CVE-2024-1394
Description
Important: golang security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-2562.html
Vendor advisory: alma — https://bugzilla.redhat.com/2268273
Vendor advisory: alma — https://bugzilla.redhat.com/2268022
Vendor advisory: alma — https://bugzilla.redhat.com/2268018
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-2568.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-3265.html
Vendor advisory: alma — https://bugzilla.redhat.com/2271903
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:3265
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-5258.html
Vendor advisory: alma — https://bugzilla.redhat.com/2295010
Vendor advisory: alma — https://bugzilla.redhat.com/2294000
Vendor advisory: alma — https://bugzilla.redhat.com/2292668
Vendor advisory: alma — https://bugzilla.redhat.com/2274767
Vendor advisory: alma — https://bugzilla.redhat.com/2268021
Vendor advisory: alma — https://bugzilla.redhat.com/2268019
Vendor advisory: alma — https://bugzilla.redhat.com/2268017
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:5258
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4761.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4379.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4762.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-2569.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4371.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-1502.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4502.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-1501.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2025-7118.html
Vendor advisory: alma — https://bugzilla.redhat.com/2315719
Vendor advisory: alma — https://bugzilla.redhat.com/2310529
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4378.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-1462.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-7262.html
Vendor advisory: alma — https://bugzilla.redhat.com/2310528
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:7262
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-1646.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:1646
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-1644.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:1644
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-1472.html
Vendor advisory: alma — https://bugzilla.redhat.com/2262921
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:1472
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:1502
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:2568
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:2562
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:2569
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:4502
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:1472
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:1644
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:1646
Vendor advisory: rocky — https://errata.rockylinux.org/RLBA-2024:3266
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:3265
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:5258
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:7262
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:7118
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4762
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4761
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4502
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4379
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4378
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4371
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:2569
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:2568
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:2562
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:1502
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:1501
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:1462
Mitigation details
Description golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads Red Hat statement The majority of RHEL utilities are not long-running applications; instead, they are command-line tools. These tools utilize Golang package as build-time dependency, which is why they are classified as having a "Moderate" level of impact. CVSS v3: 7.5…
Description
golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads
