-2023:7201
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2023:7200 https://access.redhat.com/errata/RHSA-2023:7200
This issue has been addressed in the following products: RODOO-1.1-RHEL-9 Via RHSA-2024:0269 https://access.redhat.com/errata/RHSA-2024:0269
This issue has been addressed in the following products: Red Hat Developer Tools Via RHSA-2024:1041 https://access.redhat.com/errata/RHSA-2024:1041
This issue has been addressed in the following products: STF-1.5-RHEL-8 Via RHSA-2024:1078 https://access.redhat.com/errata/RHSA-2024:1078
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1131 https://access.redhat.com/errata/RHSA-2024:1131
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1149 https://access.redhat.com/errata/RHSA-2024:1149
This issue has been addressed in the following products: OSSO-1.2-RHEL-9 Via RHSA-2024:0281 https://access.redhat.com/errata/RHSA-2024:0281
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2024:1244 https://access.redhat.com/errata/RHSA-2024:1244
This issue has been addressed in the following products: Red Hat Openshift distributed tracing 3.1 Via RHSA-2024:1434 https://access.redhat.com/errata/RHSA-2024:1434
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2024:1640 https://access.redhat.com/errata/RHSA-2024:1640
This issue has been addressed in the following products: OpenShift Custom Metrics Autoscaler 2 Via RHSA-2024:1812 https://access.redhat.com/errata/RHSA-2024:1812
This issue has been addressed in the following products: OADP-1.3-RHEL-9 Via RHSA-2024:1859 https://access.redhat.com/errata/RHSA-2024:1859
This issue has been addressed in the following products: Service Interconnect 1 for RHEL 9 Via RHSA-2024:1901 https://access.redhat.com/errata/RHSA-2024:1901
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:1896 https://access.redhat.com/errata/RHSA-2024:1896
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2160 https://access.redhat.com/errata/RHSA-2024:2160
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2193 https://access.redhat.com/errata/RHSA-2024:2193
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2245 https://access.redhat.com/errata/RHSA-2024:2245
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2272 https://access.redhat.com/errata/RHSA-2024:2272
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:2988 https://access.redhat.com/errata/RHSA-2024:2988
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 8 Via RHSA-2024:2767 https://access.redhat.com/errata/RHSA-2024:2767
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2024:2729 https://access.redhat.com/errata/RHSA-2024:2729
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2024:2730 https://access.redhat.com/errata/RHSA-2024:2730
This issue has been addressed in the following products: MTA-7.0-RHEL-9 MTA-7.0-RHEL-8 Via RHSA-2024:3316 https://access.redhat.com/errata/RHSA-2024:3316
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2024:3352 https://access.redhat.com/errata/RHSA-2024:3352
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2024:3467 https://access.redhat.com/errata/RHSA-2024:3467
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2024:2728 https://access.redhat.com/errata/RHSA-2024:2728
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2024:3479 https://access.redhat.com/errata/RHSA-2024:3479
This issue has been addressed in the following products: NETWORK-OBSERVABILITY-1.6.0-RHEL-9 Via RHSA-2024:3868 https://access.redhat.com/errata/RHSA-2024:3868