First published: Thu Mar 28 2024(Updated: )
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/booth | <1.1 | 1.1 |
ClusterLabs | <1.1 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 | |
Red Hat Enterprise Linux Server EUS | =8.4 | |
Red Hat Enterprise Linux Server EUS | =8.8 | |
Red Hat Enterprise Linux Server EUS | =9.2 | |
Red Hat Enterprise Linux | =8.0_aarch64 | |
Red Hat Enterprise Linux | =8.8_aarch64 | |
Red Hat Enterprise Linux | =9.2_aarch64 | |
Red Hat Enterprise Linux | =9.4_aarch64 | |
Red Hat Enterprise Linux for IBM Z Systems | =8.0_s390x | |
Red Hat Enterprise Linux for IBM Z Systems | =9.2_s390x | |
Red Hat Enterprise Linux for IBM Z Systems | =9.4_s390x | |
Red Hat Enterprise Linux for IBM Z Systems (s390x) | =8.8_s390x | |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | =8.0_ppc64le | |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | =8.4_ppc64le | |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | =8.8_ppc64le | |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | =9.2_ppc64le | |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | =9.4_ppc64le | |
Red Hat Enterprise Linux Server Update Services for SAP Solutions | =8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3049 has not been assigned a specific severity rating yet, but it is suggested to assess it based on its potential impact on your environment.
To remediate CVE-2024-3049, upgrade the Booth package to version 1.1 or later.
CVE-2024-3049 affects the Booth cluster ticket manager in specific versions of Red Hat Enterprise Linux and similar distributions.
Yes, CVE-2024-3049 could potentially allow an invalid HMAC to be accepted, leading to security risks.
All environments running affected versions of Booth on Red Hat Enterprise Linux and derivatives should be reviewed for CVE-2024-3049.