Red Hat statement
The majority of RHEL utilities are not long-running applications; instead, they are command-line tools. These tools utilize Golang package as build-time dependency, which is why they are classified as having a "Moderate" level of impact.
CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | receptor-0:1.4.5-1.el8ap | RHSA-2024:1640 | 2024-04-02T00:00:00Z |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | receptor-0:1.4.5-1.el9ap | RHSA-2024:1640 | 2024-04-02T00:00:00Z |
| Red Hat Developer Tools | go-toolset-1.19-golang-0:1.19.13-6.el7_9 | RHSA-2024:1468 | 2024-03-21T00:00:00Z |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8-8090020240313170136.26eb71ac | RHSA-2024:1472 | 2024-03-21T00:00:00Z |
| Red Hat Enterprise Linux 8 | grafana-pcp-0:5.1.1-2.el8_9 | RHSA-2024:1644 | 2024-04-02T00:00:00Z |
| Red Hat Enterprise Linux 8 | grafana-0:9.2.10-8.el8_9 | RHSA-2024:1646 | 2024-04-02T00:00:00Z |
| Red Hat Enterprise Linux 8 | grafana-0:9.2.10-16.el8_10 | RHSA-2024:3265 | 2024-05-22T00:00:00Z |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8100020240808093819.afee755d | RHSA-2024:5258 | 2024-08-13T00:00:00Z |
| Red Hat Enterprise Linux 8 | osbuild-composer-0:101-2.el8_10 | RHSA-2024:7262 | 2024-09-26T00:00:00Z |
| Red Hat Enterprise Linux 9 | golang-0:1.20.12-2.el9_3 | RHSA-2024:1462 | 2024-03-21T00:00:00Z |
| Red Hat Enterprise Linux 9 | grafana-0:9.2.10-8.el9_3 | RHSA-2024:1501 | 2024-03-25T00:00:00Z |
| Red Hat Enterprise Linux 9 | grafana-pcp-0:5.1.1-2.el9_3 | RHSA-2024:1502 | 2024-03-25T00:00:00Z |
| Red Hat Enterprise Linux 9 | golang-0:1.21.9-2.el9_4 | RHSA-2024:2562 | 2024-04-30T00:00:00Z |
| Red Hat Enterprise Linux 9 | grafana-0:9.2.10-16.el9_4 | RHSA-2024:2568 | 2024-04-30T00:00:00Z |
| Red Hat Enterprise Linux 9 | grafana-pcp-0:5.1.1-2.el9_4 | RHSA-2024:2569 | 2024-04-30T00:00:00Z |
| Red Hat Enterprise Linux 9 | buildah-2:1.33.7-3.el9_4 | RHSA-2024:4371 | 2024-07-08T00:00:00Z |
| Red Hat Enterprise Linux 9 | podman-4:4.9.4-5.el9_4 | RHSA-2024:4378 | 2024-07-08T00:00:00Z |
| Red Hat Enterprise Linux 9 | gvisor-tap-vsock-6:0.7.3-4.el9_4 | RHSA-2024:4379 | 2024-07-08T00:00:00Z |
| Red Hat Enterprise Linux 9 | skopeo-2:1.14.3-3.el9_4 | RHSA-2024:4502 | 2024-07-15T00:00:00Z |
| Red Hat Enterprise Linux 9 | containernetworking-plugins-1:1.4.0-4.el9_4 | RHSA-2024:4761 | 2024-07-23T00:00:00Z |
| Red Hat Enterprise Linux 9 | runc-4:1.1.12-3.el9_4 | RHSA-2024:4762 | 2024-07-23T00:00:00Z |
| Red Hat Enterprise Linux 9 | osbuild-composer-0:132-1.el9 | RHSA-2025:7118 | 2025-05-13T00:00:00Z |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | podman-2:4.2.0-4.el9_0 | RHSA-2024:4581 | 2024-07-16T00:00:00Z |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | containernetworking-plugins-1:1.0.1-6.el9_0 | RHSA-2024:4672 | 2024-07-22T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Extended Update Support | golang-0:1.19.13-7.el9_2 | RHSA-2024:4146 | 2024-06-27T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Extended Update Support | podman-2:4.4.1-20.el9_2 | RHSA-2024:5634 | 2024-08-20T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | buildah-1:1.23.4-5.2.rhaos4.12.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | butane-0:0.16.0-2.2.rhaos4.12.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | containernetworking-plugins-1:1.4.0-1.1.rhaos4.12.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | cri-o-0:1.25.3-5.2.rhaos4.12.git44a2cb2.el9 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | cri-tools-0:1.25.0-2.2.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | ignition-0:2.14.0-5.2.rhaos4.12.el9 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | openshift-clients-0:4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | podman-3:4.2.0-7.2.rhaos4.12.el9 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | runc-3:1.1.6-5.2.rhaos4.12.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | skopeo-2:1.9.4-3.2.rhaos4.12.el8 | RHSA-2024:1574 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | buildah-1:1.29.1-2.2.rhaos4.13.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | containernetworking-plugins-1:1.4.0-1.1.rhaos4.13.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | cri-o-0:1.26.5-11.1.rhaos4.13.git919cc6e.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | cri-tools-0:1.26.0-4.1.