CVE-2023-24536

medium
Published 2023-05-25 · Modified 2023-11-27
CVSS v3
CVSS v2
VIR risk
5.5

Description

Moderate: container-tools:rhel8 security and bug fix update

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-6939.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:6939

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-6938.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2182884

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2182883

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2175721

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:6938

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6474.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2228689

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6473.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2174485

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6402.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6363.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184484

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178492

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6346.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2222167

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196029

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196027

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196026

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184483

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184482

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184481

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178488

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178358

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2163037

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-24536

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-24536.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6474

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6473

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6402

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6363

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6346

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:3318

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6939

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6938

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption Red Hat statement For Red Hat Enterprise Linux, * Conmon uses Go in unit testing, but not functionally in the package. Go is used only in test files, hence, not in the actual code, thus, conmon is not-affected. * The CVE refers to multipart form parsing routine…

Description

golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption

Red Hat statement

For Red Hat Enterprise Linux, * Conmon uses Go in unit testing, but not functionally in the package. Go is used only in test files, hence, not in the actual code, thus, conmon is not-affected. * The CVE refers to multipart form parsing routine mime/multipart.Reader.ReadForm, which is not used in Grafana, hence it is not-affected. * Butane does not parse multipart forms, hence, it is also not-affected. Redhat has marked this vulnerability as moderate as this vulnerability could lead to a potential denial of service when all the resource of a system is consumed which is technically not a clear case of denial of service.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
CERT-MANAGER-1.10-RHEL-9cert-manager-operator-bundle-container-v1.10.3-4RHSA-2023:43352023-08-08T00:00:00Z
CERT-MANAGER-1.10-RHEL-9cert-manager-operator-container-v1.10.3-2RHSA-2023:43352023-08-08T00:00:00Z
CERT-MANAGER-1.10-RHEL-9jetstack-cert-manager-container-v1.10.2-18RHSA-2023:43352023-08-08T00:00:00Z
Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-grafana-dashboard-rhel8:2.3.0-5RHSA-2023:31672023-05-18T00:00:00Z
Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-operator-bundle:2.3.0-5RHSA-2023:31672023-05-18T00:00:00Z
Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-reports-rhel8:2.3.0-5RHSA-2023:31672023-05-18T00:00:00Z
Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-rhel8:2.3.0-5RHSA-2023:31672023-05-18T00:00:00Z
Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-rhel8-operator:2.3.0-5RHSA-2023:31672023-05-18T00:00:00Z
Cryostat 2 on RHEL 8cryostat-tech-preview/jfr-datasource-rhel8:2.3.0-5RHSA-2023:31672023-05-18T00:00:00Z
Migration Toolkit for Virtualization 2.4migration-toolkit-virtualization/mtv-controller-rhel9:2.4.3-5RHBA-2023:61092023-10-25T00:00:00Z
MTA-6.2-RHEL-9mta/mta-hub-rhel9:6.2.0-16RHSA-2023:46272023-08-14T00:00:00Z
OADP-1.1-RHEL-8oadp/oadp-velero-rhel8:1.1.5-3RHSA-2023:39182023-06-29T00:00:00Z
Openshift Serverless 1 on RHEL 8openshift-serverless-clients-0:1.8.1-3.el8RHSA-2023:34502023-06-05T00:00:00Z
OSSO-1.1-RHEL-8openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8:v1.1-30RHSA-2023:46572023-08-23T00:00:00Z
