RHSA-2024:8329: Important: Red Hat build of Cryostat security update
An update is now available for the Red Hat build of Cryostat 3 on RHEL 8.<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)</li> <li> golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158)</li> <li> golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155)</li> <li> com.graphql-java/graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java (CVE-2024-40094)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Red Hat build of Cryostat security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8329?
The severity of RHSA-2024:8329 is categorized based on the vulnerabilities addressed, specifically CVE-2024-34156.
How do I fix RHSA-2024:8329?
To fix RHSA-2024:8329, apply the latest security update for Red Hat Cryostat 3 on RHEL 8.
What vulnerabilities are addressed in RHSA-2024:8329?
RHSA-2024:8329 addresses vulnerabilities including stack exhaustion issues in the golang decoder resulting from deeply nested structures as identified by CVE-2024-34156.
Which software is affected by RHSA-2024:8329?
RHSA-2024:8329 affects the Red Hat build of Cryostat 3 on RHEL 8.
When was RHSA-2024:8329 released?
RHSA-2024:8329 was released as an update for Red Hat Cryostat 3 on RHEL 8.