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | ignition-0:2.15.0-7.1.rhaos4.13.el9 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | openshift-clients-0:4.13.0-202404020737.p0.gd192e90.assembly.stream.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | podman-3:4.4.1-5.2.rhaos4.13.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | runc-4:1.1.12-1.1.rhaos4.13.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.13 | skopeo-2:1.11.2-2.2.rhaos4.13.el8 | RHSA-2024:1763 | 2024-04-18T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | butane-0:0.19.0-1.3.rhaos4.14.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | containernetworking-plugins-1:1.4.0-1.2.rhaos4.14.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | cri-o-0:1.27.4-6.1.rhaos4.14.gitd09e4c0.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | cri-tools-0:1.27.0-3.1.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | ignition-0:2.16.2-2.1.rhaos4.14.el9 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | openshift-clients-0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | ose-aws-ecr-image-credential-provider-0:4.14.0-202403251040.p0.g607e2dd.assembly.stream.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | podman-3:4.4.1-11.3.rhaos4.14.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | skopeo-2:1.11.2-10.3.rhaos4.14.el8 | RHSA-2024:1567 | 2024-04-03T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | buildah-1:1.29.1-10.4.rhaos4.14.el8 | RHSA-2024:1897 | 2024-04-26T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | butane-0:0.19.0-1.4.rhaos4.14.el8 | RHSA-2024:1897 | 2024-04-26T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | conmon-3:2.1.7-3.4.rhaos4.14.el8 | RHSA-2024:1897 | 2024-04-26T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | containernetworking-plugins-1:1.4.0-1.3.rhaos4.14.el8 | RHSA-2024:1897 | 2024-04-26T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | cri-o-0:1.27.4-7.2.rhaos4.14.git082c52f.el8 | RHSA-2024:1897 | 2024-04-26T00:00:00Z |
| Red Hat OpenShift Container Platform 4.14 | cri-tools-0:1.27.0-3.2.el8 | RHSA-2024:1897 | 2024-04-26T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| NBDE Tang Server | tang-operator-bundle-container | Will not fix |
| OpenShift Developer Tools and Services | helm | Affected |
| OpenShift Developer Tools and Services | odo | Will not fix |
| OpenShift Pipelines | openshift-pipelines-client | Not affected |
| OpenShift Serverless | openshift-serverless-clients | Affected |
| Red Hat Ansible Automation Platform 1.2 | helm | Will not fix |
| Red Hat Ansible Automation Platform 1.2 | openshift-clients | Will not fix |
| Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification-preflight | Fix deferred |
| Red Hat Certification Program for Red Hat Enterprise Linux 9 | redhat-certification-preflight | Fix deferred |
| Red Hat Enterprise Linux 7 | buildah | Out of support scope |
| Red Hat Enterprise Linux 7 | containernetworking-plugins | Out of support scope |
| Red Hat Enterprise Linux 7 | host-metering | Out of support scope |
| Red Hat Enterprise Linux 7 | podman | Out of support scope |
| Red Hat Enterprise Linux 7 | rhc-worker-script | Out of support scope |
| Red Hat Enterprise Linux 7 | skopeo | Out of support scope |
| Red Hat Enterprise Linux 8 | container-tools:4.0/buildah | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:4.0/conmon | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:4.0/containernetworking-plugins | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:4.0/podman | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:4.0/runc | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:4.0/skopeo | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:4.0/toolbox | Not affected |
| Red Hat Enterprise Linux 8 | git-lfs | Not affected |
| Red Hat Enterprise Linux 8 | rhc | Not affected |
| Red Hat Enterprise Linux 8 | weldr-client | Not affected |
| Red Hat Enterprise Linux 9 | butane | Will not fix |
| Red Hat Enterprise Linux 9 | conmon | Not affected |
| Red Hat Enterprise Linux 9 | git-lfs | Not affected |
| Red Hat Enterprise Linux 9 | ignition | Will not fix |
| Red Hat Enterprise Linux 9 | toolbox | Not affected |
| Red Hat Enterprise Linux 9 | weldr-client | Not affected |
| Red Hat OpenShift Container Platform 4 | conmon-rs | Not affected |
| Red Hat OpenShift Container Platform 4 | golang-github-prometheus-promu | Not affected |