Red Hat Ansible Automation Platform 2.3 for RHEL 8openshift-clients-0:4.12.0-202307200611.p0.g49844f7.assembly.stream.el8RHSA-2023:44702023-08-03T00:00:00Z
Red Hat Enterprise Linux 8go-toolset:rhel8-8080020230517172404.6b4b45d8RHSA-2023:33192023-05-25T00:00:00Z
Red Hat Enterprise Linux 8container-tools:4.0-8090020230828093056.e7857ab1RHSA-2023:69382023-11-14T00:00:00Z
Red Hat Enterprise Linux 8container-tools:rhel8-8090020230825121312.e7857ab1RHSA-2023:69392023-11-14T00:00:00Z
Red Hat Enterprise Linux 9golang-0:1.19.9-2.el9_2RHSA-2023:33182023-05-25T00:00:00Z
Red Hat Enterprise Linux 9toolbox-0:0.0.99.4-6.el9_3RHSA-2023:63462023-11-07T00:00:00Z
Red Hat Enterprise Linux 9skopeo-2:1.13.3-1.el9RHSA-2023:63632023-11-07T00:00:00Z
Red Hat Enterprise Linux 9containernetworking-plugins-1:1.3.0-4.el9RHSA-2023:64022023-11-07T00:00:00Z
Red Hat Enterprise Linux 9buildah-1:1.31.3-1.el9RHSA-2023:64732023-11-07T00:00:00Z
Red Hat Enterprise Linux 9podman-2:4.6.1-5.el9RHSA-2023:64742023-11-07T00:00:00Z
Red Hat Migration Toolkit for Containers 1.7rhmtc/openshift-velero-plugin-rhel8:v1.7.10-2RHSA-2023:36242023-06-15T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/cloud-network-config-controller-rhel8:v4.13.0-202305262054.p0.g71ccef5.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/egress-router-cni-rhel8:v4.13.0-202305270643.p0.g879b72b.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/kubevirt-csi-driver-rhel8:v4.13.0-202305262054.p0.gefa0b94.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/network-tools-rhel8:v4.13.0-202305300541.p0.gb4098c6.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/oc-mirror-plugin-rhel8:v4.13.0-202305262054.p0.g74d3207.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/openshift-route-controller-manager-rhel8:v4.13.0-202305262054.p0.gd7a8e22.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-api-server-rhel8:v4.13.0-202305291355.p0.g8db33db.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-csr-approver-rhel8:v4.13.0-202305291355.p0.g6160d18.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-node-agent-rhel8:v4.13.0-202305262054.p0.ge8de058.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-orchestrator-rhel8:v4.13.0-202305262054.p0.g6160d18.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-cloud-controller-manager-rhel8:v4.13.0-202305262054.p0.gb5200ba.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:v4.13.0-202305262054.p0.g68c0ecf.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:v4.13.0-202305262054.p0.g0f4b92a.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-machine-controllers-rhel8:v4.13.0-202305262054.p0.g4c0f96a.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-apiserver-network-proxy-rhel8:v4.13.0-202305262054.p0.g61e198c.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-cloud-controller-manager-rhel8:v4.13.0-202305262054.p0.g946daa0.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-cluster-api-controllers-rhel8:v4.13.0-202305262054.p0.g4251ed3.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-ebs-csi-driver-rhel8:v4.13.0-202305262054.p0.gd8fa531.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-ebs-csi-driver-rhel8-operator:v4.13.0-202305262054.p0.gb6dee5c.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-pod-identity-webhook-rhel8:v4.13.0-202305262054.p0.g4969655.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-cloud-controller-manager-rhel8:v4.13.0-202305262054.p0.g7afcf26.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-cloud-node-manager-rhel8:v4.13.0-202305262054.p0.g7afcf26.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-cluster-api-controllers-rhel8:v4.13.0-202305262054.p0.g9885d4d.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-disk-csi-driver-rhel8:v4.13.0-202305262054.p0.g202e8af.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-disk-csi-driver-rhel8-operator:v4.13.0-202305262054.p0.g67bda47.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-file-csi-driver-operator-rhel8:v4.13.0-202305262054.p0.g994c32c.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-file-csi-driver-rhel8:v4.13.0-202305262054.p0.gfd94a03.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-installer-rhel8:v4.13.0-202305270643.p0.gb332f7a.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-machine-controllers:v4.13.0-202305262054.p0.gd20bc57.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-rhel8-operator:v4.13.0-202305290832.p0.gb771b3b.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-runtimecfg-rhel8:v4.13.0-202305262054.p0.gf0c1297.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cli:v4.13.0-202305291355.p0.g1024efc.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cli-artifacts:v4.13.0-202305291355.p0.g1024efc.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cloud-credential-operator:v4.13.0-202305262054.p0.gd3b5ffa.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-api-rhel8:v4.13.0-202305262054.p0.g0142186.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z

