CVE-2024-3049: Booth: specially crafted hash can lead to invalid hmac being accepted by booth server
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcrymdgetalgodlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Other sources
When an unknown or specially-crafted hash is passed to gcrymdgetalgodlen, 0 is returned. This value is then used for memcmp, so the wrong hmac may be accepted by the Booth server as valid.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3049?
CVE-2024-3049 has not been assigned a specific severity rating yet, but it is suggested to assess it based on its potential impact on your environment.
How do I fix CVE-2024-3049?
To remediate CVE-2024-3049, upgrade the Booth package to version 1.1 or later.
Which software is affected by CVE-2024-3049?
CVE-2024-3049 affects the Booth cluster ticket manager in specific versions of Red Hat Enterprise Linux and similar distributions.
Can CVE-2024-3049 lead to security breaches?
Yes, CVE-2024-3049 could potentially allow an invalid HMAC to be accepted, leading to security risks.
What environments should be reviewed for CVE-2024-3049?
All environments running affected versions of Booth on Red Hat Enterprise Linux and derivatives should be reviewed for CVE-2024-3049.