| Red Hat OpenShift Container Platform 4 | lifecycle-agent-operator-bundle-container | Not affected |
| Red Hat OpenShift Container Platform 4 | openshift4/bare-metal-event-relay-operator-bundle | Out of support scope |
| Red Hat OpenShift Container Platform 4 | openshift4/numaresources-operator-bundle | Not affected |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-machine-approver-rhel9 | Not affected |
| Red Hat OpenShift Container Platform 4 | rhcos | Affected |
| Red Hat Openshift Container Storage 4 | mcg | Out of support scope |
| Red Hat OpenShift Dev Spaces | devspaces/machineexec-rhel8 | Affected |
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-operator-bundle | Will not fix |
| Red Hat OpenShift on AWS | rosa | Affected |
| Red Hat OpenShift Virtualization 4 | kubevirt | Not affected |
| Red Hat OpenStack Platform 16.1 | etcd | Out of support scope |
| Red Hat OpenStack Platform 16.1 | golang-qpid-apache | Will not fix |
| Red Hat OpenStack Platform 16.1 | qpid-proton | Not affected |
| Red Hat OpenStack Platform 16.2 | golang-github-infrawatch-apputils | Will not fix |
| Red Hat OpenStack Platform 16.2 | golang-qpid-apache | Will not fix |
| Red Hat OpenStack Platform 16.2 | qpid-proton | Not affected |
| Red Hat OpenStack Platform 17.1 | golang-github-infrawatch-apputils | Affected |
| Red Hat OpenStack Platform 17.1 | golang-qpid-apache | Will not fix |
| Red Hat OpenStack Platform 17.1 | qpid-proton | Not affected |
| Red Hat OpenStack Platform 18.0 | etcd | Will not fix |
| Red Hat Service Interconnect 1 | qpid-proton | Will not fix |
| Red Hat Service Interconnect 1 | skupper-cli | Affected |
| Red Hat Service Interconnect 1 | skupper-router | Will not fix |
| Red Hat Software Collections | rh-git227-git-lfs | Not affected |
| Red Hat Storage 3 | heketi | Out of support scope |
Apply commands
yum update -y receptor
# or:
dnf upgrade -y receptor
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | OpenShift Developer Tools and Services | Affected |
| redhat | OpenShift Pipelines | Not affected |
| redhat | OpenShift Serverless | Affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Affected |
| redhat | Red Hat OpenShift Dev Spaces | Affected |
| redhat | Red Hat OpenShift on AWS | Affected |
| redhat | Red Hat OpenShift Virtualization 4 | Not affected |
| redhat | Red Hat OpenStack Platform 16.1 | Not affected |
| redhat | Red Hat OpenStack Platform 16.2 | Not affected |
| redhat | Red Hat OpenStack Platform 17.1 | Affected |
| redhat | Red Hat OpenStack Platform 17.1 | Not affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
| rocky | 9 | fixed | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/golang-fips/go | <=1.22.1 | |
| Go | github.com/golang-fips/openssl/v2 | <2.0.1 | 2.0.1 |
| Go | github.com/microsoft/go-crypto-openssl | <=0.2.8 | |
| Go | github.com/microsoft/go-crypto-openssl/openssl | <0.2.9 | 0.2.9 |
| Go | github.com/microsoft/go-crypto-openssl | <0.2.9 | 0.2.9 |
References
- https://access.redhat.com/errata/RHSA-2024:1462
- https://access.redhat.com/errata/RHSA-2024:1501
- https://access.redhat.com/errata/RHSA-2024:1502
- https://access.redhat.com/errata/RHSA-2024:2562
- https://access.redhat.com/errata/RHSA-2024:2568
- https://access.redhat.com/errata/RHSA-2024:2569
- https://access.redhat.com/errata/RHSA-2024:4371
- https://access.redhat.com/errata/RHSA-2024:4378
- https://access.redhat.com/errata/RHSA-2024:4379
- https://access.redhat.com/errata/RHSA-2024:4502
- https://access.redhat.com/errata/RHSA-2024:4761
- https://access.redhat.com/errata/RHSA-2024:4762
- https://access.redhat.com/errata/RHSA-2025:7118
- https://errata.rockylinux.org/RLSA-2024:7262
- https://errata.rockylinux.org/RLSA-2024:5258
- https://errata.rockylinux.org/RLSA-2024:3265
- https://errata.rockylinux.org/RLBA-2024:3266
- https://errata.rockylinux.org/RLSA-2024:1646
- https://errata.rockylinux.org/RLSA-2024:1644
- https://errata.rockylinux.org/RLSA-2024:1472
- https://github.com/golang-fips/openssl/security/advisories/GHSA-78hx-gp6g-7mj6
- https://nvd.nist.gov/vuln/detail/CVE-2024-1394
- https://github.com/microsoft/go-crypto-openssl/commit/104fe7f6912788d2ad44602f77a0a0a62f1f259f
- https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136
- https://access.redhat.com/errata/RHSA-2024:4581
Verify integrity in audit chain (admin only). AS-IS.