First published: Mon Jul 22 2024(Updated: )
An update is now available for the Red Hat build of Cryostat 3 on RHEL 8.<br>Security Fix(es):<br><li> golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788)</li> <li> golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Cryostat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:4697 is critical due to the potential for denial of service caused by malformed DNS messages.
To fix RHSA-2024:4697, update your Red Hat Cryostat installation to the latest version provided in the advisory.
RHSA-2024:4697 addresses vulnerabilities related to malformed DNS messages and unexpected behavior in net/netip libraries in Golang.
RHSA-2024:4697 affects users of the Red Hat build of Cryostat 3 on RHEL 8.
RHSA-2024:4697 was released to address critical security flaws that could impact the stability of network operations.