CVE-2024-24790: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
Last updated 14 November 2024
Other sources
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
— Launchpad
Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.22.4 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.21.11
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24790?
CVE-2024-24790 is classified as a moderate severity vulnerability.
How do I fix CVE-2024-24790?
To remediate CVE-2024-24790, upgrade golang to versions 1.22.4 or later, or 1.21.11 for specific packages.
What systems are affected by CVE-2024-24790?
CVE-2024-24790 affects specific versions of golang in Red Hat and Debian packages.
What types of addresses are impacted by CVE-2024-24790?
CVE-2024-24790 affects the Is methods for IPv4-mapped IPv6 addresses.
Is CVE-2024-24790 a critical vulnerability?
No, CVE-2024-24790 is not classified as a critical vulnerability.