Package state

ProductPackageState
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel8-operatorAffected
Node Maintenance Operatorworkload-availability/node-maintenance-rhel8-operatorAffected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Will not fix
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Pipelinesopenshift-pipelines-clientAffected
OpenShift Service Mesh 2openshift-golang-builder-containerWill not fix
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2thanos-containAffected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Affected
Red Hat AMQ Broker 7amq-broker-rhel8-operator-containerAffected
Red Hat Ansible Automation Platform 2receptorAffected
Red Hat Application Interconnect 1.0skupper-cliAffected
Red Hat Ceph Storage 3golangOut of support scope
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Enterprise Linux 8container-tools:3.0/buildahWill not fix
Red Hat Enterprise Linux 8container-tools:3.0/containernetworking-pluginsAffected
Red Hat Enterprise Linux 8container-tools:3.0/podmanAffected
Red Hat Enterprise Linux 8container-tools:3.0/skopeoAffected
Red Hat Enterprise Linux 8container-tools:3.0/toolboxWill not fix
Red Hat Enterprise Linux 8git-lfsWill not fix
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 8grafana-pcpNot affected
Red Hat Enterprise Linux 8osbuild-composerWill not fix
Red Hat Enterprise Linux 8rhcNot affected
Red Hat Enterprise Linux 8weldr-clientWill not fix
Red Hat Enterprise Linux 9butaneNot affected
Red Hat Enterprise Linux 9conmonNot affected
Red Hat Enterprise Linux 9git-lfsWill not fix
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat Enterprise Linux 9grafana-pcpNot affected
Red Hat Enterprise Linux 9ignitionWill not fix
Red Hat Enterprise Linux 9osbuild-composerWill not fix
Red Hat Enterprise Linux 9weldr-clientWill not fix
Red Hat OpenShift Container Platform 4butaneWill not fix
Red Hat OpenShift Container Platform 4containernetworking-pluginsWill not fix
Red Hat OpenShift Container Platform 4cri-toolsAffected
Red Hat OpenShift Container Platform 4ignitionWill not fix
Red Hat OpenShift Container Platform 4openshiftAffected
Red Hat OpenShift Container Platform 4openshift-golang-builder-containerAffected
Red Hat Openshift Data Foundation 4mcgNot affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/udi-rhel8Affected
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-agent-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Will not fix
Red Hat OpenShift GitOpsopenshift-gitops-kamAffected
Red Hat OpenShift on AWSrosaAffected
Red Hat Openshift Sandboxed Containersopenshift-sandboxed-containers/osc-rhel9-operatorOut of support scope
Red Hat OpenShift Virtualization 4kubevirtAffected
Red Hat OpenStack Platform 16.2golang-github-infrawatch-apputilsNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8/osp-director-agentNot affected
Red Hat OpenStack Platform 17.0collectd-libpod-statsWill not fix
Red Hat OpenStack Platform 17.0golang-github-infrawatch-apputilsWill not fix
Red Hat Quay 3quay/clair-rhel8Affected
Red Hat Satellite 6foreman_ygg_workerNot affected
Red Hat Satellite 6satellite:el8/yggdrasil-worker-forwarderNot affected
Red Hat Satellite 6yggdrasilNot affected
Red Hat Satellite 6yggdrasil-worker-forwarderNot affected

Apply commands

bash fix
Apply RHSA-2023:4335 for CERT-MANAGER-1.10-RHEL-9
yum update -y cert-manager-operator-bundle-container-v1
# or:
dnf upgrade -y cert-manager-operator-bundle-container-v1

Affected

VendorProductVersion
redhatCustom Metric Autoscaler operator for Red Hat OpenshiftNot affected
redhatLogging Subsystem for Red Hat OpenShiftNot affected
redhatNode HealthCheck OperatorAffected
redhatNode Maintenance OperatorAffected
redhatOpenShift Developer Tools and ServicesAffected
redhatOpenShift PipelinesAffected
redhatRed Hat 3scale API Management Platform 2Affected
redhatRed Hat Advanced Cluster Management for Kubernetes 2Affected
redhatRed Hat Advanced Cluster Security 3Affected
redhatRed Hat AMQ Broker 7Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Application Interconnect 1.0Affected
redhatRed Hat Ceph Storage 5Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat Openshift Data Foundation 4Not affected
redhatRed Hat Openshift Data Foundation 4Not affected
redhatRed Hat OpenShift Dev SpacesAffected
redhatRed Hat OpenShift distributed tracing 2Affected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
redhat rhel9fixed
suse slesaffected
debian debianbullseyeaffected
debian debianbookwormfixed1.19.8-2

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.20.0-0,<1.20.31.19.8

References

Verify integrity in audit chain (admin only). AS-IS.