Loading HuntDB...

Red Hat OpenShift Container Platform 4.14

212 Versions 22 CVEs

Versions

v4.14.0-202404161544.p0.g9d87281.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb31bf58.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g9cd9922.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g9232c1f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g95d55a0.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gd93a218.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g4e05963.assembly.stream.el8

OTHER 1 CVE

0:4.14.0-202404151639.p0.gf7b14a9.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga0733c1.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb7c61bc.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g9e9b51d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g937b5fd.assembly.stream.el8

OTHER 1 CVE

0:4.14.19-202403280926.p0.gc1f8861.assembly.4.14.19.el9

OTHER 1 CVE

0:1.27.4-6.1.rhaos4.14.gitd09e4c0.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g5553a22.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g697083a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb19eec1.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ge1dd453.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gf0e7cbb.assembly.stream.el8

OTHER 1 CVE

0:1.27.6-2.rhaos4.14.gitb3bd0bf.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g074a22c.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g607e2dd.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g3362d67.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g1c0ecea.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gfb20cda.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g32c1028.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g1a5e72f.assembly.stream.el8

OTHER 1 CVE

3:4.4.1-11.4.rhaos4.14.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g833e1de.assembly.stream.el8

OTHER 1 CVE

0:4.14.0-202404160939.p0.g7bee54d.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g7c0025b.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gc28b223.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g9203d4d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202409130708.p1.g9020ea1.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gf066e57.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g004ecde.assembly.stream.el8

OTHER 1 CVE

0:2.16.2-2.1.rhaos4.14.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g74f5363.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7b56c30.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g29f61f6.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gd876f5a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g711b4f6.assembly.stream.el8

OTHER 1 CVE

0:1.27.4-7.2.rhaos4.14.git082c52f.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g02471d9.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8853e6e.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8666a36.assembly.stream.el8

OTHER 1 CVE

1:1.4.0-1.3.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8ecfd7f.assembly.stream.el8

OTHER 1 CVE

1:1.4.0-1.2.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g09e96a9.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g3985c55.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga687275.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202408260910.p0.gfdd6037.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g95bcf9a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202409111409.p1.g52565ca.assembly.stream.el8

OTHER 1 CVE

2:1.11.3-3.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202411131205.p0.g839a801.assembly.stream.el8

OTHER 1 CVE

3:2.1.7-3.4.rhaos4.14.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.ga367cea.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g9c104de.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g2287fb2.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g264fa5c.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g7bee54d.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g855f3fc.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g5d436c6.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gd3a4a6c.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gece171d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gf21b470.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g801a912.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g446871f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gf401f53.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g2dbe78f.assembly.stream.el8

OTHER 1 CVE

0:1.27.8-10.rhaos4.14.git807f92c.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g72e998c.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gd8cf3c9.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g2a6627b.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g1a957da.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8985876.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7d3fa77.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g5d5105f.assembly.stream.el8

OTHER 1 CVE

414.92.202411130444-0

OTHER 1 CVE

v4.14.0-202404161544.p0.g8f5c90c.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gcd6eae1.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8bd8602.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404170009.p0.g1839fb4.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gbc56886.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8a626fe.assembly.stream.el8

OTHER 1 CVE

1:1.29.1-10.4.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7295a5e.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g5ee0a9d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7bee54d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202310201027.p0.g8b38d12.assembly.stream

OTHER 1 CVE

v4.14.0-202404161544.p0.gf350a68.assembly.stream.el8

OTHER 1 CVE

0:4.14.0-202404151639.p0.g607e2dd.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g44a2b94.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g078aee5.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404170009.p0.g96b62a5.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gf6b13c7.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7fd94aa.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ge79d817.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404171239.p0.gb0c0321.assembly.stream.el9

OTHER 1 CVE

0:4.14.0-202404151639.p0.g81558cc.assembly.stream.el9

OTHER 1 CVE

4:1.1.12-1.2.rhaos4.14.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g6f50b1a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g27f5650.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gc273cd5.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g33f630d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g59a701a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g33a706e.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g93fba13.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g27209ef.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gdcfcfb3.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g34dfccb.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202406112008.p0.g36b3cca.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gd429c8b.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g48fafc4.assembly.stream.el8

OTHER 2 CVEs

v4.14.0-202407021509.p0.g1f72681.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7ad2773.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g43a15be.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb4c4fb1.assembly.stream.el8

OTHER 1 CVE

2:1.11.2-10.4.rhaos4.14.el9

OTHER 1 CVE

0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.gaf210dc.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202407260439.p0.g8d9b39e.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g3a74316.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga4a2f27.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404171239.p0.g88d3f42.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g716a0c3.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g823eb51.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga333cb0.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gdb0c549.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g5d70863.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g35f4739.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga9bcbde.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g08fb27e.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8926a29.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gfb6fb27.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gcafed17.assembly.stream.el9

OTHER 1 CVE

3:4.4.1-21.rhaos4.14.el9

OTHER 1 CVE

v4.14.0-202404170009.p0.g8926a29.assembly.stream.el8

OTHER 1 CVE

3:4.4.1-19.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g61a3465.assembly.stream.el8

OTHER 1 CVE

0:1.27.2-7.rhaos4.14.git1cc7a64.el8

OTHER 1 CVE

0:1.27.0-3.1.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.gd139e6b.assembly.stream.el8

OTHER 1 CVE

0:1.27.8-12.rhaos4.14.git7597c43.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g2fdbd1b.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g13046b3.assembly.stream.el8

OTHER 1 CVE

0:0.19.0-1.3.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g1a646b9.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7296ed5.assembly.stream.el9

OTHER 1 CVE

0:4.14.0-202310261440.p0.g1586504.assembly.4.14.0.el9

OTHER 1 CVE

v4.14.0-202404170009.p0.gd4a1162.assembly.stream.el8

OTHER 1 CVE

414.92.202407300859-0

OTHER 2 CVEs

v4.14.0-202404161544.p0.g46dedc6.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga5ed57f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga4b845a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g06e8ce0.assembly.stream.el8

OTHER 1 CVE

0:1.27.0-3.2.el8

OTHER 1 CVE

0:4.14.0-202403251040.p0.g607e2dd.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gaf40ed0.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb04567f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g3c3f82f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ge372516.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g78da43a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404170009.p0.g3dc363d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga683453.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gaab7b5b.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g27f105d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g270579c.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga267125.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g69d0021.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gae83c55.assembly.stream.el8

OTHER 1 CVE

0:2.16.2-2.2.rhaos4.14.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g9189357.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gd99fb31.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ge292817.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gafffdd4.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g1a9befc.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8558e14.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g9dcaa7f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb3af193.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g91fa980.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gad7aa0a.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g8ba0b37.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g2fa33aa.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gc683f65.assembly.stream.el8

OTHER 1 CVE

0:1.27.7-3.rhaos4.14.git674563e.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g7d96f56.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g7436369.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gb287d08.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gad85376.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g354c55d.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.ga676e6b.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g219f6f6.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g0dbbb61.assembly.stream.el8

OTHER 1 CVE

3:4.4.1-13.4.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404171239.p0.g2eab0f9.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g2e2e277.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g5e74b0f.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g54a95bd.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gdff4b0f.assembly.stream.el8

OTHER 1 CVE

3:4.4.1-11.3.rhaos4.14.el9

OTHER 1 CVE

0:4.14.0-202404151639.p0.gd2acdd5.assembly.stream.el8

OTHER 1 CVE

0:0.19.0-1.4.rhaos4.14.el8

OTHER 1 CVE

414.92.202407091253-0

OTHER 1 CVE

v4.14.0-202404161544.p0.gc038d5a.assembly.stream.el9

OTHER 1 CVE

v4.14.0-202404161544.p0.g78a710f.assembly.stream.el8

OTHER 1 CVE

0:4.14.0-202404151639.p0.g8926a29.assembly.stream.el8

OTHER 1 CVE

2:1.11.2-10.3.rhaos4.14.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.gf7b14a9.assembly.stream.el8

OTHER 1 CVE

v4.14.0-202404161544.p0.g13aebf7.assembly.stream.el8

OTHER 1 CVE

Recent CVEs

CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

UNKNOWN Oct 15, 2024

CVE-2024-9675

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

UNKNOWN Oct 09, 2024

CVE-2024-9341

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

UNKNOWN Oct 01, 2024

CVE-2024-45496

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container.

UNKNOWN Sep 16, 2024

CVE-2024-7387

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

UNKNOWN Sep 16, 2024

CVE-2024-6508

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

UNKNOWN Aug 21, 2024

CVE-2024-7409

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

UNKNOWN Aug 05, 2024

CVE-2024-6409

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.

UNKNOWN Jul 08, 2024

CVE-2024-6387

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

UNKNOWN Jul 01, 2024

CVE-2024-1394

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.

UNKNOWN Mar 21, 2024